脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2022-50998 |
|
dos の脆弱性 (CVE-2022-50998)
dos に 脆弱性 (CVE-2022-50998) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2022-50999 |
|
dos に バッファオーバーフロー (CVE-2022-50999)
dos に 脆弱性 (CVE-2022-50999) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2021-47996 |
|
dos に バッファオーバーフロー (CVE-2021-47996)
dos に 脆弱性 (CVE-2021-47996) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2023-54354 |
|
dos の脆弱性 (CVE-2023-54354)
dos に 脆弱性 (CVE-2023-54354) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-79655 |
|
path-traversal の脆弱性 (CVE-2026-79655)
path-traversal に 脆弱性 (CVE-2026-79655) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-79622 |
|
path-traversal に パストラバーサル (CVE-2026-79622)
path-traversal に パストラバーサル (CVE-2026-79622) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-18798 |
|
dos の脆弱性 (CVE-2026-18798)
dos に 脆弱性 (CVE-2026-18798) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-57863 |
|
path-traversal に パストラバーサル (CVE-2026-57863)
path-traversal に パストラバーサル (CVE-2026-57863) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-63072 |
|
dos に 境界外書き込み (CVE-2026-63072)
dos に 境界外書き込み (CVE-2026-63072) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-54874 |
|
dos の脆弱性 (CVE-2026-54874)
dos に 脆弱性 (CVE-2026-54874) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-63075 |
|
dos の脆弱性 (CVE-2026-63075)
dos に 脆弱性 (CVE-2026-63075) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-14457 |
|
dos の脆弱性 (CVE-2026-14457)
dos に 脆弱性 (CVE-2026-14457) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-63076 |
|
dos の脆弱性 (CVE-2026-63076)
dos に 脆弱性 (CVE-2026-63076) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-79658 |
|
dos の脆弱性 (CVE-2026-79658)
dos に 脆弱性 (CVE-2026-79658) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-75971 |
|
wordpress に 権限昇格 (CVE-2026-75971)
wordpress に 脆弱性 (CVE-2026-75971) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``import_start`` 経由で攻撃可能。
|
| CVE-2026-19949 |
|
wordpress に SQLインジェクション (CVE-2026-19949)
wordpress に SQLインジェクション (CVE-2026-19949) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-78576 |
|
wordpress に SQLインジェクション (CVE-2026-78576)
wordpress に SQLインジェクション (CVE-2026-78576) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-78572 |
|
wordpress に 安全でないデシリアライゼーション (CVE-2026-78572)
wordpress に 脆弱性 (CVE-2026-78572) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-75037 |
|
CVE-2026-75037 の脆弱性 (CVE-2026-75037)
CVE-2026-75037 に 脆弱性 (CVE-2026-75037) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-16231 |
|
express に クロスサイトスクリプティング (CVE-2026-16231)
express に XSS (クロスサイトスクリプティング) (CVE-2026-16231) が存在。機密情報が外部に流出する可能性があります。対策: `4.3.0` 以上に更新。
|
| CVE-2026-78563 |
|
wordpress に クロスサイトスクリプティング (CVE-2026-78563)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-78563) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-67578 |
|
FA-50 all versions miss authentication for some configuration.
An attacker with access to the...
FA-50 all versions miss authentication for some configuration.
An attacker with access to the...
|
| CVE-2026-16601 |
|
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
|
| CVE-2026-18328 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-18323 |
|
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
|
| CVE-2026-19851 |
|
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17...
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17...
|
| CVE-2026-68062 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-68960 |
|
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager....
|
| CVE-2026-69665 |
|
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If...
|
| CVE-2026-68959 |
|
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
|
| CVE-2026-19892 |
|
wordpress の脆弱性 (CVE-2026-19892)
wordpress に 脆弱性 (CVE-2026-19892) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-78685 |
|
CVE-2026-78685 の脆弱性 (CVE-2026-78685)
CVE-2026-78685 に 脆弱性 (CVE-2026-78685) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-78680 |
|
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot...
|
| CVE-2026-78677 |
|
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing...
|
| CVE-2026-78681 |
|
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which...
|
| CVE-2026-75574 |
|
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
|
| CVE-2026-78675 |
|
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing...
|
| CVE-2026-72696 |
|
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job:...
|
| CVE-2026-72695 |
|
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that...
|
| CVE-2026-56703 |
|
CVE-2026-56703 に コードインジェクション (CVE-2026-56703)
CVE-2026-56703 に コードインジェクション (CVE-2026-56703) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-56707 |
|
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass...
|
| CVE-2026-56702 |
|
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the...
|
| CVE-2026-34968 |
|
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the...
|
| CVE-2026-66766 |
|
dos の脆弱性 (CVE-2026-66766)
dos に 脆弱性 (CVE-2026-66766) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-78282 |
|
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
|
| CVE-2026-78264 |
|
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
|
| CVE-2026-78263 |
|
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
|
| CVE-2026-77384 |
|
dos の脆弱性 (CVE-2026-77384)
dos に 脆弱性 (CVE-2026-77384) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-32561 |
|
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
|
| CVE-2026-32556 |
|
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
|