CVEリスト - 高リスク・悪用確認済み脆弱性

NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。

Assigner(CNA/発行元):[email protected] この条件を外す

CVSS スコア
表示中 120 / 10271
«« 先頭 « 前へ 1 / 514 次へ »
CVE 説明 CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-9691 Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. 9.8 該当なし 2026-06-15 2026-06-15
CVE-2026-52703 Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. 9.6 該当なし 2026-06-15 2026-06-15
CVE-2026-52702 Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions. 7.1 該当なし 2026-06-15 2026-06-15
CVE-2026-52700 Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. 8.5 該当なし 2026-06-15 2026-06-15
CVE-2026-52699 Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions. 7.5 該当なし 2026-06-15 2026-06-15
CVE-2026-52697 Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions. 8.5 該当なし 2026-06-15 2026-06-15
CVE-2026-52695 Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. 7.5 該当なし 2026-06-15 2026-06-15
CVE-2026-52694 Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions. 7.5 該当なし 2026-06-15 2026-06-15
CVE-2026-52693 Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. 9.3 該当なし 2026-06-15 2026-06-15
CVE-2026-52692 Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. 7.5 該当なし 2026-06-15 2026-06-15
CVE-2026-49781 Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. 9.8 該当なし 2026-06-15 2026-06-15
CVE-2026-49780 Customer Privilege Escalation in Dokan <= 5.0.2 versions. 8.8 該当なし 2026-06-15 2026-06-15
CVE-2026-49776 Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions. 9.3 該当なし 2026-06-15 2026-06-15
CVE-2026-49775 Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. 6.5 該当なし 2026-06-15 2026-06-15
CVE-2026-49773 Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions. 6.5 該当なし 2026-06-15 2026-06-15
CVE-2026-49770 Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. 9.8 該当なし 2026-06-15 2026-06-15
CVE-2026-49769 Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. 9.8 該当なし 2026-06-15 2026-06-15
CVE-2026-49768 Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. 9.8 該当なし 2026-06-15 2026-06-15
CVE-2026-49766 Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. 9.9 該当なし 2026-06-15 2026-06-15
CVE-2026-49765 Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. 9.8 該当なし 2026-06-15 2026-06-15
«« 先頭 « 前へ 1 / 514 次へ »
cvelogic Threat Intelligence