脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: グループ: attack-types クリア
ID タイトル
CVE-2016-20066 wordpress に クロスサイトスクリプティング (CVE-2016-20066)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2016-20066) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-50100 jvn の脆弱性 (CVE-2026-50100)
jvn に 脆弱性 (CVE-2026-50100) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-12198 microweber/microweber に パストラバーサル (CVE-2026-12198)
microweber/microweber に パストラバーサル (CVE-2026-12198) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-12191 deserialization の脆弱性 (CVE-2026-12191)
deserialization に 脆弱性 (CVE-2026-12191) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-12187 CVE-2026-12187 の脆弱性 (CVE-2026-12187)
CVE-2026-12187 に 脆弱性 (CVE-2026-12187) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-54410 dos の脆弱性 (CVE-2026-54410)
dos に 脆弱性 (CVE-2026-54410) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-6428 sqli に SQLインジェクション (CVE-2026-6428)
sqli に SQLインジェクション (CVE-2026-6428) が存在。機密情報が外部に流出する可能性があります。`GET /cgi-bin/koha/reports/catalogue_out.pl` 経由で攻撃可能。
CVE-2026-5513 wordpress に クロスサイトスクリプティング (CVE-2026-5513)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-5513) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-9109 wordpress に クロスサイトスクリプティング (CVE-2026-9109)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-9109) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-11769 github.com/grafana/grafana-operator に 情報漏洩 (CVE-2026-11769)
github.com/grafana/grafana-operator に 脆弱性 (CVE-2026-11769) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``Dashboard`` 経由で攻撃可能。対策: `5.24.0` 以上に更新。
CVE-2026-9848 wordpress に SQLインジェクション (CVE-2026-9848)
wordpress に SQLインジェクション (CVE-2026-9848) が存在。機密情報が外部に流出する可能性があります。``posts_request`` 経由で攻撃可能。
CVE-2025-14098 dos の脆弱性 (CVE-2025-14098)
dos に 脆弱性 (CVE-2025-14098) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-53868 dos の脆弱性 (CVE-2026-53868)
dos に 脆弱性 (CVE-2026-53868) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-53823 openclaw の脆弱性 (CVE-2026-53823)
openclaw に 脆弱性 (CVE-2026-53823) が存在。機密情報が外部に流出する可能性があります。対策: `2026.5.3` 以上に更新。
CVE-2026-53608 @apostrophecms/seo に クロスサイトスクリプティング (CVE-2026-53608)
@apostrophecms/seo に XSS (クロスサイトスクリプティング) (CVE-2026-53608) が存在。機密情報が外部に流出する可能性があります。``seoGoogleTrackingId`` 経由で攻撃可能。対策: `1.5.0` 以上に更新。
CVE-2026-4870 dos の脆弱性 (CVE-2026-4870)
dos に 脆弱性 (CVE-2026-4870) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-6961 github.com/mattermost/mattermost-server に パストラバーサル (CVE-2026-6961)
github.com/mattermost/mattermost-server に パストラバーサル (CVE-2026-6961) が存在。データの不正な改ざんを許す可能性があります。対策: `10.11.17` 以上に更新。
CVE-2026-3840 path-traversal に パストラバーサル (CVE-2026-3840)
path-traversal に パストラバーサル (CVE-2026-3840) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-50632 org.apache.cxf:cxf-rt-transports-jms の脆弱性 (CVE-2026-50632)
org.apache.cxf:cxf-rt-transports-jms に 脆弱性 (CVE-2026-50632) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `4.1.7` 以上に更新。
CVE-2026-50645 org.apache.cxf:cxf-core の脆弱性 (CVE-2026-50645)
org.apache.cxf:cxf-core に 脆弱性 (CVE-2026-50645) が存在。不正な操作・情報露出のリスクがあります。対策: `3.6.12` 以上に更新。
CVE-2026-45169 dos の脆弱性 (CVE-2026-45169)
dos に 脆弱性 (CVE-2026-45169) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-47368 path-traversal に パストラバーサル (CVE-2026-47368)
path-traversal に パストラバーサル (CVE-2026-47368) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-47366 privilege-escalation の脆弱性 (CVE-2026-47366)
privilege-escalation に 脆弱性 (CVE-2026-47366) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2025-7737 jvn の脆弱性 (CVE-2025-7737)
jvn に 脆弱性 (CVE-2025-7737) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-11933 Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion
CVE-2026-45418 sqli に SQLインジェクション (CVE-2026-45418)
sqli に SQLインジェクション (CVE-2026-45418) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /actions/subtitle_edit.php` 経由で攻撃可能。
