Secure Gatev1.1.0新着セキュリティニュース バックナンバー

新着セキュリティニュース バックナンバー

直近表示から外れた情報を確認できます。診断結果とは別情報として扱います。

総件数224294件
表示件数50件/ページ
ページ71

CVE-2026-65520

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

CVE-2026-65517

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.

CVE-2026-65515

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.

CVE-2026-65513

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.

CVE-2026-65509

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.

CVE-2026-65508

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

CVE-2026-65507

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

CVE-2026-65504

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.

CVE-2026-65502

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

CVE-2026-61982

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.

CVE-2026-61964

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.

CVE-2026-61963

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.

CVE-2026-61961

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.

CVE-2026-61959

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.

CVE-2026-54489

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity.

CVE-2026-53976

Threat Intelligence NVD CVE 危険度: high 緊急度: high

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API credentials, and environment variables, enabling full authentication bypass by forging session cookies on password-protected deployments.

CVE-2026-53975

Threat Intelligence NVD CVE 危険度: high 緊急度: high

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured, matching the default Docker deployment, enabling attackers to execute arbitrary OS commands as the application user and retrieve full command output including stdout, stderr, and exit code from the server response.

CVE-2026-34502

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.

CVE-2026-34501

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.

CVE-2026-34191

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

CVE-2026-32548

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

CVE-2026-32469

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

CVE-2026-32327

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVE-2026-28183

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.

CVE-2026-28180

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

CVE-2026-28179

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.

CVE-2026-28178

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.

CVE-2026-28177

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

CVE-2026-28172

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

CVE-2026-28169

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

CVE-2026-28146

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.

CVE-2026-28143

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

CVE-2026-28141

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

CVE-2026-28140

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

CVE-2026-28139

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

CVE-2026-28111

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

CVE-2026-28082

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

CVE-2026-28005

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

CVE-2026-25403

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

CVE-2026-19045

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-19044

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the component create_scene/add_node. This manipulation of the argument projectPath causes command injection. The attack needs to be launched locally. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-15246

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

The RealHomes Memberships WordPress plugin before 3.1.0 does not verify that a membership payment actually completed, nor check a nonce or the user's capability, before granting a paid membership package, allowing any authenticated user such as a Subscriber to obtain paid membership packages without paying.

CVE-2025-49506

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

CVE-2026-64993

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.

CVE-2026-5134

Threat Intelligence NVD CVE 危険度: high 緊急度: high

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-19041

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the file src/controllers/packages.ts of the component NPM Package Version Handler. The manipulation leads to command injection. It is possible to initiate the attack remotely. Upgrading to version 1.11.9 is sufficient to resolve this issue. The identifier of the patch is a40f54d4533ba6618e1749383a245900eeb024c1. The affected component should be upgraded.

CVE-2026-19040

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Executing a manipulation can lead to server-side request forgery. The attack may be performed from remote. Upgrading to version 1.11.10 is sufficient to fix this issue. This patch is called f068ab4ad6f0907ac7001b995588c2673f11a755. You should upgrade the affected component.

CVE-2026-18501

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Badge Widget Variable Substitution in all versions up to, and including, 1.2.69 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE-2026-16731

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may allow an unauthenticated attacker to forge valid authentication credentials, bypass authentication and authorization, and impersonate legitimate clients. An attacker can gain full access to the system configuration, allowing modification, reset, or unauthorized alteration of system parameters or injecting network traffic into the connected network.

CVE-2026-16316

Threat Intelligence NVD CVE 危険度: medium 緊急度: medium

OMICRON StationGuard 4.00 contains an improper input validation vulnerability in its IEC 61850 Sampled Values (SV) frame processing. A specially crafted SV frame can cause the affected process to terminate, disrupting alert processing for Sampled Values traffic. The vulnerability does not affect overall system availability or the processing of other traffic types, and the process is automatically restarted, and the failure is immediately reported to the user.