یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 760 نتیجه
فیلترهای فعال EPSS ≥ 50% پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

نامشخص CISA KEV EPSS 91.9% اولویت 44

CVE-2020-8657 — EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

EyesOfNetwork contains a use of hard-coded credentials vulnerability, as it uses the same API key by default. Exploitation allows an attacker to calculate or guess the admin access token.

EyesOfNetwork / EyesOfNetwork
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 74.0% اولویت 40

CVE-2018-18325 — DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability

DotNetNuke (DNN) contains an inadequate encryption strength vulnerability resulting from the use of a weak encryption algorithm to protect input parameters. This CVE ID resolves an incomplete patch for CVE-2018-15811.

DotNetNuke (DNN) / DotNetNuke (DNN)
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 88.4% اولویت 43

CVE-2020-8193 — Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated access to certain URL endpoints. The attacker must have access to the NetScaler IP (NSIP) in order to perform exploitation.

Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 99.9% اولویت 46

CVE-2019-1653 — Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.

Cisco / Small Business RV320 and RV325 Routers
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 83.7% اولویت 42

CVE-2020-3161 — Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.

Cisco / Cisco IP Phones
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 99.5% اولویت 46

CVE-2018-0171 — Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.

Cisco / IOS and IOS XE
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 100.0% اولویت 46

CVE-2021-1498 — Cisco HyperFlex HX Data Platform Command Injection Vulnerability

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.

Cisco / HyperFlex HX
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 99.9% اولویت 46

CVE-2021-1497 — Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.

Cisco / HyperFlex HX
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 99.9% اولویت 51

CVE-2019-3396 — Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability

Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.

Atlassian / Confluence Server and Data Server
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع
نامشخص CISA KEV EPSS 95.4% اولویت 50

CVE-2019-11580 — Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability

Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.

Atlassian / Crowd and Crowd Data Center
2021-11-0300:00
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 60/100 داده قدیمی جزئیات و راهکار رفع