Remote Code Execution

⚔️ Attack Types Related 19
slug: rce

Explanation

RCE (Remote Code Execution) は「攻撃者が遠隔から、サーバー上で任意のプログラムを実行できる」最も深刻な脆弱性です。 これが成立すると、サーバー全体が乗っ取られ、データ全削除・暗号通貨マイニング・ランサムウェア感染・他社攻撃の踏み台化など何でもされます。 セキュリティ業界では「最悪レベル」「最優先で塞ぐべき」と扱われます。
📌 Example
Log4Shell (CVE-2021-44228), Heartbleed (CVE-2014-0160) の後継 OpenSSL系, MOVEit Transfer (CVE-2023-34362) など。被害規模は数千億円〜兆円単位。

🔖 Related tags

🛡 Vulnerabilities tagged with this 2,172

ID Title
CVE-2026-43631 Vulnerability in cpp (CVE-2026-43631)
CVE-2026-3418 Unrestricted File Upload in CVE-2026-3418 (CVE-2026-3418)
CVE-2026-15733 OS Command Injection in CVE-2026-15733 (CVE-2026-15733)
CVE-2026-14812 Vulnerability in wordpress (CVE-2026-14812)
CVE-2024-39024 In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
CVE-2026-71476 Path Traversal in nx (CVE-2026-71476)
CVE-2026-66709 Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-65553 Code Injection in CVE-2026-65553 (CVE-2026-65553)
CVE-2026-65548 Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
CVE-2026-53975 OS Command Injection in CVE-2026-53975 (CVE-2026-53975)
CVE-2026-66909 Unsafe Deserialization in apache (CVE-2026-66909)
CVE-2026-15459 Authentication Bypass in wordpress (CVE-2026-15459)
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
CVE-2026-67531 Code Injection in CVE-2026-67531 (CVE-2026-67531)
CVE-2026-55522 Code Injection in praisonaiagents (CVE-2026-55522)
CVE-2026-67623 Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
CVE-2026-15979 Path Traversal in wordpress (CVE-2026-15979)
CVE-2026-71294 Unsafe Deserialization in CVE-2026-71294 (CVE-2026-71294)
CVE-2026-71291 Bolt CMS renders content field values through Twig's full application-level Environment with no...
CVE-2026-71288 Koha's guided report builder (reports/guided_reports.pl) reads the `order_by` CGI parameter and,...
CVE-2026-71281 Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
CVE-2026-71279 Path Traversal in CVE-2026-71279 (CVE-2026-71279)
CVE-2026-71269 Path Traversal in CVE-2026-71269 (CVE-2026-71269)
CVE-2026-71268 Path Traversal in CVE-2026-71268 (CVE-2026-71268)
CVE-2026-71271 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
CVE-2026-71262 Vulnerability in path-traversal (CVE-2026-71262)
CVE-2026-71259 ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
CVE-2026-71254 Out-of-Bounds Write in c (CVE-2026-71254)
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
CVE-2026-71232 Code Injection in CVE-2026-71232 (CVE-2026-71232)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →