脆弱性一覧
CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。
| ID | タイトル | |
|---|---|---|
| CVE-2026-42487 |
|
c の脆弱性 (CVE-2026-42487)
c に 脆弱性 (CVE-2026-42487) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-54695 |
|
pipecat-ai の脆弱性 (CVE-2026-54695)
pipecat-ai に 脆弱性 (CVE-2026-54695) が存在。不正な操作・情報露出のリスクがあります。`POST /start` 経由で攻撃可能。対策: `1.4.0` 以上に更新。
|
| CVE-2026-65898 |
|
dompurify に クロスサイトスクリプティング (CVE-2026-65898)
dompurify に XSS (クロスサイトスクリプティング) (CVE-2026-65898) が存在。不正な操作・情報露出のリスクがあります。``uponSanitizeAttribute`` 経由で攻撃可能。対策: `3.4.11` 以上に更新。
|
| CVE-2026-55603 |
|
http-proxy-middleware の脆弱性 (CVE-2026-55603)
http-proxy-middleware に 脆弱性 (CVE-2026-55603) が存在。データの不正な改ざんを許す可能性があります。``req.body`` 経由で攻撃可能。対策: `4.1.1` 以上に更新。
|
| CVE-2026-55602 |
|
http-proxy-middleware の脆弱性 (CVE-2026-55602)
http-proxy-middleware に 脆弱性 (CVE-2026-55602) が存在。データの不正な改ざんを許す可能性があります。``router`` 経由で攻撃可能。対策: `2.0.10` 以上に更新。
|
| CVE-2026-55388 |
|
piscina の脆弱性 (CVE-2026-55388)
piscina に 脆弱性 (CVE-2026-55388) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /upload` 経由で攻撃可能。対策: `6.0.0-rc.2` 以上に更新。
|
| CVE-2026-55746 |
|
cotonti/cotonti に クロスサイトスクリプティング (CVE-2026-55746)
cotonti/cotonti に XSS (クロスサイトスクリプティング) (CVE-2026-55746) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-55744 |
|
cotonti/cotonti に CSRF (CVE-2026-55744)
cotonti/cotonti に 脆弱性 (CVE-2026-55744) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-55741 |
|
csrf に CSRF (CVE-2026-55741)
csrf に 脆弱性 (CVE-2026-55741) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-9860 |
|
wordpress に 危険なファイルアップロード (CVE-2026-9860)
wordpress に 脆弱性 (CVE-2026-9860) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-50200 |
|
Steeltoe.Management.Endpoint に 情報漏洩 (CVE-2026-50200)
Steeltoe.Management.Endpoint に 脆弱性 (CVE-2026-50200) が存在。機密情報が外部に流出する可能性があります。``Sanitizer`` 経由で攻撃可能。対策: `4.2.0` 以上に更新。
|
| CVE-2026-50196 |
|
Steeltoe.Discovery.Eureka の脆弱性 (CVE-2026-50196)
Steeltoe.Discovery.Eureka に 脆弱性 (CVE-2026-50196) が存在。不正な操作・情報露出のリスクがあります。``DataCenterInfo.FromJson`` 経由で攻撃可能。対策: `3.4.0` 以上に更新。
|
| CVE-2026-48997 |
|
c に OSコマンドインジェクション (CVE-2026-48997)
c に OSコマンドインジェクション (CVE-2026-48997) が存在。データの不正な改ざんを許す可能性があります。
|
| CVE-2026-50194 |
|
Steeltoe.Management.Endpoint の脆弱性 (CVE-2026-50194)
Steeltoe.Management.Endpoint に 脆弱性 (CVE-2026-50194) が存在。機密情報が外部に流出する可能性があります。``Host`` 経由で攻撃可能。対策: `4.2.0` 以上に更新。
|
| CVE-2026-12529 |
|
CVE-2026-12529 の脆弱性 (CVE-2026-12529)
CVE-2026-12529 に 脆弱性 (CVE-2026-12529) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-11407 |
|
pimcore/pimcore の脆弱性 (CVE-2026-11407)
pimcore/pimcore に 脆弱性 (CVE-2026-11407) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-12530 |
|
Amazon bedrock-agentcore の脆弱性 (CVE-2026-12530)
Amazon bedrock-agentcore に 脆弱性 (CVE-2026-12530) が存在。機密情報が外部に流出する可能性があります。対策: `1.6.1` 以上に更新。
|
| CVE-2026-48979 |
|
php-standard-library/h2 の脆弱性 (CVE-2026-48979)
php-standard-library/h2 に 脆弱性 (CVE-2026-48979) が存在。データの不正な改ざんを許す可能性があります。``StreamException`` 経由で攻撃可能。対策: `6.2.1` 以上に更新。
|
| CVE-2026-55470 |
|
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 の脆弱性 (CVE-2026-55470)
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 に 脆弱性 (CVE-2026-55470) が存在。不正な操作・情報露出のリスクがあります。``RegexTimeout`` 経由で攻撃可能。対策: `6.9.10` 以上に更新。
|
| CVE-2026-55760 |
|
com.github.jknack:handlebars に パストラバーサル (CVE-2026-55760)
com.github.jknack:handlebars に パストラバーサル (CVE-2026-55760) が存在。機密情報が外部に流出する可能性があります。対策: `4.5.2` 以上に更新。
|
| CVE-2026-55409 |
|
filament/forms に クロスサイトスクリプティング (CVE-2026-55409)
filament/forms に XSS (クロスサイトスクリプティング) (CVE-2026-55409) が存在。機密情報が外部に流出する可能性があります。``RichEditor`` 経由で攻撃可能。対策: `3.3.53` 以上に更新。
|
| CVE-2026-55405 |
|
dev.langchain4j:langchain4j-mariadb に SQLインジェクション (CVE-2026-55405)
dev.langchain4j:langchain4j-mariadb に SQLインジェクション (CVE-2026-55405) が存在。機密情報が外部に流出する可能性があります。``COMBINED_JSON`` 経由で攻撃可能。対策: `1.16.3-beta26` 以上に更新。
|
| CVE-2025-26240 |
|
pdfkit の脆弱性 (CVE-2025-26240)
pdfkit に 脆弱性 (CVE-2025-26240) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-54415 |
|
CVE-2026-54415 に 権限昇格 (CVE-2026-54415)
CVE-2026-54415 に 脆弱性 (CVE-2026-54415) が存在。機密情報が外部に流出する可能性があります。
|
| CVE-2026-55738 |
|
c の脆弱性 (CVE-2026-55738)
c に 脆弱性 (CVE-2026-55738) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-54417 |
|
c の脆弱性 (CVE-2026-54417)
c に 脆弱性 (CVE-2026-54417) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-54814 |
|
CVE-2026-54814 の脆弱性 (CVE-2026-54814)
CVE-2026-54814 に 脆弱性 (CVE-2026-54814) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-39445 |
|
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
|
| CVE-2026-40738 |
|
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
|
| CVE-2025-69130 |
|
wordpress に 安全でないデシリアライゼーション (CVE-2025-69130)
wordpress に 脆弱性 (CVE-2025-69130) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
|
| CVE-2026-39442 |
|
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
|
| CVE-2026-39556 |
|
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
|
| CVE-2026-40757 |
|
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
|
| CVE-2026-39560 |
|
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
|
| CVE-2026-40733 |
|
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
|
| CVE-2026-40752 |
|
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
|
| CVE-2026-39576 |
|
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
|
| CVE-2026-40756 |
|
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
|
| CVE-2026-9570 |
|
wordpress に クロスサイトスクリプティング (CVE-2026-9570)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-9570) が存在。不正な操作・情報露出のリスクがあります。
|
| CVE-2026-40736 |
|
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
|
| CVE-2026-40753 |
|
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
|
| CVE-2026-40751 |
|
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
|
| CVE-2026-40754 |
|
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
|
| CVE-2026-40735 |
|
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
|
| CVE-2026-40760 |
|
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
|
| CVE-2026-40758 |
|
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
|
| CVE-2026-40755 |
|
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
|
| CVE-2026-40739 |
|
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
|
| CVE-2026-40761 |
|
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
|
| CVE-2026-40759 |
|
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
|