約4万件の脆弱性から分析、2025年の危険な「脆弱性タイプ」トップ25
一方「Improper Privilege Management(CWE-269)」や「Improper Authentication(CWE-287)」など、前年まで上位に位置していた一部抽象度の高い脆弱性タイプはトップ25圏外となった。
2025年のトップ25は以下のとおり。
第1位:→:Cross-site Scripting(CWE-79)
第2位:↑:SQL Injection(CWE-89)
第3位:↑:Cross-Site Request Forgery(CWE-352)
第4位:↑:Missing Authorization(CWE-862)
第5位:↓:Out-of-bounds Write(CWE-787)
第6位:↓:Path Traversal(CWE-22)
第7位:↑:Use After Free(CWE-416)
第8位:↓:Out-of-bounds Read(CWE-125)
第9位:↓:OS Command Injection(CWE-78)
第10位:↑:Code Injection(CWE-94)
第11位:新:Classic Buffer Overflow(CWE-120)
第12位:↓:Unrestricted Upload of File with Dangerous Type(CWE-434)
第13位:↑:NULL Pointer Dereference(CWE-476)
第14位:新:Stack-based Buffer Overflow(CWE-121)
第15位:↑:Deserialization of Untrusted Data(CWE-502)
第16位:新:Heap-based Buffer Overflow(CWE-122)
第17位:↑:Incorrect Authorization(CWE-863)
第18位:↓:Improper Input Validation(CWE-20)
第19位:新:Improper Access Control(CWE-284)
第20位:↓:Exposure of Sensitive Information to an Unauthorized Actor(CWE-200)
第21位:↑:Missing Authentication for Critical Function(CWE-306)
第22位:↓:Server-Side Request Forgery(CWE-918)
第23位:↓:Command Injection(CWE-77)
第24位:↑:Authorization Bypass Through User-Controlled Key(CWE-639)
第25位:↑:Allocation of Resources Without Limits or Throttling(CWE-770)
(Security NEXT - 2025/12/25 )
ツイート
PR
関連記事
米当局「脆弱性悪用リスト」、7月に26件 - 8割超が3日以内対応
先週注目された記事(2026年7月26日〜2026年8月1日)
インシデント件数減少、ただしサイト改ざんは倍増
2026年2Qの脆弱性DB登録、約13%増となる1万3131件
2026年2Qの脆弱性届出、ソフト製品関連が3割増
先週注目された記事(2026年7月19日〜2026年7月25日)
先週注目された記事(2026年7月12日〜2026年7月18日)
先週注目された記事(2026年7月5日〜2026年7月11日)
先週注目された記事(2026年6月28日〜2026年7月4日)
先週注目された記事(2026年6月14日〜2026年6月20日)

