NVD脆弱性情報トップ
検索メニュー表示
ベンダー名
プロダクト・サービス名
タイトル
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
公表日降順
更新日降順
表示数

NVD(National Vulnerability Database)で管理されている脆弱性の一覧を検索することが出来ます。
JVN(Japan Vulnerability Note)より先に脆弱性情報が更新される事が多いため、JVNに未記載の脆弱性が更新されている場合があります。

JVN(Japan Vulnerability Note)に関連した脆弱性がある場合は詳細画面で情報を表示します。

CWEで検索する場合は、CWE概要を参照して、CWE番号を確認してください。

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

更新日:2026年4月26日4:08

No CVSS レベル
攻撃区分
ベンダー名 プロダクト名 タイトル CWE CVE 更新日 公表日 影響表示 Exploit
PoC
検索
351 6.5 MEDIUM
ネットワーク
totolink a3300r_firmware An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the user parameter to /cgi-bin/cstecgi.cgi. New CWE-77
コマンドインジェクション
CVE-2026-31172 2026-04-25 00:12 2026-04-24 表示 GitHub Exploit DB Packet Storm
352 6.5 MEDIUM
ネットワーク
totolink a3300r_firmware An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the informEnable parameter to /cgi-bin/cstecgi.cgi. New CWE-77
コマンドインジェクション
CVE-2026-31174 2026-04-25 00:12 2026-04-24 表示 GitHub Exploit DB Packet Storm
353 9.8 CRITICAL
ネットワーク
totolink a3300r_firmware An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunEnable parameter to /cgi-bin/cstecgi.cgi. New CWE-77
コマンドインジェクション
CVE-2026-31175 2026-04-25 00:12 2026-04-24 表示 GitHub Exploit DB Packet Storm
354 6.5 MEDIUM
ネットワーク
totolink a3300r_firmware An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun_user parameter to /cgi-bin/cstecgi.cgi. New CWE-77
コマンドインジェクション
CVE-2026-31176 2026-04-25 00:12 2026-04-24 表示 GitHub Exploit DB Packet Storm
355 9.8 CRITICAL
ネットワーク
wwbn avideo WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` para… Update CWE-77
コマンドインジェクション
CVE-2026-41304 2026-04-25 00:11 2026-04-22 表示 GitHub Exploit DB Packet Storm
356 9.3 CRITICAL
ネットワーク
wwbn avideo WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `cu… Update CWE-78
OSコマンド・インジェクション
CVE-2026-41064 2026-04-25 00:10 2026-04-22 表示 GitHub Exploit DB Packet Storm
357 5.4 MEDIUM
ネットワーク
wwbn avideo WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override … Update CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-41063 2026-04-25 00:08 2026-04-22 表示 GitHub Exploit DB Packet Storm
358 6.5 MEDIUM
ネットワーク
wwbn avideo WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVideoEncoderReceiveImage.json.php` only checks the U… Update CWE-22
パス・トラバーサル
CVE-2026-41062 2026-04-25 00:08 2026-04-22 表示 GitHub Exploit DB Packet Storm
359 5.4 MEDIUM
ネットワーク
wwbn avideo WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor,… Update CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-41061 2026-04-25 00:08 2026-04-22 表示 GitHub Exploit DB Packet Storm
360 6.5 MEDIUM
ネットワーク
wwbn avideo WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows a… Update CWE-918
サーバサイドリクエストフォージェリ
CVE-2026-41060 2026-04-25 00:08 2026-04-22 表示 GitHub Exploit DB Packet Storm
361 8.1 HIGH
ネットワーク
wwbn avideo WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()`… Update CWE-22
パス・トラバーサル
CVE-2026-41058 2026-04-25 00:07 2026-04-22 表示 GitHub Exploit DB Packet Storm
362 7.1 HIGH
ネットワーク
wwbn avideo WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` … Update CWE-346
同一生成元ポリシー違反
CVE-2026-41057 2026-04-25 00:07 2026-04-22 表示 GitHub Exploit DB Packet Storm
363 7.8 HIGH
ローカル
- - radare2 prior to 6.1.4 contains a command injection vulnerability in the PDB parser's print_gvars() function that allows attackers to execute arbitrary commands by crafting a malicious PDB file with … New CWE-78
OSコマンド・インジェクション
CVE-2026-40517 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
364 8.1 HIGH
ネットワーク
- - Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.20 and 6.13.0, manipulating query parameters on Control Panel and REST API endpoints, or arguments in Gra… New CWE-470
クラスまたはコードを選択する外部から制御された入力の使用
CVE-2026-41175 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
365 - -
- - pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires… New CWE-789
過剰なサイズ値のメモリ割り当て
CVE-2026-41312 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
366 - -
- - pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to long runtimes. This requires loading a… New CWE-834
過度なイテレーション
CVE-2026-41313 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
367 - -
- - pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF which leads to the RAM being exhausted. This requires… New CWE-789
過剰なサイズ値のメモリ割り当て
CVE-2026-41314 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
368 5.5 MEDIUM
ネットワーク
- - IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A privileged user could uploa… New CWE-434
危険なタイプのファイルの無制限アップロード
CVE-2025-36074 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
369 2.7 LOW
ネットワーク
- - IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel. New CWE-613
不適切なセッション期限
CVE-2026-1272 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
370 4.9 MEDIUM
ネットワーク
- - IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel. New CWE-840
ビジネスロジックエラー
CVE-2026-1274 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
371 6.5 MEDIUM
ネットワーク
- - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutr… New CWE-1284
入力で指定された数量の不適切な検証
CVE-2026-1352 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
372 4.8 MEDIUM
ネットワーク
- - IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 New CWE-269
不適切な権限管理
CVE-2026-1726 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
373 9.8 CRITICAL
ネットワーク
- - In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with a generated token when an OA… New CWE-89
