یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 1,384 نتیجه
فیلترهای فعال دسته: operating-systems پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

نامشخص CISA KEV EPSS 69.6% اولویت 38

CVE-2013-3896 — Microsoft Silverlight Information Disclosure Vulnerability

Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.

Microsoft / Silverlight
2022-05-2500:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
زیاد CVSS 7.1 EPSS 0.4% اولویت 39

CVE-2022-1353 — CVE-2022-1353 — linux kernel

A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.

Debian / Debian linux / linux kernel
2022-04-2916:15
2 منبع · 2 رسمی اعتماد خوب · 70/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
زیاد CVSS 7.0 EPSS 0.7% اولویت 39

CVE-2021-44733 — CVE-2021-44733 — linux kernel

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

Debian / Debian linux / linux kernel
2021-12-2217:15
2 منبع · 2 رسمی اعتماد خوب · 70/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.1 EPSS 10.3% اولویت 62

CVE-2021-43890 — Microsoft Windows AppX Installer Spoofing Vulnerability

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing…

Microsoft / Microsoft Products microsoft / app installer Microsoft / Windows
2021-12-1500:00
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 10.0 EPSS 100.0% اولویت 100

CVE-2021-44228 — Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP…

siemens / 6bk1602-0aa12-0tp0 firmware Apache / Log4j2
2021-12-1000:00
6 منبع · 5 رسمی اعتماد قوی · 82/100 کیفیت خوب · 76/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 83.4% اولویت 42

CVE-2010-1871 — Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.

Red Hat / JBoss Seam 2
2021-12-1000:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 74.3% اولویت 80

CVE-2021-42287 — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

Microsoft / Microsoft Products microsoft / windows server 2008 Microsoft / Active Directory
2021-11-1001:19
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 70.2% اولویت 79

CVE-2021-42278 — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.

Microsoft / Microsoft Products microsoft / windows server 2004 Microsoft / Active Directory
2021-11-1001:19
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
متوسط CVSS 6.8 اولویت 37

CVE-2021-40114 — CVE-2021-40114 — secure firewall management center

Multiple Cisco products are affected by a vulnerability in the way the Snort detection engine processes ICMP traffic that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper memory resource management while the Snort detection engine is processing ICMP…

cisco / secure firewall management center
2021-10-2719:15
2 منبع · 2 رسمی اعتماد خوب · 68/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع
زیاد CVSS 7.8 EPSS 0.4% اولویت 43

CVE-2021-41864 — CVE-2021-41864 — linux kernel

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

Debian / Debian linux / linux kernel
2021-10-0200:15
2 منبع · 2 رسمی اعتماد خوب · 70/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.0 EPSS 100.0% اولویت 94

CVE-2021-40438 — Apache HTTP Server-Side Request Forgery (SSRF)

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Oracle / resf / rocky linux Apache / Apache
2021-09-1615:15
4 منبع · 4 رسمی اعتماد خوب · 77/100 کیفیت خوب · 74/100 داده قدیمی جزئیات و راهکار رفع
زیاد CVSS 7.8 EPSS 0.3% اولویت 43

CVE-2021-38166 — CVE-2021-38166 — linux kernel

In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.

Debian / Debian linux / linux kernel
2021-08-0718:15
2 منبع · 2 رسمی اعتماد خوب · 70/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
متوسط CVSS 5.8 اولویت 32

CVE-2021-1495 — CVE-2021-1495 — secure firewall threat defense

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of specific HTTP header parameters. An attacker could exploit this vulnerability by sending crafted HTTP packets through an…

cisco / secure firewall threat defense
2021-04-2918:15
2 منبع · 2 رسمی اعتماد خوب · 68/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع
متوسط CVSS 5.3 اولویت 29

CVE-2021-1236 — CVE-2021-1236 — ios xe

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a flaw in the detection algorithm. An attacker could exploit this vulnerability by sending crafted packets that would flow…

cisco / ios xe
2021-01-1322:15
2 منبع · 2 رسمی اعتماد خوب · 68/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع
متوسط CVSS 5.8 اولویت 32

CVE-2021-1224 — CVE-2021-1224 — secure firewall management center

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect detection of the HTTP payload if it is contained at least partially within the TFO…

cisco / secure firewall management center
2021-01-1322:15
2 منبع · 2 رسمی اعتماد خوب · 68/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع