Live
2026年8月30日
Sources: NVD · GHSA · OSV · CISA KEV · JVN
ログイン
新規登録
JA
·
EN
·
FR
SecPulse
v1
脆弱性
KEV
タグ
カテゴリ
脆弱性
KEV
タグ
カテゴリ
ホーム
/
カテゴリ
/
Webアプリケーション
🌐
Webアプリケーション
slug: web-application
🛡 関連する脆弱性
283
ID
タイトル
重要度
検知
CVE-2026-67623
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
High
3週間前
CVE-2026-71288
Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
High
3週間前
CVE-2026-71287
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
High
3週間前
CVE-2026-71280
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
High
3週間前
CVE-2026-71271
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
High
3週間前
CVE-2026-71272
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
High
3週間前
CVE-2026-71270
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
High
3週間前
CVE-2026-71259
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
High
3週間前
CVE-2026-7444
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
High
3週間前
CVE-2026-7520
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
High
3週間前
CVE-2026-71209
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
High
3週間前
CVE-2026-71215
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
High
3週間前
CVE-2026-71206
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
High
3週間前
CVE-2026-6627
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
High
3週間前
CVE-2026-6147
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
High
3週間前
CVE-2026-55739
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce...
High
3週間前
CVE-2026-54418
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData,...
High
3週間前
CVE-2026-18859
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of...
High
3週間前
CVE-2026-17347
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an...
High
4週間前
CVE-2026-17346
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON /...
High
4週間前
CVE-2026-44097
A low-privileged remote attacker with "operator" access can upload arbitrary files via the REST...
High
4週間前
CVE-2026-44098
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
High
4週間前
CVE-2026-6267
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5,...
High
1ヶ月前
CVE-2026-5490
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote...
High
1ヶ月前
CVE-2026-67428
Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)
High
1ヶ月前
CVE-2026-67424
Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation
High
1ヶ月前
CVE-2026-67201
V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass...
High
1ヶ月前
CVE-2026-65443
Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.
High
1ヶ月前
CVE-2026-65447
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
High
1ヶ月前
CVE-2026-65446
Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
High
1ヶ月前
« Previous
Next »
Showing
61
to
90
of
283
results
1
2
3
4
5
6
7
8
9
10
🍪 Cookie について
当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。
すべて受け入れる
必須のみ
詳細 →