🛡️ مركز معلومات الثغرات
قاعدة بيانات الثغرات والتهديدات الأمنية المحدّثة
| المعرّف | الخطورة | CVSS | الوصف | الحالة | النشر |
|---|---|---|---|---|---|
| CVE-2026-5251 | متوسط | 6.3 |
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user…
|
— | أبريل 1, 2026 |
| CVE-2024-58342 | متوسط | 6.3 |
XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does…
|
— | أبريل 1, 2026 |
| CVE-2026-5248 | متوسط | 6.3 |
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app…
|
— | أبريل 1, 2026 |
| CVE-2025-71280 | متوسط | 6.2 |
XenForo before 2.3.7 allows information disclosure via local account page caching on shared systems. On systems where mu…
|
— | أبريل 1, 2026 |
| CVE-2026-35055 | متوسط | 6.1 |
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. A…
|
— | أبريل 1, 2026 |
| CVE-2026-20085 | متوسط | 6.1 |
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to co…
|
— | أبريل 1, 2026 |
| CVE-2026-20041 | متوسط | 6.1 |
A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attac…
|
— | أبريل 1, 2026 |
| CVE-2026-3877 | متوسط | 6.1 |
A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution a…
|
⚡ Exploit | أبريل 1, 2026 |
| CVE-2025-13916 | متوسط | 5.9 |
IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker t…
|
— | أبريل 1, 2026 |
| CVE-2025-66484 | متوسط | 5.5 |
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to …
|
— | أبريل 1, 2026 |
| CVE-2026-4364 | متوسط | 5.4 |
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 …
|
— | أبريل 1, 2026 |
| CVE-2025-66485 | متوسط | 5.4 |
IBM Aspera Shares 1.9.9 through 1.11.0 is vulnerable to HTTP header injection, caused by improper validation of input by…
|
— | أبريل 1, 2026 |
| CVE-2026-5312 | متوسط | 5.3 |
A weakness has been identified in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, D…
|
— | أبريل 1, 2026 |
| CVE-2026-5311 | متوسط | 5.3 |
A security flaw has been discovered in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-32…
|
— | أبريل 1, 2026 |
| CVE-2026-1491 | متوسط | 5.3 |
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 …
|
— | أبريل 1, 2026 |
| CVE-2026-2862 | متوسط | 5.3 |
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 …
|
— | أبريل 1, 2026 |
| CVE-2026-34510 | متوسط | 5.3 |
OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file…
|
— | أبريل 1, 2026 |
| CVE-2026-34999 | متوسط | 5.3 |
OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that al…
|
— | أبريل 1, 2026 |
| CVE-2026-21861 | حرج | 9.1 |
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerabi…
|
⚡ Exploit | مارس 31, 2026 |
| CVE-2026-30877 | حرج | 9.1 |
baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in t…
|
— | مارس 31, 2026 |