یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 760 نتیجه
فیلترهای فعال EPSS ≥ 50% پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

کم EPSS 79.7% اولویت 40

CVE-2023-38408 — https://errata.almalinux.org/8/ALSA-2026-69266.html

سلام، شما یک ایمیل به‌روزرسانی امنیتی AlmaLinux دریافت می‌کنید زیرا برای دریافت اعلان‌های خطا از AlmaLinux مشترک شده‌اید. AlmaLinux: 8 نوع: امنیتی شدت: مهم تاریخ انتشار: 2026-09-21 خلاصه: OpenSSH یک پیاده‌سازی پروتکل SSH است که توسط تعدادی از سیستم‌عامل‌های لینوکس، یونیکس و مشابه پشتیبانی می‌شود. این شامل فایل‌های اصلی لازم برای هر دو کلاینت OpenSSH و سرور…

OpenSSH / OpenSSH AlmaLinux / AlmaLinux
2026-09-2100:00
2 منبع · 2 رسمی اعتماد خوب · 76/100 کیفیت خوب · 78/100 داده تازه جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 62.5% اولویت 42

CVE-2025-62593 — آسیب‌پذیری تزریق کد ری در پروژه ری

پروژه ری (Ray-Project Ray) حاوی یک آسیب‌پذیری تزریق کد است که می‌تواند امکان اجرای کد از راه دور را فراهم کند. توسعه‌دهندگانی که از ری به عنوان یک ابزار توسعه استفاده می‌کنند، ممکن است در معرض این آسیب‌پذیری باشند که از طریق فایرفاکس و سافاری قابل بهره‌برداری است.

Ray-Project / Ray
2026-08-1700:00
3 منبع · 2 رسمی اعتماد خوب · 70/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص EPSS 62.6% اولویت 27

CVE-2019-11500 — CVE-2019-11500: تجزیه‌کننده‌های پروتکل IMAP و ManageSieve هنگام اسکن داده‌ها در رشته‌های نقل‌قول‌شده، بایت تهی را به درستی مدیریت نمی‌کنند.

28 Aug 2019CVE-2019-11500: IMAP and ManageSieve protocol parsers do not properly handle NUL byte when scanning data in quoted strings

Dovecot / Dovecot
2026-08-0717:46
1 منبع · 1 رسمی اعتماد متوسط · 51/100 نیازمند توجه · 50/100 داده قدیمی جزئیات و راهکار رفع
کم EPSS 63.5% اولویت 34

CVE-2016-0777 — CVE-2016-0777

January 14, 2016 OpenSSH clients between versions 5.4 and 7.1 are vulnerable to information disclosure that may allow a malicious server to retrieve information including under some circumstances, user's private keys. This may be mitigated by adding the undocumented config option UseRoaming no to ssh_config. For more information see CVE-2016-0777 and…

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 64/100 کیفیت خوب · 77/100 داده تازه جزئیات و راهکار رفع
کم EPSS 99.5% اولویت 41

CVE-2024-6387 — Qualys Security Advisory Team

July 1, 2024 sshd(8) in Portable OpenSSH versions 8.5p1 to 9.7p1 (inclusive). Race condition resulting in potential remote code execution. A race condition in sshd(8) could allow remote code execution as root on non-OpenBSD systems. This attack could be prevented by disabling the login grace timeout (LoginGraceTime=0 in sshd_config) though this makes…

OpenSSH / OpenSSH
2026-08-0717:41
1 منبع · 1 رسمی اعتماد خوب · 64/100 کیفیت خوب · 77/100 داده تازه جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.3 EPSS 78.0% اولویت 82

CVE-2026-16232 — Check Point SmartConsole Improper Authentication Vulnerability

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires…

checkpoint / multi-domain security management Check Point / SmartConsole
2026-07-2200:00
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 63.0% اولویت 42

CVE-2026-0770 — Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Langflow / Langflow
2026-07-2100:00
3 منبع · 2 رسمی اعتماد خوب · 70/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 76.1% اولویت 45

CVE-2026-25089 — Fortinet FortiSandbox OS Command Injection Vulnerability

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Fortinet / FortiSandbox
2026-07-1600:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 88.5% اولویت 47

CVE-2026-48908 — JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

JoomShaper / SP Page Builder
2026-07-0700:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 88.2% اولویت 47

CVE-2026-20230 — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.

Cisco / Unified Communications Manager
2026-06-2500:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 96.9% اولویت 49

CVE-2026-20253 — Splunk Enterprise Missing Authentication for Critical Function Vulnerability

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

Splunk / Enterprise
2026-06-1800:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 99.9% اولویت 50

CVE-2026-10520 — Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS…

Ivanti / Sentry
2026-06-1100:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.6 EPSS 77.4% اولویت 83

CVE-2026-8037 — Progress LoadMaster Command Injection Vulnerability

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

progress / connection manager for objectscale Progress / LoadMaster
2026-06-0414:16
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 65/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 74.2% اولویت 44

CVE-2024-21182 — Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

Oracle / Oracle / WebLogic Server
2026-06-0100:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع