یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 760 نتیجه
فیلترهای فعال EPSS ≥ 50% پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

بحرانی CISA KEV CVSS 9.0 EPSS 100.0% اولویت 94

CVE-2021-40438 — Apache HTTP Server-Side Request Forgery (SSRF)

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Oracle / resf / rocky linux Apache / Apache
2021-09-1615:15
4 منبع · 4 رسمی اعتماد خوب · 77/100 کیفیت خوب · 74/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 99.7% اولویت 99

CVE-2021-38647 — Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.

microsoft / azure automation state configuration Microsoft / Open Management Infrastructure (OMI)
2021-09-1512:15
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.8 EPSS 67.3% اولویت 75

CVE-2021-36934 — Microsoft Windows SAM Local Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete…

microsoft / windows 10 1809 Microsoft / Windows
2021-07-2207:15
4 منبع · 4 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 10.0 EPSS 99.7% اولویت 100

CVE-2021-22205 — GitLab Community and Enterprise Editions Remote Code Execution Vulnerability

GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.

gitlab / gitlab GitLab / Community and Enterprise Editions
2021-04-2318:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 78.3% اولویت 81

CVE-2021-21975 — VMware Server Side Request Forgery in vRealize Operations Manager API

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

vmware / cloud foundation VMware / vRealize Operations Manager API
2021-03-3118:15
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 65/100 داده قدیمی جزئیات و راهکار رفع
متوسط CISA KEV CVSS 6.1 EPSS 85.6% اولویت 75

CVE-2020-3580 — Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

Multiple vulnerabilities in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the web services interface of an affected device. The vulnerabilities are due to…

cisco / secure firewall threat defense Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
2020-10-2119:15
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 65/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 100.0% اولویت 81

CVE-2020-3452 — Cisco ASA and FTD Read-Only Path Traversal Vulnerability

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP…

cisco / adaptive security appliance software Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
2020-07-2220:15
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 65/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 69.3% اولویت 79

CVE-2020-3259 — Cisco ASA and FTD Information Disclosure Vulnerability

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking…

cisco / secure firewall threat defense Cisco / Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)
2020-05-0617:15
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 65/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 10.0 EPSS 99.8% اولویت 100

CVE-2020-0796 — Microsoft SMBv3 Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.

microsoft / windows 10 1903 Microsoft / SMBv3
2020-03-1216:15
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 100.0% اولویت 99

CVE-2019-19781 — Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability

Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an unspecified vulnerability that could allow an unauthenticated attacker to perform code execution.

citrix / application delivery controller firmware Citrix / Application Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance
2019-12-2714:15
3 منبع · 3 رسمی اعتماد خوب · 65/100 نیازمند توجه · 66/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.8 EPSS 73.9% اولویت 81

CVE-2019-1458 — Microsoft Win32k Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

microsoft / windows 10 1507 Microsoft / Win32k
2019-12-1022:15
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 100.0% اولویت 99

CVE-2019-2725 — Oracle WebLogic Server, Injection

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can…

oracle / agile plm Oracle / WebLogic Server
2019-04-2619:29
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 81.6% اولویت 82

CVE-2019-0752 — Microsoft Internet Explorer Type Confusion Vulnerability

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862.

microsoft / internet explorer Microsoft / Internet Explorer
2019-04-0921:29
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 99.9% اولویت 81

CVE-2018-0296 — Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is also possible on certain software releases that the ASA will not reload, but an attacker could view sensitive system…

cisco / adaptive security appliance software Cisco / Adaptive Security Appliance (ASA)
2018-06-0712:29
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 65/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 8.1 EPSS 99.6% اولویت 89

CVE-2017-12615 — Apache Tomcat on Windows Remote Code Execution Vulnerability

When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

Red Hat / Red Hat Enterprise Linux apache / tomcat
2017-09-1913:29
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 98.5% اولویت 99

CVE-2012-4681 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted…

Oracle / oracle / jdk Oracle / Java SE
2012-08-2800:55
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 93.7% اولویت 97

CVE-2012-1723 — Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

Oracle / oracle / jdk Oracle / Java SE
2012-06-1621:55
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
متوسط CISA KEV CVSS 6.5 EPSS 90.0% اولویت 78

CVE-2009-3960 — Adobe BlazeDS Information Disclosure Vulnerability

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external…

adobe / blazeds
2010-02-1518:30
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع