NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。
Assigner(CNA/発行元):[email protected] この条件を外す
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2026-14871 | osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem. | 7.1 | 0.31% | 2026-07-17 | 2026-07-17 |
| CVE-2026-2293 | A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue affects nest.Js: 11.1.13. | 8.2 | 0.68% | 2026-02-27 | 2026-07-14 |
| CVE-2026-11944 | openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary files on the server via crafted path traversal sequences. | 5.3 | 0.38% | 2026-07-14 | 2026-07-14 |
| CVE-2026-10715 | Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite the draft associated with another user's post. | 5.1 | 0.21% | 2026-06-12 | 2026-07-14 |
| CVE-2026-11779 | An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation. | 5.3 | 0.24% | 2026-06-26 | 2026-06-26 |
| CVE-2026-50712 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.ui.Tree component | 4.8 | 0.24% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50711 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Number Card component. | 4.6 | 0.26% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50710 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to unsafe evaluation of user-controlled data in the Number Card component. | 4.6 | 0.26% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50709 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Notifications > Events panel. | 4.8 | 0.24% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50708 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the MultiSelectDialog component. | 4.8 | 0.24% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50705 | A Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of untrusted input in the Form Dashboard headline renderer. | 4.6 | 0.26% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50704 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the File View breadcrumb renderer. | 4.6 | 0.26% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50703 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the Desk desktop icon renderer. | 4.8 | 0.24% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50701 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the dashboard-view component. | 5.1 | 0.27% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50700 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input in the frappe.get_avatar function. | 4.6 | 0.26% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50699 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev. An authenticated attacker with write access to Auto Repeat can persist HTML/JavaScript in reference_document using a whitelisted write path and trigger script execution when users open the affected Auto Repeat form. | 4.6 | 0.31% | 2026-06-24 | 2026-06-25 |
| CVE-2026-50698 | A Stored Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled input before generating HTML output in the Audit Trail component. | 4.6 | 0.26% | 2026-06-24 | 2026-06-25 |
| CVE-2026-10850 | Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint. | 6.9 | 0.24% | 2026-06-17 | 2026-06-23 |
| CVE-2026-11994 | Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. A user with permission to create or update reports can store arbitrary HTML/JavaScript in the description field of a report. | 4.8 | 0.32% | 2026-06-22 | 2026-06-22 |
| CVE-2026-11943 | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on invoice and bill detail pages. An authenticated user can store HTML/JavaScript in their own profile name. | 4.8 | 0.26% | 2026-06-22 | 2026-06-22 |