脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-36960 |
|
csrf に CSRF (CVE-2026-36960)
csrf に 脆弱性 (CVE-2026-36960) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2025-14576 |
|
dos の脆弱性 (CVE-2025-14576)
dos に 脆弱性 (CVE-2025-14576) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-36959 |
|
u-speed の脆弱性 (CVE-2026-36959)
u-speed に 脆弱性 (CVE-2026-36959) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-36956 |
|
csrf に CSRF (CVE-2026-36956)
csrf に 脆弱性 (CVE-2026-36956) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-36957 |
|
dos の脆弱性 (CVE-2026-36957)
dos に 脆弱性 (CVE-2026-36957) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-36958 |
|
u-speed の脆弱性 (CVE-2026-36958)
u-speed に 脆弱性 (CVE-2026-36958) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7246 |
|
palletsprojects に コマンドインジェクション (CVE-2026-7246)
palletsprojects に コマンドインジェクション (CVE-2026-7246) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7399 |
|
CVE-2026-7399 の脆弱性 (CVE-2026-7399)
CVE-2026-7399 に 脆弱性 (CVE-2026-7399) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-7402 |
|
CVE-2026-7402 の脆弱性 (CVE-2026-7402)
CVE-2026-7402 に 脆弱性 (CVE-2026-7402) が存在。データの不正な改ざんを許す可能性があります。
|
| CVE-2024-13971 |
|
lobster-world に XXE (外部XMLエンティティ) (CVE-2024-13971)
lobster-world に 脆弱性 (CVE-2024-13971) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-5402 |
|
dos の脆弱性 (CVE-2026-5402)
dos に 脆弱性 (CVE-2026-5402) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7270 |
|
freebsd の脆弱性 (CVE-2026-7270)
freebsd に 脆弱性 (CVE-2026-7270) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2024-39847 |
|
4d に XXE (外部XMLエンティティ) (CVE-2024-39847)
4d に 脆弱性 (CVE-2024-39847) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-41940 KEV |
|
【KEV】Webpros cpanel-whm-and-wp2-wordpress-squared の脆弱性 (CVE-2026-41940)
Webpros cpanel-whm-and-wp2-wordpress-squared に 脆弱性 (CVE-2026-41940) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
|
| CVE-2026-44015 |
|
github.com/0xJacky/Nginx-UI に SSRF (サーバー側リクエスト偽造) (CVE-2026-44015)
github.com/0xJacky/Nginx-UI に SSRF (CVE-2026-44015) が存在。機密情報が外部に流出する可能性があります。`GET /api/settings` 経由で攻撃可能。
|
| CVE-2018-25304 |
|
CVE-2018-25304 の脆弱性 (CVE-2018-25304)
CVE-2018-25304 に 脆弱性 (CVE-2018-25304) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-37555 |
|
dos の脆弱性 (CVE-2026-37555)
dos に 脆弱性 (CVE-2026-37555) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-6849 |
|
Improper neutralization of special elements used in an OS command ('OS command injection')...
Improper neutralization of special elements used in an OS command ('OS command injection')...
|
| CVE-2026-42198 |
|
dos の脆弱性 (CVE-2026-42198)
dos に 脆弱性 (CVE-2026-42198) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7111 |
|
hmbrand に 解放後使用 (Use-After-Free) (CVE-2026-7111)
hmbrand に 脆弱性 (CVE-2026-7111) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-5161 |
|
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM...
Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM...
|
| CVE-2026-5141 |
|
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment...
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment...
|
| CVE-2026-41952 |
|
privilege-escalation の脆弱性 (CVE-2026-41952)
privilege-escalation に 脆弱性 (CVE-2026-41952) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-41220 |
|
privilege-escalation に 境界外書き込み (CVE-2026-41220)
privilege-escalation に 境界外書き込み (CVE-2026-41220) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-5140 |
|
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM...
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM...
|
| CVE-2026-42615 |
|
CVE-2026-42615 に クロスサイトスクリプティング (CVE-2026-42615)
CVE-2026-42615 に XSS (クロスサイトスクリプティング) (CVE-2026-42615) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-40560 |
|
miyagawa の脆弱性 (CVE-2026-40560)
miyagawa に 脆弱性 (CVE-2026-40560) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-7355 |
|
Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
|
| CVE-2026-7356 |
|
Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7357 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7357)
google に 脆弱性 (CVE-2026-7357) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7358 |
|
Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7359 |
|
Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch...
Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7361 |
|
Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
|
| CVE-2026-7345 |
|
google の脆弱性 (CVE-2026-7345)
google に 脆弱性 (CVE-2026-7345) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7346 |
|
google に バッファオーバーフロー (CVE-2026-7346)
google に 脆弱性 (CVE-2026-7346) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-7347 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7347)
google に 脆弱性 (CVE-2026-7347) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7348 |
|
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7349 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7349)
google に 脆弱性 (CVE-2026-7349) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7350 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7350)
google に 脆弱性 (CVE-2026-7350) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7352 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7352)
google に 脆弱性 (CVE-2026-7352) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7353 |
|
google の脆弱性 (CVE-2026-7353)
google に 脆弱性 (CVE-2026-7353) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7354 |
|
Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: H...
Out of bounds read and write in Angle in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7335 |
|
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7336 |
|
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7337 |
|
google の脆弱性 (CVE-2026-7337)
google に 脆弱性 (CVE-2026-7337) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7338 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7338)
google に 脆弱性 (CVE-2026-7338) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7339 |
|
google の脆弱性 (CVE-2026-7339)
google に 脆弱性 (CVE-2026-7339) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7341 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7341)
google に 脆弱性 (CVE-2026-7341) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7342 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7342)
google に 脆弱性 (CVE-2026-7342) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-7343 |
|
google に 解放後使用 (Use-After-Free) (CVE-2026-7343)
google に 脆弱性 (CVE-2026-7343) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|