CVEリスト - 高リスク・悪用確認済み脆弱性

NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。

Assigner(CNA/発行元):[email protected] この条件を外す

CVSS スコア
表示中 201220 / 756
CVE 説明 CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-41658 CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions. 5.5 0.06% 2025-08-04 2026-06-17
CVE-2025-41688 A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox. 7.2 0.61% 2025-07-31 2026-06-17
CVE-2025-2813 An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80. 7.5 0.58% 2025-07-31 2026-06-17
CVE-2025-41687 An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices. 9.8 0.68% 2025-07-23 2026-06-17
CVE-2025-41684 An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint tls_iotgen_setting). 8.8 0.67% 2025-07-23 2026-06-17
CVE-2025-41683 An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of improper sanitizing of user input in the Main Web Interface (endpoint event_mail_test). 8.8 0.67% 2025-07-23 2026-06-17
CVE-2025-41681 A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content. 4.8 0.27% 2025-07-21 2026-06-17
CVE-2025-41679 An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service. 5.3 0.61% 2025-07-21 2026-06-17
CVE-2025-41678 A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. 6.5 0.56% 2025-07-21 2026-06-17
CVE-2025-41677 A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. 4.9 0.56% 2025-07-21 2026-06-17
CVE-2025-41676 A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. 4.9 0.50% 2025-07-21 2026-06-17
CVE-2025-41675 A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. 7.2 0.57% 2025-07-21 2026-06-17
CVE-2025-41674 A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. 7.2 0.57% 2025-07-21 2026-06-17
CVE-2025-41673 A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. 7.2 0.57% 2025-07-21 2026-06-17
CVE-2025-29572 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. 該当なし 該当なし 2025-07-18 2025-07-18
CVE-2025-41668 A low privileged remote attacker with file access can replace a critical file or folder used by the service security-profile to get read, write and execute access to any file on the device. 8.8 0.50% 2025-07-08 2026-06-17
CVE-2025-41667 A low privileged remote attacker with file access can replace a critical file used by the arp-preinit script to get read, write and execute access to any file on the device. 8.8 0.50% 2025-07-08 2026-06-17
CVE-2025-41666 A low privileged remote attacker with file access can replace a critical file used by the watchdog to get read, write and execute access to any file on the device after the watchdog has been initialized. 8.8 0.50% 2025-07-08 2026-06-17
CVE-2025-41665 An low privileged remote attacker can enforce the watchdog of the affected devices to reboot the PLC due to incorrect default permissions of a config file. 6.5 0.30% 2025-07-08 2026-06-17
CVE-2025-25271 An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface. 8.8 0.29% 2025-07-08 2026-06-17
cvelogic Threat Intelligence