脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: タグ: rce クリア
ID タイトル
CVE-2026-55799 apache に コードインジェクション (CVE-2026-55799)
apache に コードインジェクション (CVE-2026-55799) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-66915 CVE-2026-66915 に コードインジェクション (CVE-2026-66915)
CVE-2026-66915 に コードインジェクション (CVE-2026-66915) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-19089 wordpress に 危険なファイルアップロード (CVE-2026-19089)
wordpress に 脆弱性 (CVE-2026-19089) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-16985 wordpress に 危険なファイルアップロード (CVE-2026-16985)
wordpress に 脆弱性 (CVE-2026-16985) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-15038 wordpress に 認証バイパス (CVE-2026-15038)
wordpress に 認証バイパス (CVE-2026-15038) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-42170 A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file...
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file...
CVE-2026-48120 Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell comma...
Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup files leading to arbitrary kakoune and shell commands being executed by simply opening a file. Kakoune 2026.05.21 fixes the issue. As a workaround, ad...
CVE-2026-46409 CVE-2026-46409 に コードインジェクション (CVE-2026-46409)
CVE-2026-46409 に コードインジェクション (CVE-2026-46409) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-64638 wordpress に クロスサイトスクリプティング (CVE-2026-64638)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-64638) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-68772 CVE-2026-68772 に 安全でないデシリアライゼーション (CVE-2026-68772)
CVE-2026-68772 に 脆弱性 (CVE-2026-68772) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-17603 CVE-2026-17603 に コードインジェクション (CVE-2026-17603)
CVE-2026-17603 に コードインジェクション (CVE-2026-17603) が存在。不正な操作・情報露出のリスクがあります。
CVE-2022-4995 CVE-2022-4995 に 危険なファイルアップロード (CVE-2022-4995)
CVE-2022-4995 に 脆弱性 (CVE-2022-4995) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-54212 dos に 境界外書き込み (CVE-2026-54212)
dos に 境界外書き込み (CVE-2026-54212) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-54210 dos に 境界外書き込み (CVE-2026-54210)
dos に 境界外書き込み (CVE-2026-54210) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-54211 dos に 境界外書き込み (CVE-2026-54211)
dos に 境界外書き込み (CVE-2026-54211) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-16258 wordpress に 安全でないデシリアライゼーション (CVE-2026-16258)
wordpress に 脆弱性 (CVE-2026-16258) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-15215 wordpress に 権限昇格 (CVE-2026-15215)
wordpress に 脆弱性 (CVE-2026-15215) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-70640 cpp の脆弱性 (CVE-2026-70640)
cpp に 脆弱性 (CVE-2026-70640) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-5857 c に 境界外書き込み (CVE-2026-5857)
c に 境界外書き込み (CVE-2026-5857) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-48080 ssrf に 情報漏洩 (CVE-2026-48080)
ssrf に 脆弱性 (CVE-2026-48080) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`GET /api/tenants/{id}` 経由で攻撃可能。
CVE-2026-43631 cpp の脆弱性 (CVE-2026-43631)
cpp に 脆弱性 (CVE-2026-43631) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-3418 CVE-2026-3418 に 危険なファイルアップロード (CVE-2026-3418)
CVE-2026-3418 に 脆弱性 (CVE-2026-3418) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-15733 CVE-2026-15733 に OSコマンドインジェクション (CVE-2026-15733)
CVE-2026-15733 に OSコマンドインジェクション (CVE-2026-15733) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-14812 wordpress の脆弱性 (CVE-2026-14812)
wordpress に 脆弱性 (CVE-2026-14812) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2024-39024 In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
CVE-2026-71476 nx に パストラバーサル (CVE-2026-71476)
nx に パストラバーサル (CVE-2026-71476) が存在。不正な操作・情報露出のリスクがあります。``NX_SELF_HOSTED_REMOTE_CACHE_SERVER`` 経由で攻撃可能。対策: `23.0.2` 以上に更新。
CVE-2026-66709 Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-65553 CVE-2026-65553 に コードインジェクション (CVE-2026-65553)
CVE-2026-65553 に コードインジェクション (CVE-2026-65553) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-65548 Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
CVE-2026-53975 CVE-2026-53975 に OSコマンドインジェクション (CVE-2026-53975)
CVE-2026-53975 に OSコマンドインジェクション (CVE-2026-53975) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-66909 apache に 安全でないデシリアライゼーション (CVE-2026-66909)
apache に 脆弱性 (CVE-2026-66909) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-15459 wordpress に 認証バイパス (CVE-2026-15459)
wordpress に 認証バイパス (CVE-2026-15459) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
CVE-2026-67531 CVE-2026-67531 に コードインジェクション (CVE-2026-67531)
CVE-2026-67531 に コードインジェクション (CVE-2026-67531) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-55522 praisonaiagents に コードインジェクション (CVE-2026-55522)
praisonaiagents に コードインジェクション (CVE-2026-55522) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``tools.py`` 経由で攻撃可能。対策: `1.6.58` 以上に更新。
CVE-2026-67623 Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
CVE-2026-15979 wordpress に パストラバーサル (CVE-2026-15979)
wordpress に パストラバーサル (CVE-2026-15979) が存在。データの不正な改ざんを許す可能性があります。
CVE-2026-71294 CVE-2026-71294 に 安全でないデシリアライゼーション (CVE-2026-71294)
CVE-2026-71294 に 脆弱性 (CVE-2026-71294) が存在。機密情報が外部に流出する可能性があります。``allowed_classes`` 経由で攻撃可能。
CVE-2026-71291 Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
CVE-2026-71288 Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
CVE-2026-71281 Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
CVE-2026-71279 CVE-2026-71279 に パストラバーサル (CVE-2026-71279)
CVE-2026-71279 に パストラバーサル (CVE-2026-71279) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``name`` 経由で攻撃可能。
CVE-2026-71269 CVE-2026-71269 に パストラバーサル (CVE-2026-71269)
CVE-2026-71269 に パストラバーサル (CVE-2026-71269) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /library/` 経由で攻撃可能。
CVE-2026-71268 CVE-2026-71268 に パストラバーサル (CVE-2026-71268)
CVE-2026-71268 に パストラバーサル (CVE-2026-71268) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71271 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
CVE-2026-71262 path-traversal の脆弱性 (CVE-2026-71262)
path-traversal に 脆弱性 (CVE-2026-71262) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71259 ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
CVE-2026-71254 c に 境界外書き込み (CVE-2026-71254)
c に 境界外書き込み (CVE-2026-71254) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-18933 wordpress に 危険なファイルアップロード (CVE-2026-18933)
wordpress に 脆弱性 (CVE-2026-18933) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71232 CVE-2026-71232 に コードインジェクション (CVE-2026-71232)
CVE-2026-71232 に コードインジェクション (CVE-2026-71232) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →