یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 288 نتیجه
فیلترهای فعال دسته: control-panels پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

نامشخص CISA KEV EPSS 9.4% اولویت 32

CVE-2026-35273 — Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability

Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.

Oracle / Oracle / PeopleSoft Enterprise PeopleTools
2026-06-1200:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CVSS 10.0 اولویت 55

CVE-2026-49261 — CVE-2026-49261 — mariadb

MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_cmd` enabled would execute shell commands embedded in the name of the joiner node. This is fixed in 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2. As a…

mariadb / mariadb
2026-06-1118:16
3 منبع · 2 رسمی اعتماد خوب · 73/100 نیازمند توجه · 63/100 داده قدیمی جزئیات و راهکار رفع
زیاد CVSS 7.5 EPSS 1.0% اولویت 41

CVE-2026-42536 — CVE-2026-42536 — http server

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Apache Software Foundation / Apache HTTP Server apache / http server
2026-06-0816:16
3 منبع · 3 رسمی اعتماد خوب · 74/100 نیازمند توجه · 69/100 داده قدیمی جزئیات و راهکار رفع
زیاد CVSS 7.5 EPSS 1.1% اولویت 42

CVE-2026-34355 — CVE-2026-34355 — http server

A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.

Apache Software Foundation / Apache HTTP Server apache / http server
2026-06-0816:16
3 منبع · 3 رسمی اعتماد خوب · 74/100 نیازمند توجه · 69/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 74.2% اولویت 44

CVE-2024-21182 — Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

Oracle / Oracle / WebLogic Server
2026-06-0100:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV EPSS 0.8% اولویت 55

CVE-2026-54420 — LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability

A vulnerability in the LiteSpeed cPanel plugin allows a user with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.

LiteSpeed Technologies / LiteSpeed Products LiteSpeed / cPanel Plugin
2026-05-3100:00
3 منبع · 3 رسمی اعتماد خوب · 69/100 نیازمند توجه · 67/100 در حال قدیمی‌شدن جزئیات و راهکار رفع
بحرانی CVSS 9.2 EPSS 10.1% اولویت 49

CVE-2026-9256 — CVE-2026-9256 — nginx open source

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a…

nginx / nginx f5 / nginx open source
2026-05-2215:16
3 منبع · 3 رسمی اعتماد خوب · 74/100 نیازمند توجه · 69/100 داده قدیمی جزئیات و راهکار رفع
کم اولویت 15

How and where can I receive cPanel/WHM Security Notices?

Question How and where can I receive cPanel/WHM Security Notices? Answer cPanel may occasionally send Security Notices. The emails will come from the following email address: [email protected]. Please be sure to check your spam folder and/or whitelist it so you can receive emails in your inbox. The message will be sent to your contact address, which…

cPanel / cPanel & WHM
2026-05-2102:18
1 منبع · 1 رسمی اعتماد متوسط · 51/100 نیازمند توجه · 50/100 داده قدیمی جزئیات و راهکار رفع
زیاد اولویت 38

Security¶

Security

LiteSpeed Technologies / LiteSpeed Web Server
2026-05-1900:00
1 منبع · 1 رسمی اعتماد متوسط · 57/100 نیازمند توجه · 62/100 داده تازه جزئیات و راهکار رفع
زیاد CISA KEV EPSS 1.0% اولویت 55

CVE-2026-48172 — LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

Any cPanel user (including an attacker or a compromised account) may exploit the lsws.redisAble function to execute arbitrary scripts as root. This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions between v2.3 and v2.4.4.

LiteSpeed Technologies / LiteSpeed Products LiteSpeed / cPanel Plugin
2026-05-1900:00
3 منبع · 3 رسمی اعتماد خوب · 69/100 نیازمند توجه · 67/100 در حال قدیمی‌شدن جزئیات و راهکار رفع
زیاد CVSS 8.2 اولویت 45

CVE-2026-32992 — CVE-2026-32992 — cpanel

SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the request and capture credentials.

cpanel / cpanel
2026-05-1322:16
2 منبع · 2 رسمی اعتماد خوب · 68/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع
زیاد CVSS 8.6 اولویت 47

CVE-2026-29205 — CVE-2026-29205 — cpanel

Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdavd attachment download endpoints.

cpanel / cpanel
2026-05-1322:16
2 منبع · 2 رسمی اعتماد خوب · 68/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CVSS 9.2 EPSS 66.0% اولویت 63

CVE-2026-42945 — CVE-2026-42945 — dos

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated…

nginx / nginx f5 / dos
2026-05-1316:16
4 منبع · 3 رسمی اعتماد خوب · 79/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
زیاد اولویت 38

ec9762281cbfc9406f9e0e656f693d64107e2632

LiteSpeed Documentation GitHub Get Started Get Started Welcome LiteSpeed Web Server LiteSpeed Web Server Overview Trial License Installation Installation Standalone Installation One-Click Installation Updates Changelog Changelog Table of contents Version 6.4 Release Candidates RC1 Build 1 Build 0 Version 6.3.6 Build 6 Build 5 Build 4 Build 3 Build 2 Build 1…

LiteSpeed Technologies / LiteSpeed Web Server
2026-05-0100:00
1 منبع · 1 رسمی اعتماد متوسط · 57/100 نیازمند توجه · 62/100 داده تازه جزئیات و راهکار رفع
بحرانی CISA KEV EPSS 98.5% اولویت 93

CVE-2026-41940 — WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

We have pushed out a patch for the following cPanel & WHM versions: 11.86.0.41 and higher 11.94.0.28 and higher 11.102.0.39 and higher 11.110.0.97 and higher 11.118.0.63 and higher 11.124.0.35 and higher 11.126.0.54 and higher 11.130.0.19 and higher 11.132.0.29 and higher 11.134.0.20 and higher 11.136.0.5 and higher

cPanel / cPanel & WHM WebPros / cPanel & WHM and WP2 (WordPress Squared)
2026-04-2816:19
3 منبع · 3 رسمی اعتماد خوب · 66/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع
کم اولویت 15

How to hide the SecurityRisk score label in Wordpress Toolkit for Plesk?

Applicable to: Plesk for Linux Plesk for Windows Question How to hide the SecurityRisk score label in WP Toolkit for Plesk? Answer For Linux Log in to Plesk. Install the Panel.ini Editor from the Extensions menu (if not already installed). Open Panel.ini Editor at Extensions > My Extensions. In Panel.ini Editor, switch to the Editor tab. If…

Plesk / Plesk
2026-04-2322:23
1 منبع · 1 رسمی اعتماد متوسط · 51/100 نیازمند توجه · 50/100 داده قدیمی جزئیات و راهکار رفع
کم EPSS 0.3% اولویت 17

CVE-2026-27860 — CVE-2026-27860.md: v2.4/v3.1 regression: auth-ldap is not escaping usernames. If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication.

Security ​Dovecot was designed since the beginning with security in mind and with many ways to provide privilege separation. Although the code is written with C, it’s a little bit special C variant that makes it much more difficult to write security holes accidentally than with most other C-based projects.Please see bugreport-mail for more information how…

Dovecot / Dovecot
2026-03-2700:00
1 منبع · 1 رسمی اعتماد متوسط · 48/100 نیازمند توجه · 50/100 داده قدیمی جزئیات و راهکار رفع