🛡️ مركز معلومات الثغرات
قاعدة بيانات الثغرات والتهديدات الأمنية المحدّثة
| المعرّف | الخطورة | CVSS | الوصف | الحالة | النشر |
|---|---|---|---|---|---|
| CVE-2026-1626 | متوسط | 6.5 |
An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or ma…
|
— | فبراير 27, 2026 |
| CVE-2026-3255 | متوسط | 6.5 |
HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function.
The HTTP…
|
— | فبراير 27, 2026 |
| CVE-2026-28354 | متوسط | 6.5 |
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne…
|
⚡ Exploit | فبراير 27, 2026 |
| CVE-2026-28352 | متوسط | 6.5 |
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers…
|
— | فبراير 27, 2026 |
| CVE-2026-28271 | متوسط | 6.5 |
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functional…
|
— | فبراير 27, 2026 |
| CVE-2026-27773 | متوسط | 6.5 |
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
|
— | فبراير 27, 2026 |
| CVE-2026-27734 | متوسط | 6.5 |
Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c…
|
— | فبراير 27, 2026 |
| CVE-2026-20733 | متوسط | 6.5 |
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
|
— | فبراير 27, 2026 |
| CVE-2026-22890 | متوسط | 6.5 |
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
|
— | فبراير 27, 2026 |
| CVE-2026-22878 | متوسط | 6.5 |
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
|
— | فبراير 27, 2026 |
| CVE-2026-24488 | متوسط | 6.5 |
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up …
|
— | فبراير 27, 2026 |
| CVE-2024-10938 | متوسط | 6.5 |
The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives …
|
— | فبراير 27, 2026 |
| CVE-2026-25774 | متوسط | 6.5 |
Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
|
— | فبراير 27, 2026 |
| CVE-2026-27793 | متوسط | 6.5 |
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G…
|
— | فبراير 27, 2026 |
| CVE-2026-27754 | متوسط | 6.5 |
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for sessio…
|
— | فبراير 27, 2026 |
| CVE-2026-27753 | متوسط | 6.5 |
SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication bypass vulnerability that allows re…
|
— | فبراير 27, 2026 |
| CVE-2026-2362 | متوسط | 6.4 |
The WP Accessibility plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'alt' attribute…
|
— | فبراير 27, 2026 |
| CVE-2026-2383 | متوسط | 6.4 |
The Simple Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field in all ve…
|
— | فبراير 27, 2026 |
| CVE-2025-14040 | متوسط | 6.4 |
The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th…
|
— | فبراير 27, 2026 |
| CVE-2025-14142 | متوسط | 6.4 |
The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t…
|
— | فبراير 27, 2026 |