セキュリティ診断、情報提供

セキュリティに関する情報の提供、ウェブ診断ツールを提供しているサイトです。

  アナウンス          一覧表示

更新日:2026年7月20日18:00

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日
1 6.8 警告 OpenBSD OpenSSH OpenBSDのOpenSSHにおける認証に関する脆弱性 CWE-287
不適切な認証
CVE-2001-1585 2026-07-17 17:48 2001-12-31
2 10 危険 サン・マイクロシステムズ Solaris サン・マイクロシステムズのSolarisにおけるOS コマンドインジェクションの脆弱性 CWE-78
OSコマンド・インジェクション
CVE-2001-1583 2026-07-17 17:48 2001-12-31
3 7.2 危険 サン・マイクロシステムズ Sun Solaris
Solaris
サン・マイクロシステムズのSun Solaris等の複数製品におけるバッファエラーの脆弱性 CWE-119
バッファエラー
CVE-2001-1582 2026-07-17 17:48 2001-12-31
4 5 警告 SCO UnixWare
Open UNIX
SCOのOpen UNIX等の複数製品における不特定の脆弱性 CWE-Other
その他
CVE-2001-1579 2026-07-17 17:48 2001-12-31
5 2.1 注意 SCO openserver SCOのopenserverにおける不特定の脆弱性 CWE-Other
その他
CVE-2001-1578 2026-07-17 17:48 2001-12-31
6 5.5 警告
ローカル
OpenBSD OpenBSD OpenBSDにおけるNULL ポインタデリファレンスに関する脆弱性 CWE-476
NULL ポインタデリファレンス
CVE-2001-1559 2026-07-17 17:48 2001-12-31
7 5 警告 Snort.org Snort Snort.orgのSnortにおける不特定の脆弱性 CWE-Other
その他
CVE-2001-1558 2026-07-17 17:48 2001-12-31
8 2.1 注意 zonelabs zonealarm zonelabsのzonealarmにおける不特定の脆弱性 CWE-Other
その他
CVE-2001-1548 2026-07-17 17:48 2001-12-31
9 7.2 危険 フォア・チューン BSD/OS フォア・チューンのBSD/OSにおける不特定の脆弱性 CWE-Other
その他
CVE-2001-1541 2026-07-17 17:48 2001-12-31
10 7.5 重要
ネットワーク
symfony twig symfonyのtwigにおける重要な情報の平文保存に関する脆弱性 CWE-312
重要な情報の平文保存
CVE-2001-1537 2026-07-17 17:48 2001-12-31

更新日":2026年7月21日4:31

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日
1 7.8 HIGH
ローカル
microsoft windows_subsystem_for_linux Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally. New CWE-126
バッファオーバーリード
CVE-2026-57968
2026-07-21 03:39 2026-07-15
2 4.7 MEDIUM
ローカル
microsoft windows_subsystem_for_linux Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally. New CWE-367
Time-of-check Time-of-use (TOCTOU) 競合状態
CVE-2026-57973
2026-07-21 03:39 2026-07-15
3 6.5 MEDIUM
ネットワーク
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
windows_server_2019<…
Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. New CWE-908
初期化されていないリソースの使用
CVE-2026-57982
2026-07-21 03:39 2026-07-15
4 7.0 HIGH
ローカル
microsoft windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2022
windows_server_2025
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally. New CWE-362
競合状態
CVE-2026-58527
2026-07-21 03:38 2026-07-15
5 4.6 MEDIUM
物理
microsoft windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2019
windows_server_2022
windows_server_2025
Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack. New CWE-125
境界外読み取り
CVE-2026-58528
2026-07-21 03:33 2026-07-15
6 7.8 HIGH
ローカル
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2016
windows_server_2019
windows_server_2022<…
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally. New CWE-122
ヒープオーバーフロー
CVE-2026-58530
2026-07-21 03:28 2026-07-15
7 7.5 HIGH
ネットワーク
microsoft windows_10_1607
windows_10_1809
windows_10_21h2
windows_10_22h2
windows_11_24h2
windows_11_25h2
windows_11_26h1
windows_server_2012
windows_server_2016
windows_server_2019<…
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network. New CWE-362
CWE-416
競合状態
解放済みメモリの使用
CVE-2026-58531
2026-07-21 03:26 2026-07-15
8 9.8 CRITICAL
ネットワーク
langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authentication when the AUTO_LOGIN configuration is enabl… New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-9103
2026-07-21 03:22 2026-07-18
9 9.9 CRITICAL
ネットワーク
langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists b… New CWE-94
コード・インジェクション
CVE-2026-9135
2026-07-21 03:22 2026-07-18
10 - - - The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links outside of the intended privilege boundary. An attacker with low-privilege CLI access can create a symbolic link that references a privileged filesyst… New CWE-59
リンク解釈の問題
CVE-2026-8170
2026-07-21 03:16 2026-07-21

対象期間 : 2026-06-01 〜 2026-10-31

No 名前 通常サポート セキュリティサポート 延長サポート
1 注意 MariaDB 10.6 2026-06-30
2 注意 SQL Server 2016 Service Pack 2 2021-07-13 2026-07-14
3 Azul Zulu Builds of OpenJDK 26 2026-09-30
4 Oracle JDK 11 (LTS) 2023-09-30 2026-09-30
5 Python3.10 2026-10-31
2026-7-20 JST
メディア・ニュース
No イメージ 名前 URL 変更部分の抜粋 タグ
1 Ars Technica https://arstechnica.com/ 105,India’s first privately-developed rocket reaches orbit on dramatic debut launch,“On the first attempt, reaching orbit, I never thought it was possible.”,Stephen Clark,–,7/19/2026,|,8,As mosquito r ...
  • English
  • News
  • 海外
  • ブログ
  • サイト情報収集
2 Mashable https://mashable.com/ Look Up,NYT Connections hints today: Clues, answers for July 19, 2026,National Ice Cream Day 2026 deals: Score free food from Dairy Queen, Ben & Jerry's, Target, and more,Lawsuit says AI tool dispropo ...
  • English
  • News
  • 海外
  • ブログ
3 ScanNetSecurity https://scan.netsecurity.ne.jp/ 2026.07.20(月),高速バスに乗ったら運転士から私的なショートメール ~ 予約データを運行管理者から不正取得,サイバー攻撃による事業停止を最小限に ~ 演習を交えて実効性を高める中小企業向け BCP 策定支援,オーミケンシへのランサムウェア攻撃、外部のクラウドストレージサービスへのデータ送信を確認,GMOサイバーセキュリティ byイエラエ、陸上自衛隊システム通信・サイバー学校にセキュリティ ...
  • Japanese
  • News
  • 情報提供
4 ZDNet Japan セキュリティ https://japan.zdnet.com/security/ AIにパスワードを生成させてはいけない--パスワードジェネレーターの方がはるかに安全,2026-07-20 07:00,QRコードフィッシングが増加傾向に--身を守るために知っておくべきこと,「部屋を貸す」から「企業を理解する」営業へ--レオパレス21がユーソナーと挑む“営業文化改革”の全貌,ASUSが提案する、AIインフラ構築の“成功の方程式”,AI時代におけるERP設計の主流は「疎結合+イベン ...
  • Japanese
  • News
  • 情報提供