重大な露出リスク
CVE-2023-22814 Westerndigital My Cloud Os Auth Bypass
- CVSS 10
- 認証バイパス — 未認証アクセスのリスク
新たな重大 Westerndigital My Cloud Os Auth Bypass(CVSS 10)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。
最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。
重大な露出リスク
新たな重大 Westerndigital My Cloud Os Auth Bypass(CVSS 10)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
重大な露出リスク
新たな重大 Ivanti Endpoint Manager Deserialization(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
重大な露出リスク
新たな重大 Ivanti Endpoint Manager RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
CISA KEV — 実環境での悪用が確認
本ダイジェストではこのカテゴリに該当なし。
本ダイジェストではこのカテゴリに該当なし。
本ダイジェストではこのカテゴリに該当なし。
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to ca...
A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights.
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remot...
A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows applicatio...
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to th...
UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB.
SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB).
An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3.