実際の悪用を確認
CVE-2024-36401 OSGeo GeoServer GeoTools Eval Injection
- 実環境での悪用(CISA KEV)
- CISA KEV に掲載
- リモートコード実行の露出リスク
OSGeo GeoServer RCE は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。
日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。
最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。
実際の悪用を確認
OSGeo GeoServer RCE は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。
重大な露出リスク
新たな重大公開(CVSS 9.9)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。
重大な露出リスク
新たな重大 Tenda Ax1806 Firmware Buffer Overflow(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。
CISA KEV — 実環境での悪用が確認
OSGeo GeoServer GeoTools Eval Injection
本ダイジェストではこのカテゴリに該当なし。
本ダイジェストではこのカテゴリに該当なし。
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending...
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a speci...
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a speci...
Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API.
新たな重大 Tenda Ax1806 Firmware Buffer Overflow が公開。
新たな重大 Tenda Ax1806 Firmware Buffer Overflow が公開。
新たな重大 Tenda Ax1806 Firmware Buffer Overflow が公開。
Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application....
TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php.
A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbitrary code execution.