📧 info@ciso.sa | 📱 +966550939344 | الرياض، المملكة العربية السعودية
🔧 صيانة مجدولة — السبت 2:00-4:00 صباحاً. قد تكون بعض الميزات غير متاحة مؤقتاً.    ●   
💎
خطة Pro بخصم 50% احصل على جميع ميزات AI والتقارير غير المحدودة والدعم ذي الأولوية. ترقّ الآن
مركز البحث
ESC للإغلاق
Global data_breach تكنولوجيا التعليم CRITICAL 10h Global malware الخدمات المالية CRITICAL 12h Global data_breach التكنولوجيا / الخدمات السحابية HIGH 14h Global phishing تطبيقات الهاتف المحمول / تكنولوجيا المستهلك HIGH 15h Global malware,apt,vulnerability البنية التحتية الحرجة، النقل، الفضاء والطيران HIGH 16h Global general عمليات الأمن السيبراني HIGH 16h Global supply_chain أمان البرمجيات CRITICAL 17h Global vulnerability التكنولوجيا والبرمجيات HIGH 17h Global vulnerability القطاع الحكومي CRITICAL 18h Global ransomware التعليم CRITICAL 18h Global data_breach تكنولوجيا التعليم CRITICAL 10h Global malware الخدمات المالية CRITICAL 12h Global data_breach التكنولوجيا / الخدمات السحابية HIGH 14h Global phishing تطبيقات الهاتف المحمول / تكنولوجيا المستهلك HIGH 15h Global malware,apt,vulnerability البنية التحتية الحرجة، النقل، الفضاء والطيران HIGH 16h Global general عمليات الأمن السيبراني HIGH 16h Global supply_chain أمان البرمجيات CRITICAL 17h Global vulnerability التكنولوجيا والبرمجيات HIGH 17h Global vulnerability القطاع الحكومي CRITICAL 18h Global ransomware التعليم CRITICAL 18h Global data_breach تكنولوجيا التعليم CRITICAL 10h Global malware الخدمات المالية CRITICAL 12h Global data_breach التكنولوجيا / الخدمات السحابية HIGH 14h Global phishing تطبيقات الهاتف المحمول / تكنولوجيا المستهلك HIGH 15h Global malware,apt,vulnerability البنية التحتية الحرجة، النقل، الفضاء والطيران HIGH 16h Global general عمليات الأمن السيبراني HIGH 16h Global supply_chain أمان البرمجيات CRITICAL 17h Global vulnerability التكنولوجيا والبرمجيات HIGH 17h Global vulnerability القطاع الحكومي CRITICAL 18h Global ransomware التعليم CRITICAL 18h
📅 النشرة الأمنية اليومية — 02 Mar 2026

🇸🇦 النشرة الأمنية السعودية

جميع الثغرات الأمنية والتهديدات والأخبار المجمّعة اليوم من مصادر موثوقة — محدّث باستمرار

26 ثغرة
0 تهديد
1 خبر
1 CISA KEV
🛡 الثغرات الأمنية (CVE)
26 ثغرة
CVE-2025-52468
Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importi
02:48 KSA
عالٍ CVSS 8.8 CWE-79
Chamilo is a learning management system. Prior to version 1.11.30, an input validation vulnerability exists when importing user data from CSV files. This flaw occurs due to insufficient sanitization of user data, specifically in the "Last Name", "First Name", and "Username" field…
CVE-2026-21385
Memory corruption while using alignments for memory allocation.
07:01 KSA
عالٍ CVSS 7.8 ⚠ CISA KEV CWE-190
Memory corruption while using alignments for memory allocation.
CVE-2025-64427
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prio
02:48 KSA
عالٍ CVSS 7.1 CWE-200
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0…
CVE-2025-47371
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
02:48 KSA
متوسط CVSS 6.5 CWE-617
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
CVE-2026-28396
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not rev
02:48 KSA
متوسط CVSS 6.5 CWE-613
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not revoke existing refresh tokens, allowing an attacker with a previously stolen refresh token to continue minting valid JWTs after the victim resets their password. …
CVE-2025-47384
Transient DOS when MAC configures config id greater than supported maximum value.
02:48 KSA
متوسط CVSS 6.5 CWE-617
Transient DOS when MAC configures config id greater than supported maximum value.
CVE-2026-2583
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in a
02:48 KSA
متوسط CVSS 6.4 CWE-79
The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `blocksy_meta` metadata fields in all versions up to, and including, 2.1.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co…
CVE-2025-15597
A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps
02:48 KSA
متوسط CVSS 6.3 CWE-266
A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of the component API Endpoint. Such manipulation leads to improper access controls. It is possible to launch the attack remotely. The e…
CVE-2026-28361
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not valid
02:48 KSA
متوسط CVSS 6.3 CWE-639
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the MCP token service did not validate token ownership, allowing a Creator within the same base to read, regenerate, or delete another user's MCP tokens if the token ID was known. This issue has …
CVE-2026-0012
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in
02:48 KSA
متوسط CVSS 6.2 CWE-284
In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0005
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing lim
02:48 KSA
متوسط CVSS 6.2 CWE-200
In onServiceDisconnected of KeyguardServiceDelegate.java, there is a possible partial bypass of app pinning allowing limited interaction with other apps without knowing the LSKF due to a missing permission check. This could lead to local information disclosure where the extent of…
CVE-2025-52475
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne
02:48 KSA
متوسط CVSS 6.1 CWE-79
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability in the admin/user_list.php endpoint. The keyword_inactive parameter is not properly sanitized, allowing attackers to inject malicious JavaScript throug…
CVE-2025-52564
Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sani
02:48 KSA
متوسط CVSS 6.1 CWE-80
Chamilo is a learning management system. Prior to version 1.11.30, the open parameter of help.php fails to properly sanitize user input. This allows an attacker to inject arbitrary HTML, such as underlined text, via a crafted URL. This issue has been patched in version 1.11.30.
CVE-2025-52563
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne
02:48 KSA
متوسط CVSS 6.1 CWE-79
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to insufficient sanitization of the page parameter in the session/add_users_to_session.php endpoint. This issue has been patched in version 1.11.30…
CVE-2025-52476
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulne
02:48 KSA
متوسط CVSS 6.1 CWE-79
Chamilo is a learning management system. Prior to version 1.11.30, there is a reflected cross-site scripting (XSS) vulnerability due to improper sanitization of the keyword_active parameter in admin/user_list.php. This issue has been patched in version 1.11.30.
CVE-2025-48642
In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This coul
02:48 KSA
متوسط CVSS 5.5 CWE-200
In jump_to_payload of payload.rs, there is a possible information disclosure due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-48644
In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lea
02:48 KSA
متوسط CVSS 5.5 CWE-20
In multiple locations, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28357
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, a stored XSS vulnerability exists i
02:48 KSA
متوسط CVSS 5.4 CWE-79
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, a stored XSS vulnerability exists in the Formula virtual cell. Formula results containing URI::() patterns are rendered via v-html without sanitization, allowing injected HTML to execute. This is…
CVE-2026-28401
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via
02:48 KSA
متوسط CVSS 5.4 CWE-79
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, rich text cell content rendered via v-html without sanitization enables stored XSS. This issue has been patched in version 0.301.3.
CVE-2026-28359
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor r
02:48 KSA
متوسط CVSS 5.4 CWE-79
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor role can inject arbitrary HTML into Rich Text cells by bypassing the TipTap editor and sending raw HTML via the API. This issue has been patched in version 0.301…
CVE-2026-28398
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments
02:48 KSA
متوسط CVSS 5.4 CWE-79
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, user-controlled content in comments and rich text cells was rendered via v-html without sanitization, enabling stored XSS. This issue has been patched in version 0.301.3.
CVE-2026-28397
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html withou
02:48 KSA
متوسط CVSS 5.4 CWE-79
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, comments rendered via v-html without sanitization enable stored XSS. This issue has been patched in version 0.301.3.
CVE-2026-27631
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada
02:48 KSA
متوسط CVSS 5.3 CWE-248
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. Prior to version 0.28.8, an uncaught exception was found in Exiv2. The vulnerability is in the preview component, which is only triggered when running Exiv2…
CVE-2026-28360
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored i
02:48 KSA
متوسط CVSS 5.3 CWE-256
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored in plaintext in the database and compared using direct string equality. This issue has been patched in version 0.301.3.
CVE-2026-28358
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint return
02:48 KSA
متوسط CVSS 5.3 CWE-204
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint returned different responses for registered and unregistered emails, allowing user enumeration. This issue has been patched in version 0.301.3.
CVE-2026-3404
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/
02:48 KSA
متوسط CVSS 5.0 CWE-610
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The attack may be performed from rem…
⚠️ استخبارات التهديدات
0 تهديد
⚠️ لا توجد تهديدات مسجّلة اليوم حتى الآن
📰 أخبار الأمن السيبراني
1 مقال
بدء تطبيق نظام PDPL: الالتزامات الرئيسية للمنظمات
21:49 KSA
تبدأ هيئة البيانات والذكاء الاصطناعي (سدايا) التطبيق الفعلي لنظام حماية البيانات الشخصية مع غرامات تصل إلى 5 ملايين ريال سعودي.

