Remote Code Execution

⚔️ Attack Types Related 19
slug: rce

Explanation

RCE (Remote Code Execution) は「攻撃者が遠隔から、サーバー上で任意のプログラムを実行できる」最も深刻な脆弱性です。 これが成立すると、サーバー全体が乗っ取られ、データ全削除・暗号通貨マイニング・ランサムウェア感染・他社攻撃の踏み台化など何でもされます。 セキュリティ業界では「最悪レベル」「最優先で塞ぐべき」と扱われます。
📌 Example
Log4Shell (CVE-2021-44228), Heartbleed (CVE-2014-0160) の後継 OpenSSL系, MOVEit Transfer (CVE-2023-34362) など。被害規模は数千億円〜兆円単位。

🔖 Related tags

🛡 Vulnerabilities tagged with this 2,172

ID Title
CVE-2026-25589 Vulnerability in keydb (CVE-2026-25589)
CVE-2026-23479 Use-After-Free in redis (CVE-2026-23479)
CVE-2026-43067 Vulnerability in linux (CVE-2026-43067)
CVE-2026-41922 OS Command Injection in CVE-2026-41922 (CVE-2026-41922)
CVE-2026-42027 Vulnerability in org.apache.opennlp:opennlp-tools (CVE-2026-42027)
CVE-2026-42796 Vulnerability in workiva (CVE-2026-42796)
CVE-2026-40076 Path Traversal in org.openmrs.web:openmrs-web (CVE-2026-40076)
CVE-2026-42090 Cross-Site Scripting (XSS) in streetwriters (CVE-2026-42090)
CVE-2026-26956 Vulnerability in vm2-project (CVE-2026-26956)
CVE-2026-29514 Vulnerability in CVE-2026-29514 (CVE-2026-29514)
CVE-2026-24118 Code Injection in vm2-project (CVE-2026-24118)
CVE-2026-24120 Code Injection in vm2-project (CVE-2026-24120)
CVE-2026-24781 Code Injection in vm2-project (CVE-2026-24781)
CVE-2026-37530 Vulnerability in c (CVE-2026-37530)
CVE-2026-43038 Vulnerability in linux (CVE-2026-43038)
CVE-2026-44015 SSRF (Server-Side Request Forgery) in github.com/0xJacky/Nginx-UI (CVE-2026-44015)
CVE-2026-42249 Path Traversal in path-traversal (CVE-2026-42249)
CVE-2026-7358 Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7356 Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7355 Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-7348 Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7335 Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2026-7336 Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2025-10539 Vulnerability in draugiemgroup (CVE-2025-10539)
CVE-2026-40972 Vulnerability in spring (CVE-2026-40972)
CVE-2024-1708 KEV [KEV] Path Traversal in Connectwise screenconnect (CVE-2024-1708)
CVE-2026-30352 Command Injection in CVE-2026-30352 (CVE-2026-30352)
CVE-2026-33453 Vulnerability in apache (CVE-2026-33453)
CVE-2026-40860 Unsafe Deserialization in org.apache.camel:camel-jms (CVE-2026-40860)
CVE-2026-40453 Vulnerability in org.apache.camel:camel-coap (CVE-2026-40453)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →