Remote Code Execution

⚔️ Attack Types Related 19
slug: rce

Explanation

RCE (Remote Code Execution) は「攻撃者が遠隔から、サーバー上で任意のプログラムを実行できる」最も深刻な脆弱性です。 これが成立すると、サーバー全体が乗っ取られ、データ全削除・暗号通貨マイニング・ランサムウェア感染・他社攻撃の踏み台化など何でもされます。 セキュリティ業界では「最悪レベル」「最優先で塞ぐべき」と扱われます。
📌 Example
Log4Shell (CVE-2021-44228), Heartbleed (CVE-2014-0160) の後継 OpenSSL系, MOVEit Transfer (CVE-2023-34362) など。被害規模は数千億円〜兆円単位。

🔖 Related tags

🛡 Vulnerabilities tagged with this 2,172

ID Title
CVE-2026-7667 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow...
CVE-2026-63030 KEV WordPress Core — WordPress Core Interpretation Conflict Vulnerability
CVE-2026-13448 Vulnerability in langflow (CVE-2026-13448)
CVE-2026-9762 Code Injection in ibm (CVE-2026-9762)
CVE-2026-9586 SQL Injection in sqli (CVE-2026-9586)
CVE-2026-9202 Vulnerability in langflow (CVE-2026-9202)
CVE-2026-9198 KEV [KEV] Code Injection in Ibm langflow (CVE-2026-9198)
CVE-2026-13352 Unrestricted File Upload in wordpress (CVE-2026-13352)
CVE-2026-15422 Vulnerability in CVE-2026-15422 (CVE-2026-15422)
CVE-2026-55579 Vulnerability in pheditor/pheditor (CVE-2026-55579)
CVE-2026-53535 Path Traversal in dos (CVE-2026-53535)
CVE-2026-14890 Unsafe Deserialization in deserialization (CVE-2026-14890)
CVE-2023-49900 OS Command Injection in CVE-2023-49900 (CVE-2023-49900)
CVE-2026-15008 Unsafe Deserialization in wordpress (CVE-2026-15008)
CVE-2026-45313 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and...
CVE-2026-30618 Code Injection in CVE-2026-30618 (CVE-2026-30618)
CVE-2026-30623 Command Injection in c (CVE-2026-30623)
CVE-2026-45534 Code Injection in CVE-2026-45534 (CVE-2026-45534)
CVE-2026-62349 Vulnerability in c (CVE-2026-62349)
CVE-2026-40501 Vulnerability in CVE-2026-40501 (CVE-2026-40501)
CVE-2026-58659 Vulnerability in lightningai (CVE-2026-58659)
CVE-2026-50148 Vulnerability in metabase (CVE-2026-50148)
CVE-2026-61457 Unrestricted File Upload in CVE-2026-61457 (CVE-2026-61457)
CVE-2026-61443 Path Traversal in CVE-2026-61443 (CVE-2026-61443)
CVE-2026-61446 Code Injection in path-traversal (CVE-2026-61446)
CVE-2026-61438 OS Command Injection in CVE-2026-61438 (CVE-2026-61438)
CVE-2026-13001 Vulnerability in wordpress (CVE-2026-13001)
CVE-2026-15428 OS Command Injection in tp-link (CVE-2026-15428)
CVE-2026-9127 Authorization Flaw in rockwellautomation (CVE-2026-9127)
CVE-2026-15265 Path Traversal in c (CVE-2026-15265)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →