یادآوری: اطلاعات این سامانه از منابع معرفی‌شده گردآوری می‌شود. پیش از هر اقدام فنی، جزئیات را در منبع اصلی بررسی کنید.
پایگاه اطلاعات امنیتی

آسیب‌پذیری‌ها

آسیب‌پذیری‌ها را بر اساس دسته‌بندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.

فیلترهابا انتخاب دسته‌بندی، فهرست سازنده‌ها و محصولات مرتبط هم محدود می‌شود. راهنمای فیلترها

برای محدودکردن نتایج یک یا چند فیلتر را انتخاب کنید و سپس دکمه اعمال فیلتر را بزنید.

پاک کردن همه 34 نتیجه
فیلترهای فعال اولویت ≥ 85 پاک کردن همه
نمای سریع

فیلترهای آماده و نماهای ذخیره‌شده

بحرانی CISA KEV EPSS 98.5% اولویت 93

CVE-2026-41940 — WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability

We have pushed out a patch for the following cPanel & WHM versions: 11.86.0.41 and higher 11.94.0.28 and higher 11.102.0.39 and higher 11.110.0.97 and higher 11.118.0.63 and higher 11.124.0.35 and higher 11.126.0.54 and higher 11.130.0.19 and higher 11.132.0.29 and higher 11.134.0.20 and higher 11.136.0.5 and higher

cPanel / cPanel & WHM WebPros / cPanel & WHM and WP2 (WordPress Squared)
2026-04-2816:19
3 منبع · 3 رسمی اعتماد خوب · 66/100 نیازمند توجه · 61/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.3 EPSS 91.3% اولویت 85

CVE-2025-9242 — WatchGuard Firebox Out-of-Bounds Write Vulnerability

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. If the Firebox was previously configured with the mobile user…

watchguard / fireware WatchGuard / Firebox
2025-09-1708:15
3 منبع · 2 رسمی اعتماد خوب · 70/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 8.4 EPSS 94.1% اولویت 86

CVE-2025-8088 — RARLAB WinRAR Path Traversal Vulnerability

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

rarlab / winrar RARLAB / WinRAR
2025-08-0812:15
2 منبع · 2 رسمی اعتماد خوب · 64/100 نیازمند توجه · 65/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 94.1% اولویت 93

CVE-2024-55591 — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

fortinet / fortiproxy Fortinet / FortiOS and FortiProxy
2025-01-1400:00
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 94.0% اولویت 93

CVE-2024-55956 — Cleo Multiple Products Unauthenticated File Upload Vulnerability

Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

cleo / harmony Cleo / Multiple Products
2024-12-1321:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 10.0 EPSS 94.7% اولویت 94

CVE-2024-51378 — CyberPanel Incorrect Default Permissions Vulnerability

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in…

cyberpanel / cyberpanel CyberPersons / CyberPanel
2024-10-2923:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 99.5% اولویت 99

CVE-2024-23692 — Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of the CVE assignment date, Rejetto HFS 2.3m is no longer supported.

rejetto / http file server Rejetto / HTTP File Server
2024-05-3110:15
3 منبع · 2 رسمی اعتماد خوب · 70/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 8.6 EPSS 100.0% اولویت 92

CVE-2024-24919 — Check Point Quantum Security Gateways Information Disclosure Vulnerability

Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the internet, with IPSec VPN, Remote Access VPN or Mobile Access enabled. This issue affects several product lines from Check Point, including CloudGuard Network,…

checkpoint / quantum spark firmware Check Point / Quantum Security Gateways
2024-05-2819:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 94.7% اولویت 93

CVE-2024-21413 — Microsoft Outlook Improper Input Validation Vulnerability

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

Microsoft / Microsoft Products Microsoft / Office Outlook microsoft / 365 apps
2024-02-1318:16
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 8.1 EPSS 95.4% اولویت 88

CVE-2024-21412 — Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability

Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.

Microsoft / Microsoft Products Microsoft / Windows microsoft / windows 10 1809
2024-02-1300:00
3 منبع · 3 رسمی اعتماد خوب · 73/100 کیفیت خوب · 73/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 8.2 EPSS 82.1% اولویت 86

CVE-2023-41266 — Qlik Sense Path Traversal Vulnerability

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized…

qlik / qlik sense Qlik / Sense
2023-08-2923:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.6 EPSS 84.5% اولویت 94

CVE-2023-41265 — Qlik Sense HTTP Tunneling Vulnerability

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to…

qlik / qlik sense Qlik / Sense
2023-08-2923:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.8 EPSS 97.8% اولویت 87

CVE-2023-38831 — RARLAB WinRAR Code Execution Vulnerability

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable…

rarlab / winrar
2023-08-2317:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 100.0% اولویت 99

CVE-2023-35078 — Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a…

ivanti / endpoint manager mobile Ivanti / Endpoint Manager Mobile (EPMM)
2023-07-2500:00
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 99.7% اولویت 99

CVE-2023-3519 — Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.

citrix / netscaler application delivery controller Citrix / NetScaler ADC and NetScaler Gateway
2023-07-1900:00
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.5 EPSS 98.9% اولویت 86

CVE-2023-36884 — Microsoft Windows Search Remote Code Execution Vulnerability

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.

Microsoft / Microsoft Products Microsoft / Windows microsoft / windows 10 1507
2023-07-1119:15
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 67.9% اولویت 91

CVE-2023-28461 — Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability

Array Networks Array AG Series and vxAG (9.4.0.481 and earlier) allow remote code execution. An attacker can browse the filesystem on the SSL VPN gateway using a flags attribute in an HTTP header without authentication. The product could then be exploited through a vulnerable URL. The 2023-03-09 vendor advisory stated "a new Array AG release with the fix…

arraynetworks / arrayos ag Array Networks / AG/vxAG ArrayOS
2023-03-1523:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 7.2 EPSS 100.0% اولویت 85

CVE-2023-0669 — Fortra GoAnywhere MFT Remote Code Execution Vulnerability

Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

fortra / goanywhere managed file transfer Fortra / GoAnywhere MFT
2023-02-0620:15
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع
زیاد CISA KEV CVSS 8.8 EPSS 77.3% اولویت 88

CVE-2022-41080 — Microsoft Exchange Server Privilege Escalation Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.

Microsoft / Microsoft Products Microsoft / Exchange Server
2022-11-0922:15
3 منبع · 3 رسمی اعتماد خوب · 68/100 نیازمند توجه · 67/100 داده قدیمی جزئیات و راهکار رفع
بحرانی CISA KEV CVSS 9.8 EPSS 100.0% اولویت 99

CVE-2022-40684 — Fortinet Multiple Products Authentication Bypass Vulnerability

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted…

fortinet / fortiproxy Fortinet / Multiple Products
2022-10-1100:00
2 منبع · 2 رسمی اعتماد خوب · 69/100 کیفیت خوب · 71/100 داده قدیمی جزئیات و راهکار رفع