重大な露出リスク
CVE-2025-41687 An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management...
- CVSS 9.8
新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。
日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。
最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。
重大な露出リスク
新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。
高リスク露出
新高危 Oscommerce Online Merchant RCE — 公開後 72 時間以内のエクスプロイト出現とスキャナ動向に注意。
高リスク露出
本日のウィンドウで新たな Critical — ライフサイクル初期の露出シグナルが高まっています。
CISA KEV — 実環境での悪用が確認
本ダイジェストではこのカテゴリに該当なし。
本ダイジェストではこのカテゴリに該当なし。
本ダイジェストではこのカテゴリに該当なし。
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension develope...
A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data...
The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers.
A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and...
Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, w...
An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface.
An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected...
A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered.
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects Mag...
The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability.