脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: グループ: vendors クリア
ID タイトル
CVE-2026-11719 github.com/googleapis/mcp-toolbox の脆弱性 (CVE-2026-11719)
github.com/googleapis/mcp-toolbox に 脆弱性 (CVE-2026-11719) が存在。機密情報が外部に流出する可能性があります。対策: `1.4.0` 以上に更新。
CVE-2026-55746 cotonti/cotonti に クロスサイトスクリプティング (CVE-2026-55746)
cotonti/cotonti に XSS (クロスサイトスクリプティング) (CVE-2026-55746) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-55741 csrf に CSRF (CVE-2026-55741)
csrf に 脆弱性 (CVE-2026-55741) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-55744 cotonti/cotonti に CSRF (CVE-2026-55744)
cotonti/cotonti に 脆弱性 (CVE-2026-55744) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-11395 wordpress に SSRF (サーバー側リクエスト偽造) (CVE-2026-11395)
wordpress に SSRF (CVE-2026-11395) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-9860 wordpress に 危険なファイルアップロード (CVE-2026-9860)
wordpress に 脆弱性 (CVE-2026-9860) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-12407 wordpress の脆弱性 (CVE-2026-12407)
wordpress に 脆弱性 (CVE-2026-12407) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-50196 Steeltoe.Discovery.Eureka の脆弱性 (CVE-2026-50196)
Steeltoe.Discovery.Eureka に 脆弱性 (CVE-2026-50196) が存在。不正な操作・情報露出のリスクがあります。``DataCenterInfo.FromJson`` 経由で攻撃可能。対策: `3.4.0` 以上に更新。
CVE-2026-50107 nginx-gateway-fabric の脆弱性 (CVE-2026-50107)
nginx-gateway-fabric に 脆弱性 (CVE-2026-50107) が存在。機密情報が外部に流出する可能性があります。対策: `2.6.4` 以上に更新。
CVE-2026-11407 pimcore/pimcore の脆弱性 (CVE-2026-11407)
pimcore/pimcore に 脆弱性 (CVE-2026-11407) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-12529 CVE-2026-12529 の脆弱性 (CVE-2026-12529)
CVE-2026-12529 に 脆弱性 (CVE-2026-12529) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-48979 php-standard-library/h2 の脆弱性 (CVE-2026-48979)
php-standard-library/h2 に 脆弱性 (CVE-2026-48979) が存在。データの不正な改ざんを許す可能性があります。``StreamException`` 経由で攻撃可能。対策: `6.2.1` 以上に更新。
CVE-2026-55470 ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 の脆弱性 (CVE-2026-55470)
ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 に 脆弱性 (CVE-2026-55470) が存在。不正な操作・情報露出のリスクがあります。``RegexTimeout`` 経由で攻撃可能。対策: `6.9.10` 以上に更新。
CVE-2026-55760 com.github.jknack:handlebars に パストラバーサル (CVE-2026-55760)
com.github.jknack:handlebars に パストラバーサル (CVE-2026-55760) が存在。機密情報が外部に流出する可能性があります。対策: `4.5.2` 以上に更新。
CVE-2026-55409 filament/forms に クロスサイトスクリプティング (CVE-2026-55409)
filament/forms に XSS (クロスサイトスクリプティング) (CVE-2026-55409) が存在。機密情報が外部に流出する可能性があります。``RichEditor`` 経由で攻撃可能。対策: `3.3.53` 以上に更新。
CVE-2026-55405 dev.langchain4j:langchain4j-mariadb に SQLインジェクション (CVE-2026-55405)
dev.langchain4j:langchain4j-mariadb に SQLインジェクション (CVE-2026-55405) が存在。機密情報が外部に流出する可能性があります。``COMBINED_JSON`` 経由で攻撃可能。対策: `1.16.3-beta26` 以上に更新。
CVE-2026-32652 dell の脆弱性 (CVE-2026-32652)
dell に 脆弱性 (CVE-2026-32652) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-20190 cisco の脆弱性 (CVE-2026-20190)
cisco に 脆弱性 (CVE-2026-20190) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-42530 nginx に 解放後使用 (Use-After-Free) (CVE-2026-42530)
nginx に 脆弱性 (CVE-2026-42530) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-42055 nginx の脆弱性 (CVE-2026-42055)
nginx に 脆弱性 (CVE-2026-42055) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-54415 CVE-2026-54415 に 権限昇格 (CVE-2026-54415)
CVE-2026-54415 に 脆弱性 (CVE-2026-54415) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-49502 dell に 認証バイパス (CVE-2026-49502)
dell に 認証バイパス (CVE-2026-49502) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-35066 dos の脆弱性 (CVE-2026-35066)
dos に 脆弱性 (CVE-2026-35066) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-35065 dos の脆弱性 (CVE-2026-35065)
dos に 脆弱性 (CVE-2026-35065) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-54814 CVE-2026-54814 の脆弱性 (CVE-2026-54814)
CVE-2026-54814 に 脆弱性 (CVE-2026-54814) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-22283 dell の脆弱性 (CVE-2026-22283)
dell に 脆弱性 (CVE-2026-22283) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-32804 dell に 認証バイパス (CVE-2026-32804)
dell に 認証バイパス (CVE-2026-32804) が存在。データの不正な改ざんを許す可能性があります。
CVE-2026-11311 nginx-gateway-fabric の脆弱性 (CVE-2026-11311)
nginx-gateway-fabric に 脆弱性 (CVE-2026-11311) が存在。機密情報が外部に流出する可能性があります。対策: `2.6.4` 以上に更新。
CVE-2026-39556 Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
Unauthenticated PHP Object Injection in Konsept <= 1.9 versions.
CVE-2026-39442 Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions.
CVE-2025-69130 wordpress に 安全でないデシリアライゼーション (CVE-2025-69130)
wordpress に 脆弱性 (CVE-2025-69130) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-40738 Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions.
CVE-2026-39445 Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.
CVE-2026-39560 Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions.
CVE-2026-39576 Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions.
CVE-2026-40756 Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
Unauthenticated PHP Object Injection in Zoya <= 1.4 versions.
CVE-2026-40752 Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions.
CVE-2026-40733 Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions.
CVE-2026-40757 Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Château <= 1.2.1 versions.
CVE-2025-69115 wordpress の脆弱性 (CVE-2025-69115)
wordpress に 脆弱性 (CVE-2025-69115) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-9570 wordpress に クロスサイトスクリプティング (CVE-2026-9570)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-9570) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-8089 wordpress に クロスサイトスクリプティング (CVE-2026-8089)
wordpress に XSS (クロスサイトスクリプティング) (CVE-2026-8089) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-40753 Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
Unauthenticated PHP Object Injection in EasyMeals <= 1.5.1 versions.
CVE-2026-40751 Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
CVE-2026-40754 Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
CVE-2026-40735 Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
Unauthenticated PHP Object Injection in Reina <= 2.1 versions.
CVE-2026-40759 Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
CVE-2026-40758 Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
CVE-2026-40739 Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
Unauthenticated PHP Object Injection in LuxeDrive <= 1.4 versions.
CVE-2026-40736 Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.
Unauthenticated PHP Object Injection in Laurits <= 1.5.1 versions.

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →