|
CVE-2026-82475
|
|
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow...
|
High
|
Cwe 862
認証バイパス
|
13時間前
|
|
CVE-2026-82472
|
|
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without...
|
High
|
Cwe 306
リモートコード実行 (RCE)
|
13時間前
|
|
CVE-2026-82466
|
|
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route...
|
High
|
認証バイパス
Cwe 287
Ruby
|
13時間前
|
|
CVE-2026-81421
|
|
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected...
|
High
|
Cwe 918
SSRF (サーバーサイドリクエストフォージェリ)
|
3日前
|
|
CVE-2026-77652
|
|
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format...
|
High
|
C
Cwe 122
バッファオーバーフロー
|
3日前
|
|
CVE-2026-68863
|
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow...
|
High
|
サービス拒否 (DoS)
Cwe 121
バッファオーバーフロー
Denial Of Service
+2
|
3日前
|
|
CVE-2026-68861
|
|
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special...
|
High
|
CWE-78: OSコマンドインジェクション
Os
コマンドインジェクション
Dell
+1
|
3日前
|
|
CVE-2021-23758
KEV
|
|
Remote Code Execution in AjaxNetProfessional
Remote Code Execution in AjaxNetProfessional
|
High
|
CWE-502: 安全でないデシリアライゼーション
リモートコード実行 (RCE)
安全でないデシリアライゼーション
C#
+4
|
4日前
|
|
CVE-2026-18328
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
PHP
|
4日前
|
|
CVE-2026-18323
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
PHP
|
4日前
|
|
CVE-2026-16601
|
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
High
|
JavaScript
WordPress
リモートコード実行 (RCE)
Cwe 434
+1
|
4日前
|
|
CVE-2026-68960
|
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
High
|
Cwe 121
バッファオーバーフロー
Windows
|
4日前
|
|
CVE-2026-78680
|
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
High
|
Cwe 426
Python
リモートコード実行 (RCE)
|
5日前
|
|
CVE-2026-78675
|
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
High
|
Cwe 73
Python
パストラバーサル
|
5日前
|
|
CVE-2026-75574
|
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
High
|
PHP
Cwe 1336
WordPress
リモートコード実行 (RCE)
|
5日前
|
|
CVE-2026-72695
|
|
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
|
High
|
パストラバーサル
CWE-22: パストラバーサル
|
5日前
|
|
CVE-2026-56707
|
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
High
|
Cwe 862
WordPress
PHP
認証バイパス
|
5日前
|
|
CVE-2026-56702
|
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
High
|
PHP
Cwe 434
リモートコード実行 (RCE)
|
5日前
|
|
CVE-2026-34968
|
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
High
|
PHP
C
CWE-22: パストラバーサル
Adminer
+1
|
5日前
|
|
CVE-2026-71506
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API...
|
High
|
Cwe 863
リモートコード実行 (RCE)
Enterprise Saas
|
5日前
|
|
CVE-2026-71504
|
|
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API...
|
High
|
Cwe 862
Cwe 915
PHP
|
5日前
|
|
CVE-2026-40877
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This i...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
|
High
|
PHP
リモートコード実行 (RCE)
CWE-94: コードインジェクション
CWE-502: 安全でないデシリアライゼーション
|
5日前
|
|
CVE-2026-30864
|
|
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in v...
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.
|
High
|
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
5日前
|
|
CVE-2026-78208
|
|
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage()...
|
High
|
JavaScript
パストラバーサル
Cwe 73
|
6日前
|
|
CVE-2026-78161
|
|
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function...
|
High
|
C
CWE-119: メモリの境界外操作
CWE-787: 境界外書き込み
バッファオーバーフロー
|
6日前
|
|
CVE-2026-4671
|
|
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector...
|
High
|
Cwe 400
Denial Of Service
JavaScript
|
6日前
|
|
CVE-2026-30866
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 200
Cwe 306
Web Application
認証バイパス
|
1週間前
|
|
CVE-2026-30819
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboard revert functionality with the parameter dashboard_id in /pages/ajax.render.php. This issue has been fixed in version 3.2.3.
|
High
|
PHP
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
1週間前
|
|
CVE-2026-27490
|
|
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
|
High
|
Cwe 330
Cwe 331
Web Application
認証バイパス
|
1週間前
|
|
CVE-2026-54682
|
|
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and Format...
DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it w...
|
High
|
CWE-79: クロスサイトスクリプティング (XSS)
クロスサイトスクリプティング (XSS)
|
1週間前
|
|
CVE-2026-73197
|
|
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by...
|
High
|
サービス拒否 (DoS)
Cwe 770
Redhat
Enterprise Linux
+1
|
1週間前
|
|
CVE-2026-19905
|
|
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6...
|
High
|
SQLインジェクション
Cwe 74
CWE-89: SQLインジェクション
Sql Injection
|
2週間前
|
|
CVE-2026-14279
|
|
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...
|
High
|
WordPress
権限昇格
Cwe 269
PHP
|
2週間前
|
|
CVE-2026-73680
|
|
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration...
|
High
|
CWE-78: OSコマンドインジェクション
Cockpit
PHP
コマンドインジェクション
|
2週間前
|
|
CVE-2026-19826
|
|
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...
|
High
|
Java
安全でないデシリアライゼーション
CWE-20: 入力検証の不備
CWE-502: 安全でないデシリアライゼーション
|
2週間前
|
|
CVE-2026-19825
|
|
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0....
|
High
|
PHP
SQLインジェクション
Cwe 74
CWE-89: SQLインジェクション
|
2週間前
|
|
CVE-2026-19794
|
|
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
PHP
|
2週間前
|
|
CVE-2026-19764
|
|
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform...
|
High
|
PHP
SQLインジェクション
Cwe 74
CWE-89: SQLインジェクション
+2
|
2週間前
|
|
CVE-2026-19762
|
|
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function...
|
High
|
Java
パストラバーサル
CWE-22: パストラバーサル
|
2週間前
|
|
CVE-2026-19758
|
|
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
|
High
|
Java
パストラバーサル
CWE-22: パストラバーサル
|
2週間前
|
|
CVE-2026-19757
|
|
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown...
|
High
|
Java
パストラバーサル
CWE-22: パストラバーサル
|
2週間前
|
|
CVE-2026-73654
|
|
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
|
High
|
サービス拒否 (DoS)
Cwe 1321
リモートコード実行 (RCE)
npm
+1
|
2週間前
|
|
CVE-2026-72777
|
|
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST ...
|
High
|
Cwe 918
SSRF (サーバーサイドリクエストフォージェリ)
|
2週間前
|
|
CVE-2026-18146
|
|
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin...
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
PHP
|
2週間前
|
|
CVE-2026-73031
|
|
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers...
|
High
|
JavaScript
Vue.js
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
|
2週間前
|
|
CVE-2026-73222
|
|
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
|
High
|
JavaScript
CWE-78: OSコマンドインジェクション
Cwe 306
Cwe 352
+2
|
2週間前
|
|
CVE-2026-15426
|
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress...
|
High
|
WordPress
Cwe 269
PHP
認証バイパス
|
2週間前
|
|
CVE-2026-67620
|
|
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard...
|
High
|
SSRF (サーバーサイドリクエストフォージェリ)
Cwe 918
|
3週間前
|
|
CVE-2026-48026
|
|
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI render...
lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write ac...
|
High
|
JavaScript
CWE-79: クロスサイトスクリプティング (XSS)
クロスサイトスクリプティング (XSS)
|
3週間前
|
|
CVE-2026-18325
|
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
High
|
WordPress
クロスサイトスクリプティング (XSS)
CWE-79: クロスサイトスクリプティング (XSS)
PHP
|
3週間前
|