یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 288 نتیجه
فیلترهای فعال دسته: control-panels پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

زیاد CVSS 7.8 اولویت 40

CVE-2023-54125 — USN-8879-1: Linux kernel (Oracle) vulnerabilities

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Return error for inconsistent extended attributes ntfs_read_ea is called when we want to read extended attributes. There are some sanity checks for the validity of the EAs. However, it fails to return a proper error code for the inconsistent attributes, which might lead to…

Canonical / Ubuntu QEMU / QEMU
2025-12-2413:16
2 منبع · 2 رسمی اعتماد خوب · 69/100 نیازمند توجه · 67/100 داده تازه جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 88.6% اولویت 47

CVE-2025-61757 — Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.

Oracle / Oracle / Fusion Middleware
2025-11-2100:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص اولویت 8

Cannot install update on Plesk for Windows: The installation of the package 'plesk-modsecurity-module' failed with code 1603

Windows msiexec failed to update ModSecurity IIS module. Code 1603 is generic error, and issue could be caused by various reasons (which might be logged in Plesk autoinstaller3.log file).

Plesk / Plesk
2025-11-1215:41
1 منبع · 1 رسمی اعتماد متوسط · 51/100 نیازمند توجه · 50/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 95.9% اولویت 54

CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.

Oracle / Oracle / E-Business Suite
2025-10-2000:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 99.7% اولویت 55

CVE-2025-61882 — Oracle E-Business Suite Unspecified Vulnerability

Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.

Oracle / Oracle / E-Business Suite
2025-10-0600:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 100.0% اولویت 50

CVE-2024-38475 — Apache HTTP Server Improper Escaping of Output Vulnerability

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

Apache / HTTP Server
2025-05-0100:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 3.9% اولویت 26

CVE-2024-20953 — Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.

Oracle / Oracle / Agile Product Lifecycle Management (PLM)
2025-02-2400:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
کم اولویت 15

Adding CSP (Content Security Policy) headers to Wordpress

Question How can I add Content Security Policies to a WordPress installation? Answer Locate the functions.php file for your WordPress theme. Open functions.php with your favorite editor and add the following code: function add_custom_security_headers() { header("Strict-Transport-Security: max-age=31536000; includeSubDomains;…

cPanel / cPanel & WHM
2024-12-1620:06
1 منبع · 1 رسمی اعتماد متوسط · 57/100 نیازمند توجه · 62/100 داده تازه جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 1.7% اولویت 25

CVE-2024-21287 — Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.

Oracle / Oracle / Agile Product Lifecycle Management (PLM)
2024-11-2100:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 62.5% اولویت 37

CVE-2022-21445 — Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.

Oracle / Oracle / ADF Faces
2024-09-1800:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 94.5% اولویت 45

CVE-2020-14644 — Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.

Oracle / Oracle / WebLogic Server
2024-09-1800:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 96.3% اولویت 45

CVE-2017-3506 — Oracle WebLogic Server OS Command Injection Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.

Oracle / Oracle / WebLogic Server
2024-06-0300:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
متوسط CVSS 7.5 EPSS 0.8% اولویت 38

CVE-2024-23184 — CVE-2024-23184: داشتن تعداد زیادی هدر آدرس (از، به، رونوشت، رونوشت مخفی و غیره) به شدت CPU را درگیر می‌کند - dovecot - dovecot.org

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It…

Dovecot / Dovecot
2024-01-3000:00
1 منبع · 1 رسمی اعتماد متوسط · 43/100 کیفیت محدود · 49/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 93.2% اولویت 44

CVE-2020-2551 — Oracle Fusion Middleware Unspecified Vulnerability

Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.

Oracle / Oracle / Fusion Middleware
2023-11-1600:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 100.0% اولویت 81

CVE-2023-44487 — CVE-2023-44487 — simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

siemens / simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware IETF / HTTP/2
2023-10-1000:00
9 منبع · 8 رسمی اعتماد قوی · 82/100 کیفیت خوب · 76/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 92.3% اولویت 44

CVE-2016-3427 — Oracle Java SE and JRockit Unspecified Vulnerability

Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data…

Oracle / Oracle / Java SE and JRockit
2023-05-1200:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع