脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: グループ: products クリア
ID タイトル
CVE-2026-55568 guzzlehttp/guzzle の脆弱性 (CVE-2026-55568)
guzzlehttp/guzzle に 脆弱性 (CVE-2026-55568) が存在。機密情報が外部に流出する可能性があります。``proxy`` 経由で攻撃可能。対策: `7.12.1` 以上に更新。
CVE-2026-8713 wordpress に パストラバーサル (CVE-2026-8713)
wordpress に パストラバーサル (CVE-2026-8713) が存在。データの不正な改ざんを許す可能性があります。
CVE-2026-54414 path-traversal に パストラバーサル (CVE-2026-54414)
path-traversal に パストラバーサル (CVE-2026-54414) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `3.16.0` 以上に更新。
CVE-2026-8118 wordpress の脆弱性 (CVE-2026-8118)
wordpress に 脆弱性 (CVE-2026-8118) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-7515 wordpress の脆弱性 (CVE-2026-7515)
wordpress に 脆弱性 (CVE-2026-7515) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``doc_style`` 経由で攻撃可能。
CVE-2026-49257 mcp-pinot-server の脆弱性 (CVE-2026-49257)
mcp-pinot-server に 脆弱性 (CVE-2026-49257) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`Authorization header` 経由で攻撃可能。対策: `3.1.0` 以上に更新。
CVE-2026-56022 webmin の脆弱性 (CVE-2026-56022)
webmin に 脆弱性 (CVE-2026-56022) が存在。不正な操作・情報露出のリスクがあります。対策: `2.641` 以上に更新。
CVE-2026-56021 webmin の脆弱性 (CVE-2026-56021)
webmin に 脆弱性 (CVE-2026-56021) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-54419 sqli に SQLインジェクション (CVE-2026-54419)
sqli に SQLインジェクション (CVE-2026-54419) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-40455 sqli に SQLインジェクション (CVE-2026-40455)
sqli に SQLインジェクション (CVE-2026-40455) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-40457 CVE-2026-40457 に クロスサイトスクリプティング (CVE-2026-40457)
CVE-2026-40457 に XSS (クロスサイトスクリプティング) (CVE-2026-40457) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-55746 cotonti/cotonti に クロスサイトスクリプティング (CVE-2026-55746)
cotonti/cotonti に XSS (クロスサイトスクリプティング) (CVE-2026-55746) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-55745 cotonti/cotonti に CSRF (CVE-2026-55745)
cotonti/cotonti に 脆弱性 (CVE-2026-55745) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-9815 wordpress の脆弱性 (CVE-2026-9815)
wordpress に 脆弱性 (CVE-2026-9815) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-55742 cotonti/cotonti に CSRF (CVE-2026-55742)
cotonti/cotonti に 脆弱性 (CVE-2026-55742) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-55744 cotonti/cotonti に CSRF (CVE-2026-55744)
cotonti/cotonti に 脆弱性 (CVE-2026-55744) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-55741 csrf に CSRF (CVE-2026-55741)
csrf に 脆弱性 (CVE-2026-55741) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-9860 wordpress に 危険なファイルアップロード (CVE-2026-9860)
wordpress に 脆弱性 (CVE-2026-9860) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-55740 sqli に SQLインジェクション (CVE-2026-55740)
sqli に SQLインジェクション (CVE-2026-55740) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-48820 cakephp/cakephp に パストラバーサル (CVE-2026-48820)
cakephp/cakephp に パストラバーサル (CVE-2026-48820) が存在。不正な操作・情報露出のリスクがあります。対策: `4.5.11` 以上に更新。
CVE-2026-12529 CVE-2026-12529 の脆弱性 (CVE-2026-12529)
CVE-2026-12529 に 脆弱性 (CVE-2026-12529) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-11407 pimcore/pimcore の脆弱性 (CVE-2026-11407)
pimcore/pimcore に 脆弱性 (CVE-2026-11407) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-10741 sonatype に 認可不備 (CVE-2026-10741)
sonatype に 脆弱性 (CVE-2026-10741) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-48979 php-standard-library/h2 の脆弱性 (CVE-2026-48979)
php-standard-library/h2 に 脆弱性 (CVE-2026-48979) が存在。データの不正な改ざんを許す可能性があります。``StreamException`` 経由で攻撃可能。対策: `6.2.1` 以上に更新。
CVE-2026-48822 CVE-2026-48822 に クロスサイトスクリプティング (CVE-2026-48822)
CVE-2026-48822 に XSS (クロスサイトスクリプティング) (CVE-2026-48822) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-55450 langflow に 情報漏洩 (CVE-2026-55450)
langflow に 脆弱性 (CVE-2026-55450) が存在。不正な操作・情報露出のリスクがあります。`POST /api/v1/upload/{flow_id}` 経由で攻撃可能。対策: `1.9.1` 以上に更新。
CVE-2026-20190 cisco の脆弱性 (CVE-2026-20190)
cisco に 脆弱性 (CVE-2026-20190) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-54415 CVE-2026-54415 に 権限昇格 (CVE-2026-54415)
CVE-2026-54415 に 脆弱性 (CVE-2026-54415) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-49108 Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
CVE-2026-49268 org.apache.shiro:shiro-core の脆弱性 (CVE-2026-49268)
org.apache.shiro:shiro-core に 脆弱性 (CVE-2026-49268) が存在。機密情報が外部に流出する可能性があります。対策: `3.0.0-alpha-2` 以上に更新。
CVE-2026-54814 CVE-2026-54814 の脆弱性 (CVE-2026-54814)
CVE-2026-54814 に 脆弱性 (CVE-2026-54814) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-40757 Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
CVE-2026-40733 Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
CVE-2026-40752 Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
CVE-2026-40756 Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
CVE-2026-39576 Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
CVE-2026-39560 Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
CVE-2026-39445 Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
CVE-2026-40738 Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
CVE-2025-69130 wordpress に 安全でないデシリアライゼーション (CVE-2025-69130)
wordpress に 脆弱性 (CVE-2025-69130) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-39442 Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
CVE-2026-39556 Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
CVE-2025-69111 Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
CVE-2025-69127 Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
CVE-2026-54194 Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
CVE-2026-52706 Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
CVE-2026-54806 Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
CVE-2026-50203 apache-airflow-providers-sftp に パストラバーサル (CVE-2026-50203)
apache-airflow-providers-sftp に パストラバーサル (CVE-2026-50203) が存在。機密情報が外部に流出する可能性があります。``SFTPHook.retrieve_directory`` 経由で攻撃可能。対策: `5.8.1` 以上に更新。
CVE-2026-47340 org.apache.dolphinscheduler:dolphinscheduler-api に 情報漏洩 (CVE-2026-47340)
org.apache.dolphinscheduler:dolphinscheduler-api に 脆弱性 (CVE-2026-47340) が存在。機密情報が外部に流出する可能性があります。対策: `3.4.2` 以上に更新。
CVE-2026-49107 Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →