NVD や CVE、ほか複数の脅威フィードを束ね、RCE など高リスクな事象を深く追える一覧です。CVSS と EPSS を組み合わせ、Exploit 参照や PoC の有無から悪用しやすさを追跡します。ベンダー修正や緩和策の文脈とあわせて優先度を決め、対応サイクルを短く保ちつつ重要資産を守る支援をします。
Assigner(CNA/発行元):[email protected] この条件を外す
| CVE | 説明 | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|
| CVE-2026-48902 | The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set. | 9.8 | 0.19% | 2026-05-26 | 2026-06-17 |
| CVE-2026-48901 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. | 7.5 | 0.24% | 2026-05-26 | 2026-06-17 |
| CVE-2026-48900 | An improper access check allowed low privileged users to edit the task types of existing scheduler tasks. | 6.4 | 0.15% | 2026-05-26 | 2026-06-17 |
| CVE-2026-48899 | An improper access check allows privilege escalation through the com_users batch task. | 5.3 | 0.23% | 2026-05-26 | 2026-06-17 |
| CVE-2026-48898 | An improper access check allows privilege escalation through the com_users batch task. | 8.2 | 0.27% | 2026-05-26 | 2026-06-17 |
| CVE-2026-48897 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | 8.2 | 0.21% | 2026-05-26 | 2026-06-17 |
| CVE-2026-48896 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. | 8.2 | 0.30% | 2026-05-26 | 2026-06-17 |
| CVE-2026-40384 | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability. | 5.9 | 0.45% | 2026-05-26 | 2026-06-17 |
| CVE-2026-40383 | An improper validation of user-supplied input leads to a local file inclusion vulnerability. | 7.5 | 0.48% | 2026-05-26 | 2026-06-17 |
| CVE-2026-35223 | An improper access check allows unauthorized access to com_config webservice endpoints. | 8.6 | 0.35% | 2026-05-26 | 2026-06-17 |
| CVE-2026-35222 | Improperly validated order clauses lead to a SQL injection vulnerability in com_tags. | 6.9 | 0.31% | 2026-05-26 | 2026-06-17 |
| CVE-2026-35221 | Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder. | 6.9 | 0.31% | 2026-05-26 | 2026-06-17 |
| CVE-2026-35220 | Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users. | 4.6 | 0.10% | 2026-05-26 | 2026-07-20 |
| CVE-2026-30895 | Lack of output escaping leads to a XSS vector in the readmore links for com_content. | 6.9 | 0.18% | 2026-05-26 | 2026-06-17 |
| CVE-2026-30894 | Lack of output escaping leads to a XSS vector in the content history component. | 6.9 | 0.18% | 2026-05-26 | 2026-06-17 |
| CVE-2026-25901 | Lack of output escaping leads to a XSS vector in the multilingual associations component. | 6.9 | 0.18% | 2026-05-26 | 2026-06-17 |
| CVE-2026-25900 | Lack of output escaping leads to a XSS vector in the feed modules. | 6.9 | 0.18% | 2026-05-26 | 2026-07-20 |
| CVE-2026-23900 | Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered. | 6.5 | 0.25% | 2026-04-11 | 2026-06-17 |
| CVE-2026-23899 | An improper access check allows unauthorized access to webservice endpoints. | 8.6 | 0.40% | 2026-04-01 | 2026-06-17 |
| CVE-2026-23898 | Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism. | 8.6 | 0.45% | 2026-04-01 | 2026-06-17 |