CVE-2026-42653 CVE-2026-42653 に クロスサイトスクリプティング (CVE-2026-42653)
CVE-2026-42653 に XSS (クロスサイトスクリプティング) (CVE-2026-42653) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-12018 privilege-escalation に 権限昇格 (CVE-2026-12018)
privilege-escalation に 脆弱性 (CVE-2026-12018) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-53811 openclaw の脆弱性 (CVE-2026-53811)
openclaw に 脆弱性 (CVE-2026-53811) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `2026.5.7` 以上に更新。
CVE-2026-53814 openclaw に 情報漏洩 (CVE-2026-53814)
openclaw に 脆弱性 (CVE-2026-53814) が存在。機密情報が外部に流出する可能性があります。対策: `2026.5.20` 以上に更新。
CVE-2026-53813 openclaw の脆弱性 (CVE-2026-53813)
openclaw に 脆弱性 (CVE-2026-53813) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `2026.4.25` 以上に更新。
CVE-2026-48109 MessagePack の脆弱性 (CVE-2026-48109)
MessagePack に 脆弱性 (CVE-2026-48109) が存在。不正な操作・情報露出のリスクがあります。``Lz4Block`` 経由で攻撃可能。対策: `3.1.7` 以上に更新。
CVE-2025-27511 org.geoserver.extension:gs-db2 の脆弱性 (CVE-2025-27511)
org.geoserver.extension:gs-db2 に 脆弱性 (CVE-2025-27511) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `2.27.0` 以上に更新。
CVE-2026-53782 @steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
@steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
CVE-2026-46622 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any...
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api_tokens database table. Any attacker who obtains read access to the database — through SQL injection, a leaked backup, a misconf...
CVE-2026-46489 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG f...
SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can upload an SVG file containing embedded JavaScript. This script is base64-encoded and injected unescaped into every...
CVE-2026-47170 Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HT...
Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prior to version 1.1, authenticated users can cause the server to issue arbitrary HTTP requests to internal services via the uploadFromUrl endpoint. This allows internal port scanning,...
CVE-2026-45178 dos の脆弱性 (CVE-2026-45178)
dos に 脆弱性 (CVE-2026-45178) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-11774 An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)....
An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base)....
CVE-2025-31272 The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app...
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app...
CVE-2026-48546 CVE-2026-48546 の脆弱性 (CVE-2026-48546)
CVE-2026-48546 に 脆弱性 (CVE-2026-48546) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-46697 wordpress に SSRF (サーバー側リクエスト偽造) (CVE-2026-46697)
wordpress に SSRF (CVE-2026-46697) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-53777 path-traversal に パストラバーサル (CVE-2026-53777)
path-traversal に パストラバーサル (CVE-2026-53777) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-11816 keras に パストラバーサル (CVE-2026-11816)
keras に パストラバーサル (CVE-2026-11816) が存在。機密情報が外部に流出する可能性があります。``AttributeError`` 経由で攻撃可能。対策: `3.14.0` 以上に更新。
CVE-2026-10847 privilege-escalation の脆弱性 (CVE-2026-10847)
privilege-escalation に 脆弱性 (CVE-2026-10847) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-7250 gitlab の脆弱性 (CVE-2026-7250)
gitlab に 脆弱性 (CVE-2026-7250) が存在。不正な操作・情報露出のリスクがあります。対策: `18.10.8, 18.11.5, 19.0.2` 以上に更新。
CVE-2026-5497 vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
vLLM is vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method
CVE-2023-33999 CVE-2023-33999 に クロスサイトスクリプティング (CVE-2023-33999)
CVE-2023-33999 に XSS (クロスサイトスクリプティング) (CVE-2023-33999) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-41699 org.springframework.graphql:spring-graphql に 安全でないデシリアライゼーション (CVE-2026-41699)
org.springframework.graphql:spring-graphql に 脆弱性 (CVE-2026-41699) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-10795 wordpress の脆弱性 (CVE-2026-10795)
wordpress に 脆弱性 (CVE-2026-10795) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →