悪用確認済み脆弱性分析(CISA KEV・Exploit-DB)
| ビジネス観点のファセット |
CVSS ルール(ベーススコア) |
CVE 件数 |
|
| 日常モニタリングと広いカバレッジ |
CVSS ベーススコア ≥ 4.0 |
253281 |
→ |
| シグナルが高いものに絞って優先度付け |
CVSS ベーススコア ≥ 7.0 |
132048 |
→ |
| 露出が極めて大きく緊急の対応が必要 |
CVSS ベーススコア ≥ 9.0 |
31413 |
→ |
| 戦術 |
技法 |
CVE 件数 |
| Initial Access |
Stored/Reflected XSS |
45,322 |
| SQL Injection |
19,422 |
| Generic Input/Entry Manipulation |
5,585 |
| Execution |
RCE / Command Execution |
19,426 |
| Out-of-Bounds Write |
14,105 |
| Memory Corruption |
13,943 |
| Privilege Escalation |
CSRF Session Abuse |
9,302 |
| Missing Authorization |
8,145 |
| Authorization/Privilege Bypass |
7,866 |
| Lateral Movement |
SSRF Pivoting |
2,677 |
| Open Redirect Pivoting |
1,511 |
| Spoofing to Internal Trust Pivoting |
578 |
| Defense Evasion |
Path Traversal |
9,656 |
| Malicious File Upload Entry |
4,102 |
| XXE Injection |
1,248 |
| Credential Access |
Cryptographic Weakness |
6,174 |
| Hard-coded Credentials |
1,713 |
| Insufficiently Protected Credentials |
1,360 |
cvelogic
Threat Intelligence