悪用活動を確認
CVE-2024-11605 Wp-publications Project Wp-publications XSS
- 公開エクスプロイトまたは PoC あり
- 悪用活動が関連付け
- インターネット公開 CMS への影響
WordPress プラグインの露出と公開エクスプロイト — PoC 流通後はインターネット公開 CMS への大規模標的化が一般的です。
日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。
最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。
悪用活動を確認
WordPress プラグインの露出と公開エクスプロイト — PoC 流通後はインターネット公開 CMS への大規模標的化が一般的です。
悪用活動を確認
Sugarcrm SSRF に公開エクスプロイトまたは PoC が関連 — 日和見的スキャンと続く標的型活動を想定してください。
重大な露出リスク
新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。
CISA KEV — 実環境での悪用が確認
本ダイジェストではこのカテゴリに該当なし。
Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX.
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to...
A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ e...
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2.
Langflow Missing Authentication
The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious...
The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow hig...
本ダイジェストではこのカテゴリに該当なし。
Cisco Identity Services Engine Injection
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due...
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2.
An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1...
A stack-based buffer overflow exists in Achat v0.150 in its default configuration.
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the...
A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciw...
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions.
The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0.
The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_...