NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。
Assigner(CNA/発行元):[email protected] この条件を外す
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2025-41658 | CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions. | 5.5 | 0.06% | 2025-08-04 | 2026-06-17 |
| CVE-2025-41688 | A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox. | 7.2 | 0.61% | 2025-07-31 | 2026-06-17 |
| CVE-2025-2813 | An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80. | 7.5 | 0.58% | 2025-07-31 | 2026-06-17 |
| CVE-2025-41687 | An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices. | 9.8 | 0.68% | 2025-07-23 | 2026-06-17 |
| CVE-2025-41684 | An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting). | 8.8 | 0.67% | 2025-07-23 | 2026-06-17 |
| CVE-2025-41683 | An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint event_mail_test). | 8.8 | 0.67% | 2025-07-23 | 2026-06-17 |
| CVE-2025-41681 | A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content. | 4.8 | 0.27% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41679 | An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service. | 5.3 | 0.61% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41678 | A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. | 6.5 | 0.56% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41677 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. | 4.9 | 0.56% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41676 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. | 4.9 | 0.50% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41675 | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. | 7.2 | 0.57% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41674 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. | 7.2 | 0.57% | 2025-07-21 | 2026-06-17 |
| CVE-2025-41673 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. | 7.2 | 0.57% | 2025-07-21 | 2026-06-17 |
| CVE-2025-29572 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 該当なし | 該当なし | 2025-07-18 | 2025-07-18 |
| CVE-2025-41668 | A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device. | 8.8 | 0.50% | 2025-07-08 | 2026-06-17 |
| CVE-2025-41667 | A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device. | 8.8 | 0.50% | 2025-07-08 | 2026-06-17 |
| CVE-2025-41666 | A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been initialized. | 8.8 | 0.50% | 2025-07-08 | 2026-06-17 |
| CVE-2025-41665 | An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file. | 6.5 | 0.30% | 2025-07-08 | 2026-06-17 |
| CVE-2025-25271 | An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface. | 8.8 | 0.29% | 2025-07-08 | 2026-06-17 |