يتم تحديث هذه النشرة تلقائياً يومياً — آخر تحديث: 02 Mar 2026
أرشيف الثغرات · التهديدات · الأخبار

📣 وجدت هذا مفيداً؟
شاركه مع شبكة الأمن السيبراني الخاصة بك
in لينكدإن 𝕏 تويتر 💬 واتساب ✈ تليجرام
🍪 إعدادات الخصوصية
سيزو للاستشارات — متوافق مع نظام حماية البيانات الشخصية السعودي (PDPL)
نستخدم ملفات تعريف الارتباط والتقنيات المشابهة لتوفير أفضل تجربة على منصتنا. يمكنك اختيار الأنواع التي تقبلها.
🔒
ملفات ضرورية Always On
مطلوبة لعمل الموقع بشكل صحيح. لا يمكن تعطيلها.
📋 الجلسات، CSRF، المصادقة، تفضيلات اللغة
📊
ملفات التحليلات
تساعدنا في فهم كيفية استخدام الزوار للموقع وتحسين الأداء.
📋 إحصائيات الصفحات، مدة الجلسة، مصدر الزيارة
⚙️
ملفات وظيفية
تتيح ميزات محسنة مثل تخصيص المحتوى والتفضيلات.
📋 السمة المظلمة/الفاتحة، حجم الخط، لوحات التحكم المخصصة
📣
ملفات تسويقية
تُستخدم لتقديم محتوى وإعلانات ذات صلة باهتماماتك.
📋 تتبع الحملات، إعادة الاستهداف، تحليلات وسائل التواصل
سياسة الخصوصية →
مساعد CISO الذكي
اسألني أي شيء · وثائق · دعم
🔐

عرّفنا بنفسك

أدخل بياناتك للوصول إلى المساعد الكامل

معلوماتك آمنة ولن تُشارك
💬
المساعد السيبراني
متصل — يرد في ثوانٍ
5 / 5
🔐 تحقق من هويتك

أدخل بريدك الإلكتروني لإرسال رمز تحقق قبل إرسال طلب الدعم.

Enter للإرسال · / للأوامر 0 / 2000
CISO AI · مدعوم بالذكاء الاصطناعي
✦ استطلاع سريع ساعدنا في تحسين منصة سيزو للاستشارات ملاحظاتك تشكّل مستقبل منصتنا — لا تستغرق سوى دقيقتين.
⚠ يرجى الإجابة على هذا السؤال للمتابعة

كيف تقيّم تجربتك العامة مع منصتنا؟

قيّم من 1 (ضعيف) إلى 5 (ممتاز)

🎉
شكراً جزيلاً!
تم تسجيل إجابتك بنجاح.