یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 760 نتیجه
فیلترهای فعال EPSS ≥ 50% پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

نامشخص CISA KEV EPSS 92.8% اولویت 48

CVE-2025-34291 — Langflow Origin Validation Error Vulnerability

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code…

Langflow / Langflow
2026-05-2100:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 82.2% اولویت 46

CVE-2010-0806 — Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Microsoft / Internet Explorer
2026-05-2000:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 91.9% اولویت 48

CVE-2010-0249 — Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Microsoft / Internet Explorer
2026-05-2000:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 86.6% اولویت 47

CVE-2009-3459 — Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

Adobe / Acrobat and Reader
2026-05-2000:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 51.2% اولویت 38

CVE-2009-1537 — Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

Microsoft / DirectX
2026-05-2000:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 98.8% اولویت 50

CVE-2008-4250 — Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

Microsoft / Windows
2026-05-2000:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 91.5% اولویت 48

CVE-2026-20182 — Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

Cisco / Catalyst SD-WAN
2026-05-1400:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CVSS 9.2 EPSS 66.0% اولویت 63

CVE-2026-42945 — CVE-2026-42945 — dos

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated…

nginx / nginx f5 / dos
2026-05-1316:16
4 منبع · 3 رسمی اعتماد خوب · 79/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV EPSS 98.5% اولویت 93

CVE-2026-41940 — WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

We have pushed out a patch for the following cPanel & WHM versions: 11.86.0.41 and higher 11.94.0.28 and higher 11.102.0.39 and higher 11.110.0.97 and higher 11.118.0.63 and higher 11.124.0.35 and higher 11.126.0.54 and higher 11.130.0.19 and higher 11.132.0.29 and higher 11.134.0.20 and higher 11.136.0.5 and higher

cPanel / cPanel & WHM WebPros / cPanel & WHM and WP2 (WordPress Squared)
2026-04-2816:19
3 منبع · 3 رسمی اعتماد خوب · 66/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 66.6% اولویت 47

CVE-2024-57726 — SimpleHelp Missing Authorization Vulnerability

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

SimpleHelp / SimpleHelp
2026-04-2400:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 64.7% اولویت 46

CVE-2024-57728 — SimpleHelp Path Traversal Vulnerability

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

SimpleHelp / SimpleHelp
2026-04-2400:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 87.9% اولویت 47

CVE-2025-29635 — D-Link DIR-823X Command Injection Vulnerability

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

D-Link / DIR-823X
2026-04-2400:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 59.3% اولویت 45

CVE-2023-21529 — Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.

Microsoft / Microsoft Products Microsoft / Exchange Server
2026-04-1300:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع