CVEリスト - 高リスク・悪用確認済み脆弱性 ATT&CK の技法:Execution / RCE / Command Execution

MITRE ATT&CK CVE list for this attack path. Use risk scores and timeline to decide what to patch first and what to track next.

CVSS スコア
表示中 121140 (ほかにも結果があります)
CVE 説明 CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-54112 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. 7.8 0.16% 2026-07-14 2026-07-15
CVE-2026-54111 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. 7.0 0.16% 2026-07-14 2026-07-15
CVE-2026-54107 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally. 8.8 0.19% 2026-07-14 2026-07-15
CVE-2026-50384 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally. 7.0 0.16% 2026-07-14 2026-07-16
CVE-2026-50364 Improper link resolution before file access ('link following') in Windows Server Backup allows an authorized attacker to elevate privileges locally. 7.3 0.34% 2026-07-14 2026-07-16
CVE-2026-50356 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally. 7.0 0.16% 2026-07-14 2026-07-16
CVE-2026-49808 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. 7.8 0.16% 2026-07-14 2026-07-16
CVE-2026-49806 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. 7.0 0.16% 2026-07-14 2026-07-16
CVE-2026-49803 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. 7.0 0.16% 2026-07-14 2026-07-16
CVE-2026-49802 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally. 7.0 0.16% 2026-07-14 2026-07-16
CVE-2026-49791 Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. 7.1 0.28% 2026-07-14 2026-07-15
CVE-2026-49784 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally. 7.0 0.16% 2026-07-14 2026-07-16
CVE-2026-49183 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally. 7.0 0.16% 2026-07-14 2026-07-16
CVE-2026-49176 Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. 7.8 0.24% 2026-07-14 2026-07-15
CVE-2026-49165 Use of uninitialized resource in Microsoft Windows App Store allows an authorized attacker to disclose information locally. 7.1 0.25% 2026-07-14 2026-07-16
CVE-2026-48572 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally. 7.0 0.17% 2026-07-14 2026-07-16
CVE-2026-44800 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally. 7.8 0.16% 2026-07-14 2026-07-16
CVE-2026-42900 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. 8.1 0.40% 2026-07-14 2026-07-16
CVE-2026-9128 A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary 7.3 0.10% 2026-07-14 2026-07-14
CVE-2026-59835 A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. 8.6 0.44% 2026-07-14 2026-07-15
cvelogic Threat Intelligence