یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 760 نتیجه
فیلترهای فعال EPSS ≥ 50% پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

نامشخص CISA KEV EPSS 87.9% اولویت 47

CVE-2026-1603 — Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

Ivanti / Endpoint Manager (EPM)
2026-03-0900:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 99.7% اولویت 50

CVE-2021-22054 — Omnissa Workspace ONE Server-Side Request Forgery

Omnissa Workspace One UEM formerly known as VMware Workspace One UEM contains a server-side request forgery (SSRF) vulnerability that could allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.

Omnissa / Workspace One UEM
2026-03-0900:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 63.6% اولویت 41

CVE-2021-22681 — Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect…

Rockwell / Multiple Products
2026-03-0500:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 100.0% اولویت 50

CVE-2017-7921 — Hikvision Multiple Products Improper Authentication Vulnerability

Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.

Hikvision / Multiple Products
2026-03-0500:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 88.5% اولویت 47

CVE-2026-20127 — Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication…

Cisco / Catalyst SD-WAN Controller and Manager
2026-02-2500:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 98.9% اولویت 50

CVE-2025-49113 — RoundCube Webmail Deserialization of Untrusted Data Vulnerability

RoundCube Webmail contains a deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php.

Roundcube / Webmail
2026-02-2000:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 55.1% اولویت 39

CVE-2026-2441 — Google Chromium CSS Use-After-Free Vulnerability

Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Google / Chromium
2026-02-1700:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 76.6% اولویت 44

CVE-2008-0015 — Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the…

Microsoft / Windows
2026-02-1700:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 90.9% اولویت 53

CVE-2026-1731 — BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise,…

BeyondTrust / Remote Support (RS) and Privileged Remote Access (PRA)
2026-02-1300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 80.9% اولویت 45

CVE-2024-43468 — Microsoft Configuration Manager SQL Injection Vulnerability

Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.

Microsoft / Microsoft Products Microsoft / Configuration Manager
2026-02-1200:00
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 62/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 88.2% اولویت 52

CVE-2026-24423 — SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability

SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS command and could lead to command execution.

SmarterTools / SmarterMail
2026-02-0500:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 94.0% اولویت 48

CVE-2025-11953 — React Native Community CLI OS Command Injection Vulnerability

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

React Native Community / CLI
2026-02-0500:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 84.2% اولویت 46

CVE-2025-40551 — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

SolarWinds / Web Help Desk
2026-02-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع