🌐

Webアプリケーション

slug: web-application

🛡 関連する脆弱性 283

ID タイトル
CVE-2026-82475 iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
CVE-2026-82472 Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
CVE-2026-82466 Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
CVE-2026-81421 A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
CVE-2026-77652 A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
CVE-2026-68863 Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
CVE-2026-68861 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
CVE-2021-23758 KEV Ajax.NET Professional Ajax.NET Professional — Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2026-18323 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16601 The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
CVE-2026-18328 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-68960 A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
CVE-2026-78681 NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
CVE-2026-78680 NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
CVE-2026-78675 GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
CVE-2026-75574 The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
CVE-2026-72695 Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
CVE-2026-56707 Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
CVE-2026-56702 Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
CVE-2026-34968 Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
CVE-2026-76098 Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens fr...
CVE-2026-71504 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
CVE-2026-71505 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API...
CVE-2026-71506 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
CVE-2026-40877 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
CVE-2026-30864 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
CVE-2026-78208 exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
CVE-2026-78209 exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
CVE-2026-78161 A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
CVE-2026-78203 Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap...

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →