脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: グループ: attack-types クリア
ID タイトル
CVE-2026-71279 CVE-2026-71279 に パストラバーサル (CVE-2026-71279)
CVE-2026-71279 に パストラバーサル (CVE-2026-71279) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``name`` 経由で攻撃可能。
CVE-2026-71281 Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines...
CVE-2026-71276 sqli に SQLインジェクション (CVE-2026-71276)
sqli に SQLインジェクション (CVE-2026-71276) が存在。機密情報が外部に流出する可能性があります。``format`` 経由で攻撃可能。
CVE-2026-71280 go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL...
CVE-2026-71268 CVE-2026-71268 に パストラバーサル (CVE-2026-71268)
CVE-2026-71268 に パストラバーサル (CVE-2026-71268) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71269 CVE-2026-71269 に パストラバーサル (CVE-2026-71269)
CVE-2026-71269 に パストラバーサル (CVE-2026-71269) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /library/` 経由で攻撃可能。
CVE-2026-71271 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate...
CVE-2026-71273 c に CSRF (CVE-2026-71273)
c に 脆弱性 (CVE-2026-71273) が存在。データの不正な改ざんを許す可能性があります。``web_admin_password_enabled`` 経由で攻撃可能。
CVE-2026-71272 Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the...
CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated...
CVE-2026-71262 path-traversal の脆弱性 (CVE-2026-71262)
path-traversal に 脆弱性 (CVE-2026-71262) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71259 ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
CVE-2026-71227 dos の脆弱性 (CVE-2026-71227)
dos に 脆弱性 (CVE-2026-71227) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-71254 c に 境界外書き込み (CVE-2026-71254)
c に 境界外書き込み (CVE-2026-71254) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-18933 wordpress に 危険なファイルアップロード (CVE-2026-18933)
wordpress に 脆弱性 (CVE-2026-18933) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71239 django の脆弱性 (CVE-2026-71239)
django に 脆弱性 (CVE-2026-71239) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-71238 django の脆弱性 (CVE-2026-71238)
django に 脆弱性 (CVE-2026-71238) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-71248 sqli に SQLインジェクション (CVE-2026-71248)
sqli に SQLインジェクション (CVE-2026-71248) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71250 ssrf に SSRF (サーバー側リクエスト偽造) (CVE-2026-71250)
ssrf に SSRF (CVE-2026-71250) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-71246 ssrf に SSRF (サーバー側リクエスト偽造) (CVE-2026-71246)
ssrf に SSRF (CVE-2026-71246) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-71249 CVE-2026-71249 に クロスサイトスクリプティング (CVE-2026-71249)
CVE-2026-71249 に XSS (クロスサイトスクリプティング) (CVE-2026-71249) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-71237 sqli に SQLインジェクション (CVE-2026-71237)
sqli に SQLインジェクション (CVE-2026-71237) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /userlogin` 経由で攻撃可能。
CVE-2026-71235 ssrf に コードインジェクション (CVE-2026-71235)
ssrf に コードインジェクション (CVE-2026-71235) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71236 CVE-2026-71236 に クロスサイトスクリプティング (CVE-2026-71236)
CVE-2026-71236 に XSS (クロスサイトスクリプティング) (CVE-2026-71236) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-71233 laravel に クロスサイトスクリプティング (CVE-2026-71233)
laravel に XSS (クロスサイトスクリプティング) (CVE-2026-71233) が存在。機密情報が外部に流出する可能性があります。`PUT /api/v1/invoices/{id}` 経由で攻撃可能。
CVE-2026-60009 eclipse に パストラバーサル (CVE-2026-60009)
eclipse に パストラバーサル (CVE-2026-60009) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /file-upload` 経由で攻撃可能。
CVE-2026-71232 CVE-2026-71232 に コードインジェクション (CVE-2026-71232)
CVE-2026-71232 に コードインジェクション (CVE-2026-71232) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-66747 CVE-2026-66747 の脆弱性 (CVE-2026-66747)
CVE-2026-66747 に 脆弱性 (CVE-2026-66747) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-71231 sqli に SQLインジェクション (CVE-2026-71231)
sqli に SQLインジェクション (CVE-2026-71231) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-15452 wordpress に クロスサイトスクリプティング (CVE-2026-15452)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-15452) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-44945 privilege-escalation の脆弱性 (CVE-2026-44945)
privilege-escalation に 脆弱性 (CVE-2026-44945) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-10090 privilege-escalation の脆弱性 (CVE-2026-10090)
privilege-escalation に 脆弱性 (CVE-2026-10090) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-10059 privilege-escalation の脆弱性 (CVE-2026-10059)
privilege-escalation に 脆弱性 (CVE-2026-10059) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-8029 sqli に SQLインジェクション (CVE-2026-8029)
sqli に SQLインジェクション (CVE-2026-8029) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-7441 wordpress に クロスサイトスクリプティング (CVE-2026-7441)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-7441) が存在。不正な操作・情報露出のリスクがあります。``posttype`` 経由で攻撃可能。
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-71215 art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by...
CVE-2026-71209 audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated...
CVE-2026-71211 ssrf に SSRF (サーバー側リクエスト偽造) (CVE-2026-71211)
ssrf に SSRF (CVE-2026-71211) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-71210 ssrf の脆弱性 (CVE-2026-71210)
ssrf に 脆弱性 (CVE-2026-71210) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-71206 Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-70376 csrf に CSRF (CVE-2026-70376)
csrf に 脆弱性 (CVE-2026-70376) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`Referer header` 経由で攻撃可能。
CVE-2026-6972 wordpress に クロスサイトスクリプティング (CVE-2026-6972)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-6972) が存在。不正な操作・情報露出のリスクがあります。``chart_size`` 経由で攻撃可能。
CVE-2026-5581 wordpress の脆弱性 (CVE-2026-5581)
wordpress に 脆弱性 (CVE-2026-5581) が存在。データの不正な改ざんを許す可能性があります。``wp_ajax_nopriv_gfmu_delete_file`` 経由で攻撃可能。
CVE-2026-5651 wordpress に SQLインジェクション (CVE-2026-5651)
wordpress に SQLインジェクション (CVE-2026-5651) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-61484 apache に 安全でないデシリアライゼーション (CVE-2026-61484)
apache に 脆弱性 (CVE-2026-61484) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-55997 Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user c...
Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in plaintext with no expiration, so a malicious user could obtain one either through the Rancher API, etcd, stored automation, or direct file access on a...

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →