脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-37526 |
|
c の脆弱性 (CVE-2026-37526)
c に 脆弱性 (CVE-2026-37526) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-37552 |
|
deserialization に 安全でないデシリアライゼーション (CVE-2026-37552)
deserialization に 脆弱性 (CVE-2026-37552) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-42477 |
|
dos の脆弱性 (CVE-2026-42477)
dos に 脆弱性 (CVE-2026-42477) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-31780 |
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix u8...
In the Linux kernel, the following vulnerability has been resolved:
wifi: wilc1000: fix u8...
|
| CVE-2026-31773 |
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: SMP: derive legacy responder STK authentication from MITM state
The legacy responder path in smp_random() currently lab...
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: SMP: derive legacy responder STK authentication from MITM state
The legacy responder path in smp_random() currently labels the stored
STK as authenticated whenever pending_sec_level is BT_SECURITY_HIGH.
That reflects wh...
|
| CVE-2026-31772 |
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: fix...
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: fix...
|
| CVE-2026-5656 |
|
path-traversal に パストラバーサル (CVE-2026-5656)
path-traversal に パストラバーサル (CVE-2026-5656) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-5405 |
|
dos の脆弱性 (CVE-2026-5405)
dos に 脆弱性 (CVE-2026-5405) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-5403 |
|
dos の脆弱性 (CVE-2026-5403)
dos に 脆弱性 (CVE-2026-5403) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-31431 KEV |
|
【KEV】Linux redhat の脆弱性 (CVE-2026-31431)
Linux redhat に 脆弱性 (CVE-2026-31431) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
|
| CVE-2026-40912 |
|
github.com/traefik/traefik/v3 に パストラバーサル (CVE-2026-40912)
github.com/traefik/traefik/v3 に パストラバーサル (CVE-2026-40912) が存在。機密情報が外部に流出する可能性があります。対策: `3.6.14, 3.7.0-rc.2` 以上に更新。
|
| CVE-2026-33845 |
|
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero...
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero...
|
| CVE-2026-36960 |
|
csrf に CSRF (CVE-2026-36960)
csrf に 脆弱性 (CVE-2026-36960) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2025-14576 |
|
dos の脆弱性 (CVE-2025-14576)
dos に 脆弱性 (CVE-2025-14576) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-36956 |
|
csrf に CSRF (CVE-2026-36956)
csrf に 脆弱性 (CVE-2026-36956) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-36957 |
|
dos の脆弱性 (CVE-2026-36957)
dos に 脆弱性 (CVE-2026-36957) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-5402 |
|
dos の脆弱性 (CVE-2026-5402)
dos に 脆弱性 (CVE-2026-5402) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-41940 KEV |
|
【KEV】Webpros cpanel-whm-and-wp2-wordpress-squared の脆弱性 (CVE-2026-41940)
Webpros cpanel-whm-and-wp2-wordpress-squared に 脆弱性 (CVE-2026-41940) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
|
| CVE-2026-44015 |
|
github.com/0xJacky/Nginx-UI に SSRF (サーバー側リクエスト偽造) (CVE-2026-44015)
github.com/0xJacky/Nginx-UI に SSRF (CVE-2026-44015) が存在。機密情報が外部に流出する可能性があります。`GET /api/settings` 経由で攻撃可能。
|
| CVE-2026-37555 |
|
dos の脆弱性 (CVE-2026-37555)
dos に 脆弱性 (CVE-2026-37555) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-6849 |
|
Improper neutralization of special elements used in an OS command ('OS command injection')...
Improper neutralization of special elements used in an OS command ('OS command injection')...
|
| CVE-2026-42198 |
|
dos の脆弱性 (CVE-2026-42198)
dos に 脆弱性 (CVE-2026-42198) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-5141 |
|
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment...
