Secure Gatev1.1.0新着セキュリティニュース バックナンバー

新着セキュリティニュース バックナンバー

直近表示から外れた情報を確認できます。診断結果とは別情報として扱います。

総件数224294件
表示件数50件/ページ
ページ27

CVE-2026-73081

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a Code step from the step's name and passes that path to a shell-invoked build command. A step name containing shell metacharacters can break out of the intended build invocation and execute arbitrary commands during compilation before any code sandbox is created. An authenticated user with permission to create or edit a flow can execute commands as the worker process user, read and write the worker filesystem, exfiltrate environment secrets, and reach internal services available to the worker. This issue is fixed in version 0.80.0.

CVE-2026-72971

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

CVE-2026-71390

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction.

CVE-2026-71389

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

CVE-2026-71387

Threat Intelligence NVD CVE 危険度: high 緊急度: high

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction.

CVE-2026-71386

Threat Intelligence NVD CVE 危険度: high 緊急度: high

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-71384

Threat Intelligence NVD CVE 危険度: high 緊急度: high

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application denial-of-service condition. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-71383

Threat Intelligence NVD CVE 危険度: high 緊急度: high

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.

CVE-2026-71331

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

CVE-2026-70355

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVE-2026-70354

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

CVE-2026-70348

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

CVE-2026-70347

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70346

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70345

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70344

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-70340

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

CVE-2026-70338

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-70337

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

CVE-2026-70336

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

CVE-2026-70335

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

CVE-2026-70330

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-70329

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

CVE-2026-70328

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVE-2026-70327

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

CVE-2026-70326

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVE-2026-70325

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

CVE-2026-70324

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

CVE-2026-70323

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-70322

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

CVE-2026-70321

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-70320

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

CVE-2026-70319

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-70318

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2026-70317

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-70316

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

CVE-2026-70315

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-70314

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-70313

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

CVE-2026-70312

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

CVE-2026-70311

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-70310

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

CVE-2026-70307

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-70306

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-70304

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

CVE-2026-70130

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-69320

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

CVE-2026-69306

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-69278

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.