Secure Gatev1.1.0新着セキュリティニュース バックナンバー

新着セキュリティニュース バックナンバー

直近表示から外れた情報を確認できます。診断結果とは別情報として扱います。

総件数224649件
表示件数50件/ページ
ページ9

CVE-2026-15994

Threat Intelligence NVD CVE 危険度: high 緊急度: high

During an internal security assessment, an improper link following vulnerability was identified in Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to execute code with elevated privileges.

CVE-2026-14456

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection. It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests. The issue is present since OpenSSL 3.5 when the QUIC server implementation was added. The fix introduces a limit for pending connections. The default limit is set to 256 pending connections (waiting to be accepted by the local application). Applications may change the default by calling SSL_set_value_uint(3ossl). FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

CVE-2026-14256

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstances, could allow a local authenticated user to cause a system crash.

CVE-2026-12036

Threat Intelligence NVD CVE 危険度: high 緊急度: high

An improper link following vulnerability was reported in the VantageCoreAddin for Lenovo Vantage and Lenovo Commercial Vantage that could allow a local authenticated user to perform an arbitrary file deletion with elevated privileges.

CVE-2026-73403

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.

CVE-2026-73401

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in InstaWP Connect <= 0.1.3.7 versions.

CVE-2026-73357

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.

CVE-2026-73353

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.

CVE-2026-73349

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

CVE-2026-73346

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.

CVE-2026-73344

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.

CVE-2026-73340

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.

CVE-2026-73188

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.

CVE-2026-67991

Threat Intelligence NVD CVE 危険度: high 緊急度: high

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial of service.

CVE-2026-67990

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services.

CVE-2026-67986

Threat Intelligence NVD CVE 危険度: high 緊急度: high

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.

CVE-2026-66704

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.

CVE-2026-66700

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.

CVE-2026-66698

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.

CVE-2026-66697

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.

CVE-2026-66693

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Subscriber Broken Access Control in Motors <= 1.4.113 versions.

CVE-2026-66691

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.

CVE-2026-66689

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions.

CVE-2026-66687

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.

CVE-2026-66661

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.

CVE-2026-66660

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.

CVE-2026-66658

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Subscriber SQL Injection in Reviewer <= 3.14.2 versions.

CVE-2026-66657

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.

CVE-2026-66656

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.

CVE-2026-66655

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.

CVE-2026-66654

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.

CVE-2026-66653

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.

CVE-2026-66478

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.

CVE-2026-66472

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.

CVE-2026-66471

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.

CVE-2026-66469

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions.

CVE-2026-66468

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.

CVE-2026-66467

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Subscriber Cross Site Scripting (XSS) in FluentCommunity <= 2.7.5 versions.

CVE-2026-66466

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.

CVE-2026-66465

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

CVE-2026-66464

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in Internal Link Optimiser <= 5.2.7 versions.

CVE-2026-66463

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.

CVE-2026-66462

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.

CVE-2026-66461

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.

CVE-2026-66460

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Subscriber Cross Site Scripting (XSS) in AfterShip Tracking <= 1.18.1 versions.

CVE-2026-66459

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.

CVE-2026-66458

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.

CVE-2026-66456

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.

CVE-2026-66455

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.

CVE-2026-66454

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in WP Social Avatar <= 1.5 versions.