SQLインジェクション
CVE-2026-29198 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
374 7.8 HIGH
ローカル
- - The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCam… New CWE-427
制御されていない検索パスの要素
CVE-2026-32679 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
375 7.5 HIGH
ネットワーク
- - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application is deploy… New CWE-269
不適切な権限管理
CVE-2026-3621 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
376 7.5 HIGH
ネットワーク
- - A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the operating system. New CWE-22
パス・トラバーサル
CVE-2026-40062 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
377 - -
- - Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate … New CWE-306
重要な機能に対する認証の欠如 解説
CVE-2026-41176 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
378 - -
- - Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version 1.73.5, the RC endpoint `operations/fsinf… New CWE-78
CWE-306
OSコマンド・インジェクション
重要な機能に対する認証の欠如 解説
CVE-2026-41179 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
379 4.9 MEDIUM
ネットワーク
- - IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../… New CWE-22
パス・トラバーサル
CVE-2026-4917 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
380 5.5 MEDIUM
ネットワーク
- - IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the int… New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4918 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
381 4.8 MEDIUM
ネットワーク
- - IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI thus altering the intended f… New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-4919 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
382 6.5 MEDIUM
ネットワーク
- - IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Acce… New CWE-327
不完全、または危険な暗号アルゴリズムの使用
CVE-2026-5926 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
383 7.3 HIGH
ネットワーク
- - IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with normal user privileges on the system due … New CWE-78
OSコマンド・インジェクション
CVE-2026-5935 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
384 7.5 HIGH
ネットワーク
- - PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates the mounted request path using the still-encoded `re… New CWE-22
パス・トラバーサル
CVE-2026-41180 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
385 5.3 MEDIUM
ネットワーク
- - LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redacti… New CWE-200
CWE-359
CWE-532
情報漏えい
認可されていないアクターへの個人情報の漏えい
ログファイルからの情報漏えい
CVE-2026-41182 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
386 - -
- - Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape the sandboxed Lua environment to… New CWE-94
コード・インジェクション
CVE-2026-41196 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
387 - -
- - Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode ACIR uses for non-determinism. Noir programs can i… New CWE-131
正しくないバッファサイズ計算
CVE-2026-41197 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
388 - -
- - PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The plugin security validator in PySpector uses AST-based static analysis to preve… New CWE-184
不完全なブラックリスト
CVE-2026-41206 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
389 - -
- - Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A… New CWE-22
パス・トラバーサル
CVE-2026-41211 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
390 - -
- - STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scrip… New CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2026-41200 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
391 8.8 HIGH
ネットワーク
- - Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 contain a privilege escalation vulnerability th… New CWE-78
OSコマンド・インジェクション
CVE-2026-41208 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
392 - -
- - OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but … New CWE-284
不適切なアクセス制御
CVE-2026-41243 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
393 10.0 CRITICAL
ネットワーク
- - Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on … New CWE-287
CWE-862
CWE-1188
不適切な認証
認証の欠如
リソースの安全ではないデフォルト値への初期化
CVE-2026-41679 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
394 5.4 MEDIUM
ネットワーク
- - Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to Koollab LMS’ courselet fe… New - CVE-2026-3007 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
395 7.5 HIGH
ネットワーク
- - Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` pa… New CWE-59
リンク解釈の問題
CVE-2026-41231 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
396 9.9 CRITICAL
ネットワーク
- - Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against… New CWE-98
PHP リモートファイルインクルージョン
CVE-2026-41228 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
397 9.1 CRITICAL
ネットワーク
- - Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single qu… New CWE-94
コード・インジェクション
CVE-2026-41229 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
398 8.5 HIGH
ネットワーク
- - Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline characters in … New CWE-93
CRLF インジェクション
CVE-2026-41230 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
399 5.0 MEDIUM
ネットワーク
- - Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong array index when s… New CWE-863
不正な認証
CVE-2026-41232 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm
400 5.4 MEDIUM
ネットワーク
- - Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation when the calling res… New CWE-863
不正な認証
CVE-2026-41233 2026-04-24 23:50 2026-04-23 表示 GitHub Exploit DB Packet Storm