Improper Privilege Management, Improper Access Control, Incorrect privilege assignment...
|
| CVE-2026-41952 |
|
privilege-escalation の脆弱性 (CVE-2026-41952)
privilege-escalation に 脆弱性 (CVE-2026-41952) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-41220 |
|
privilege-escalation に 境界外書き込み (CVE-2026-41220)
privilege-escalation に 境界外書き込み (CVE-2026-41220) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-5140 |
|
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM...
Improper neutralization of CRLF sequences ('CRLF injection') vulnerability in TUBITAK BILGEM...
|
| CVE-2026-42615 |
|
CVE-2026-42615 に クロスサイトスクリプティング (CVE-2026-42615)
CVE-2026-42615 に XSS (クロスサイトスクリプティング) (CVE-2026-42615) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7355 |
|
Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Use after free in Media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
|
| CVE-2026-7356 |
|
Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Use after free in Navigation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7358 |
|
Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Animation in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7359 |
|
Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch...
Use after free in ANGLE in Google Chrome prior to 147.0.7727.138 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7361 |
|
Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Use after free in iOS in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
|
| CVE-2026-7348 |
|
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in Codecs in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7335 |
|
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in media in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7336 |
|
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
| CVE-2026-7319 |
|
path-traversal に パストラバーサル (CVE-2026-7319)
path-traversal に パストラバーサル (CVE-2026-7319) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7314 |
|
path-traversal に パストラバーサル (CVE-2026-7314)
path-traversal に パストラバーサル (CVE-2026-7314) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7315 |
|
path-traversal に パストラバーサル (CVE-2026-7315)
path-traversal に パストラバーサル (CVE-2026-7315) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-42432 |
|
openclaw の脆弱性 (CVE-2026-42432)
openclaw に 脆弱性 (CVE-2026-42432) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``openclaw`` 経由で攻撃可能。対策: `2026.4.8` 以上に更新。
|
| CVE-2026-42429 |
|
openclaw に 権限昇格 (CVE-2026-42429)
openclaw に 脆弱性 (CVE-2026-42429) が存在。データの不正な改ざんを許す可能性があります。``operator.read`` 経由で攻撃可能。対策: `2026.4.8` 以上に更新。
|
| CVE-2026-38949 |
|
CVE-2026-38949 に クロスサイトスクリプティング (CVE-2026-38949)
CVE-2026-38949 に XSS (クロスサイトスクリプティング) (CVE-2026-38949) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-38651 |
|
github.com/gravitl/netmaker の脆弱性 (CVE-2026-38651)
github.com/gravitl/netmaker に 脆弱性 (CVE-2026-38651) が存在。機密情報が外部に流出する可能性があります。``VerifyHostToken`` 経由で攻撃可能。対策: `1.5.0` 以上に更新。
|
| CVE-2026-7216 |
|
path-traversal に パストラバーサル (CVE-2026-7216)
path-traversal に パストラバーサル (CVE-2026-7216) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7212 |
|
notes-mcp に パストラバーサル (CVE-2026-7212)
notes-mcp に パストラバーサル (CVE-2026-7212) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7213 |
|
path-traversal に パストラバーサル (CVE-2026-7213)
path-traversal に パストラバーサル (CVE-2026-7213) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7214 |
|
path-traversal に パストラバーサル (CVE-2026-7214)
path-traversal に パストラバーサル (CVE-2026-7214) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7206 |
|
sqlite-mcp の脆弱性 (CVE-2026-7206)
sqlite-mcp に 脆弱性 (CVE-2026-7206) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7205 |
|
path-traversal に パストラバーサル (CVE-2026-7205)
path-traversal に パストラバーサル (CVE-2026-7205) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-7199 |
|
sqli の脆弱性 (CVE-2026-7199)
sqli に 脆弱性 (CVE-2026-7199) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-41371 |
|
openclaw の脆弱性 (CVE-2026-41371)
openclaw に 脆弱性 (CVE-2026-41371) が存在。データの不正な改ざんを許す可能性があります。``chat.send`` 経由で攻撃可能。対策: `>= 2026.3.28` 以上に更新。
|