Secure Gatev1.1.0新着セキュリティニュース バックナンバー

新着セキュリティニュース バックナンバー

直近表示から外れた情報を確認できます。診断結果とは別情報として扱います。

総件数224649件
表示件数50件/ページ
ページ84

CVE-2026-18902

Threat Intelligence NVD CVE 危険度: high 緊急度: high

A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

CVE-2026-18322

Threat Intelligence NVD CVE 危険度: high 緊急度: high

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticated attackers to submit a crafted POST request to `admin-ajax.php` using a nonce obtained from a public subscription confirmation email, setting `params[tpl][sub_wp_create_user_role]` to `administrator` via the exposed `popupControllerPps::save()` action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials.

CVE-2026-16143

Threat Intelligence NVD CVE 危険度: high 緊急度: high

The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output escaping in the saveorder() function, which stores the raw email value via VikRequest::getString() (applying only sanitize_text_field(), which does not neutralize HTML attribute-breaking characters such as double quotes), and in the editorder template which echoes the stored custmail value into an HTML input element's value attribute without esc_attr(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-15941

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy query data into Relevanssi's taxonomy restriction builder. The taxonomy value is sanitized as text but is not parameterized for SQL before being interpolated into a term taxonomy lookup query. This allows an authenticated contributor-level attacker to inject SQL through the Admin Search AJAX request and execute time-based blind SQL injection against the WordPress database.

CVE-2026-15918

Threat Intelligence NVD CVE 危険度: high 緊急度: high

VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper validation or sanitization. Because this value is placed directly into the query, an attacker who is not logged in can inject arbitrary SQL through a normal booking page and read data from the site's database — including sensitive information such as WordPress user credentials. No authentication or special privileges are required

CVE-2026-11421

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. The handler runs the value through sanitize_text_field, which preserves single quotes, and the downstream erp_crm_contact_advance_filter() function interpolates it directly into a single-quoted SQL WHERE clause before execution via $wpdb->get_results(). This makes it possible for authenticated attackers, with the plugin-supplied CRM Agent role (or higher CRM Manager / WordPress admin) and the erp_crm_list_contact capability, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

CVE-2026-18901

Threat Intelligence NVD CVE 危険度: high 緊急度: high

A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

CVE-2026-18900

Threat Intelligence NVD CVE 危険度: high 緊急度: high

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure.

CVE-2026-18898

Threat Intelligence NVD CVE 危険度: high 緊急度: high

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

JVN: NetKids iMarkにおける複数の脆弱性

Incident Knowledge JPCERT/CC CVE

株式会社アイ・エス・ティが提供するNetKids iMarkには、複数の脆弱性が存在します。

影響: 株式会社アイ・エス・ティが提供するNetKids iMarkには、複数の脆弱性が存在します。

CVE-2026-18907

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

CVE-2026-18897

Threat Intelligence NVD CVE 危険度: high 緊急度: high

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18896

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18895

Threat Intelligence NVD CVE 危険度: high 緊急度: high

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18859

Threat Intelligence NVD CVE 危険度: high 緊急度: high

A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-18856

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.1.34 will fix this issue. It is recommended to upgrade the affected component.

Weekly Report: WordPress用プラグインLoco Translateにクロスサイトリクエストフォージェリの脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

WordPress用プラグインLoco Translateには、クロスサイトリクエストフォージェリの脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: 複数のApple製品に脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

複数のApple製品には、脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: VeloCloud Orchestratorに複数の脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

VeloCloud Orchestratorには、複数の脆弱性があります。開発元によると、今回修正された一部の脆弱性が悪用された可能性があるとのことです。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: JFrog Artifactoryに複数の脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

JFrog Artifactoryには、複数の脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: IBM WebSphere Application Serverに複数の脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

IBM WebSphere Application Serverには、複数の脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: Sambaに複数の脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

Sambaには、複数の脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: Joomla!向けの拡張機能Balbooa Formsにリモートコード実行につながる脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

Joomla!向けの拡張機能Balbooa Formsには、認証なしでリモートコード実行につながる脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。また、予防措置として、不審なPHPファイルが存在しないか確認することが推奨されています。詳細は、開発者が提供する情報を参照してください。

Weekly Report: Node.jsに複数の脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

Node.jsには、複数の脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: GitLabに複数の脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

GitLabには、複数の脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: Google Chromeに複数の脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

Google Chromeには、複数の脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: Cisco Secure Firewall Management Centerソフトウェアに脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

Cisco Secure Firewall Management Centerソフトウェアには、脆弱性があります。開発者は、今回修正された脆弱性を悪用した攻撃を確認しているとのことです。この問題は、当該製品にパッチを適用することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: 複数のAdobe製品に脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

複数のAdobe製品には、脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: Ruby on Railsにリモートコード実行につながる脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

Ruby on Railsには、リモートコード実行につながる脆弱性(通称:KindaRails2Shell)があります。Ruby on Railsで作成され、特定の条件を満たすアプリケーションが影響を受けます。開発者は、本脆弱性のエクスプロイトコードが公開されていることを確認しており、脆弱性の詳細をすでに公表しています。この問題への対応として、修正済みのバージョンへの更新とあわせて、侵害の有無の確認を推奨します。詳細は、JPCERT/CCの注意喚起や関連文書に掲載している開発者などが提供する情報を確認してください。

Weekly Report: Microsoft Edgeに複数の脆弱性

Threat Intelligence JPCERT/CC RSS CVE 危険度: medium 緊急度: medium

Microsoft Edgeには、複数の脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

Weekly Report: JPCERT/CCが「TSUBAMEレポート Overflow(2026年4-6月)」を公開

Incident Knowledge JPCERT/CC EXPOSURE

JPCERT/CCは、ブログ「TSUBAMEレポート Overflow(2026年4-6月)」を公開しました。2026年4-6月の観測結果として、国内外に設置しているセンサーの観測動向の比較や、その他の活動などについて紹介しています。

影響: JPCERT/CCは、ブログ「TSUBAMEレポート Overflow(2026年4-6月)」を公開しました。2026年4-6月の観測結果として、国内外に設置しているセンサーの観測動向の比較や、その他の活動などについて紹介しています。

Weekly Report: WordPress用プラグインLoco Translateにクロスサイトリクエストフォージェリの脆弱性

Incident Knowledge JPCERT/CC CVE

WordPress用プラグインLoco Translateには、クロスサイトリクエストフォージェリの脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。

影響: WordPress用プラグインLoco Translateには、クロスサイトリクエストフォージェリの脆弱性があります。この問題は、当該製品を修正済みのバージョンに更新することで解決します。詳細は、開発者が提供する情報を参照してください。