CVEリスト - 高リスク・悪用確認済み脆弱性

NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。

Assigner(CNA/発行元):[email protected] この条件を外す

CVSS スコア
表示中 241260 / 756
CVE 説明 CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-41663 For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary commands in responses returned by WWH servers, which are then executed with elevated privileges. To get into such a position, clients would need to use insecure proxy configurations. 9.8 0.55% 2025-06-11 2026-06-17
CVE-2025-41662 Rejected reason: CVE-2025-41662 is considered redundant or unnecessary and thus should be withdrawn. Instead, a new CVE CVE-2025-41687 has been reserved to better reflect the updated analysis. 該当なし 0.07% 2025-06-11 2025-07-23
CVE-2025-41661 An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery (CSRF) protection. 8.8 0.26% 2025-06-11 2026-06-17
CVE-2025-41657 Due to an undocumented active bluetooth stack on products delivered within the period 01.01.2024 to 09.05.2025 fingerprinting is possible by an unauthenticated adjacent attacker. 4.3 0.17% 2025-06-10 2026-06-17
CVE-2025-41646 An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This leads to full compromise of the device 9.8 43.29% 2025-06-06 2026-06-17
CVE-2018-25112 An unauthenticated remote attacker may use an uncontrolled resource consumption in the IEC 61131 program of the affected products by creating large amounts of network traffic that needs to be handled by the ILC. This results in a Denial-of-Service of the device. 7.5 0.40% 2025-06-04 2026-06-16
CVE-2025-1235 A low privileged attacker can set the date of the devices to the 19th of January 2038 an therefore exceed the 32-Bit time limit. This causes the date of the switch to be set back to January 1st, 1970. 4.3 0.22% 2025-06-02 2026-06-17
CVE-2025-41653 An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted HTTP request with a malicious header, potentially causing the server to crash or become unresponsive. 7.5 0.47% 2025-05-27 2026-06-17
CVE-2025-41652 The devices are vulnerable to an authentication bypass due to flaws in the authorization mechanism. An unauthenticated remote attacker could exploit this weakness by performing brute-force attacks to guess valid credentials or by using MD5 collision techniques to forge authentication hashes, potentially compromising the device. 9.8 0.39% 2025-05-27 2026-06-17
CVE-2025-41651 Due to missing authentication on a critical function of the devices an unauthenticated remote attacker can execute arbitrary commands, potentially enabling unauthorized upload or download of configuration files and leading to full system compromise. 9.8 0.51% 2025-05-27 2026-06-17
CVE-2025-41650 An unauthenticated remote attacker can exploit input validation in cmd services of the devices, allowing them to disrupt system operations and potentially cause a denial-of-service. 7.5 0.40% 2025-05-27 2026-06-17
CVE-2025-41649 An unauthenticated remote attacker can exploit insufficient input validation to write data beyond the bounds of a buffer, potentially leading to a denial-of-service condition for the devices. 7.5 0.40% 2025-05-27 2026-06-17
CVE-2025-41655 An unauthenticated remote attacker can access a URL which causes the device to reboot. 7.5 0.41% 2025-05-26 2026-06-17
CVE-2025-41654 An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by the watchdog. 8.2 0.39% 2025-05-26 2026-06-17
CVE-2025-1985 Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject HTML code into the Web-UI in the affected device. 6.1 0.25% 2025-05-26 2026-06-17
CVE-2025-41645 An unauthenticated remote attacker could use a demo account of the portal to hijack devices that were created in that account by mistake. 8.6 0.34% 2025-05-13 2026-06-17
CVE-2025-3496 An unauthenticated remote attacker can cause a buffer overflow which could lead to unexpected behaviour or DoS via Bluetooth or RS-232 interface. 7.5 0.47% 2025-05-12 2026-06-17
CVE-2025-3020 An low privileged remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into several fields of the configuration webpage with limited impact. 5.4 0.15% 2025-05-06 2026-06-17
CVE-2025-3200 An unauthenticated remote attacker could exploit the used, insecure TLS 1.0 and TLS 1.1 protocols to intercept and manipulate encrypted communications between the Com-Server and connected systems. 9.1 0.31% 2025-04-28 2026-06-17
CVE-2021-47664 Due to improper authentication mechanism an unauthenticated remote attacker can enumerate valid usernames. 5.3 0.38% 2025-04-24 2026-06-17
cvelogic Threat Intelligence