脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-35066 |
|
dos の脆弱性 (CVE-2026-35066)
dos に 脆弱性 (CVE-2026-35066) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-42055 |
|
nginx の脆弱性 (CVE-2026-42055)
nginx に 脆弱性 (CVE-2026-42055) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-42530 |
|
nginx に 解放後使用 (Use-After-Free) (CVE-2026-42530)
nginx に 脆弱性 (CVE-2026-42530) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-54415 |
|
CVE-2026-54415 に 権限昇格 (CVE-2026-54415)
CVE-2026-54415 に 脆弱性 (CVE-2026-54415) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-54810 |
|
CVE-2026-54810 の脆弱性 (CVE-2026-54810)
CVE-2026-54810 に 脆弱性 (CVE-2026-54810) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2025-26240 |
|
pdfkit の脆弱性 (CVE-2025-26240)
pdfkit に 脆弱性 (CVE-2025-26240) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-49502 |
|
dell に 認証バイパス (CVE-2026-49502)
dell に 認証バイパス (CVE-2026-49502) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2025-71322 |
|
picklescan の脆弱性 (CVE-2025-71322)
picklescan に 脆弱性 (CVE-2025-71322) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``pty`` 経由で攻撃可能。対策: `0.0.33` 以上に更新。
|
| CVE-2026-54814 |
|
CVE-2026-54814 の脆弱性 (CVE-2026-54814)
CVE-2026-54814 に 脆弱性 (CVE-2026-54814) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-54818 |
|
sqli に SQLインジェクション (CVE-2026-54818)
sqli に SQLインジェクション (CVE-2026-54818) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-54193 |
|
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions.
|
| CVE-2026-54417 |
|
c の脆弱性 (CVE-2026-54417)
c に 脆弱性 (CVE-2026-54417) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-54816 |
|
CVE-2026-54816 に コードインジェクション (CVE-2026-54816)
CVE-2026-54816 に コードインジェクション (CVE-2026-54816) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-52707 |
|
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
|
| CVE-2026-54813 |
|
sqli に SQLインジェクション (CVE-2026-54813)
sqli に SQLインジェクション (CVE-2026-54813) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-32804 |
|
dell に 認証バイパス (CVE-2026-32804)
dell に 認証バイパス (CVE-2026-32804) が存在。データの不正な改ざんを許す可能性があります。
|
| CVE-2026-55738 |
|
c の脆弱性 (CVE-2026-55738)
c に 脆弱性 (CVE-2026-55738) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-11311 |
|
nginx-gateway-fabric の脆弱性 (CVE-2026-11311)
nginx-gateway-fabric に 脆弱性 (CVE-2026-11311) が存在。機密情報が外部に流出する可能性があります。対策: `2.6.4` 以上に更新。
|
| CVE-2026-22283 |
|
dell の脆弱性 (CVE-2026-22283)
dell に 脆弱性 (CVE-2026-22283) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2025-69170 |
|
Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.
Unauthenticated Local File Inclusion in Eventicity <= 1.5 versions.
|
| CVE-2025-69189 |
|
CVE-2025-69189 の脆弱性 (CVE-2025-69189)
CVE-2025-69189 に 脆弱性 (CVE-2025-69189) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2025-69174 |
|
Unauthenticated Local File Inclusion in Etude <= 1.6 versions.
Unauthenticated Local File Inclusion in Etude <= 1.6 versions.
|
| CVE-2025-69106 |
|
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
Unauthenticated Local File Inclusion in Imba <= 1.5.0 versions.
|
| CVE-2025-69144 |
|
Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.
Unauthenticated Local File Inclusion in Preservation <= 1.10 versions.
|
| CVE-2025-69126 |
|
Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.
Unauthenticated Local File Inclusion in Fortius <= 2.3.0 versions.
|
| CVE-2025-69158 |
|
Unauthenticated Local File Inclusion in Granola <= 1.13 versions.
Unauthenticated Local File Inclusion in Granola <= 1.13 versions.
|
| CVE-2025-69166 |
|
Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.
Unauthenticated Local File Inclusion in Gunslinger <= 1.7 versions.
|
| CVE-2025-68524 |
|
Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Avante < 3.0.5 versions.
|
| CVE-2025-69140 |
|
Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
Unauthenticated Cross Site Scripting (XSS) in SweetDate Core < 1.1.5 versions.
|
| CVE-2025-69115 |
|
wordpress の脆弱性 (CVE-2025-69115)
wordpress に 脆弱性 (CVE-2025-69115) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2025-69123 |
|
Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.
Unauthenticated Local File Inclusion in Snow Club <= 1.1 versions.
|
| CVE-2025-69157 |
|
Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.
Unauthenticated Local File Inclusion in Gamic <= 1.15 versions.
|
| CVE-2025-69120 |
|
Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.
Unauthenticated Local File Inclusion in Dazzle <= 1.0.0 versions.
|
| CVE-2025-69128 |
|
path-traversal に パストラバーサル (CVE-2025-69128)
path-traversal に パストラバーサル (CVE-2025-69128) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-39590 |
|
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions.
|
| CVE-2026-39556 |
|
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
|
| CVE-2025-69175 |
|
Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
|
| CVE-2026-39442 |
|
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
|
| CVE-2025-69130 |
|
wordpress に 安全でないデシリアライゼーション (CVE-2025-69130)
wordpress に 脆弱性 (CVE-2025-69130) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-39559 |
|
Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.
Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions.
|
| CVE-2026-39445 |
|
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
|
| CVE-2026-39523 |
|
Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.
Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions.
|
| CVE-2026-40738 |
|
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
|
| CVE-2026-39560 |
|
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
|
| CVE-2026-40752 |
|
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
|
| CVE-2026-40756 |
|
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
|
| CVE-2026-39576 |
|
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
|
| CVE-2026-40757 |
|
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
|
| CVE-2026-40733 |
|
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
|
| CVE-2026-40720 |
|
Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions.
|