🛡️ قاعدة بيانات الثغرات الأمنية
ثغرات CVE مع تحليل AI ثنائي اللغة خاص بالمملكة العربية السعودية
| المعرّف | العنوان / الوصف | الخطورة | CVSS | الحالة | النشر |
|---|---|---|---|---|---|
| CVE-2026-3880 |
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802…
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Pu…
|
HIGH |
7.3
|
— | أبريل 3, 2026 |
| CVE-2026-4107 |
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802…
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Fo…
|
HIGH |
7.3
|
— | أبريل 3, 2026 |
| CVE-2026-4108 |
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802…
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in No…
|
HIGH |
7.3
|
— | أبريل 3, 2026 |
| CVE-2026-4350 |
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in …
|
HIGH |
8.1
|
— | أبريل 3, 2026 |
| CVE-2026-22661 |
prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling …
|
HIGH |
8.1
|
— | أبريل 3, 2026 |
| CVE-2026-22663 |
prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to m…
|
HIGH |
7.5
|
— | أبريل 3, 2026 |
| CVE-2026-22664 |
prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai …
|
HIGH |
7.7
|
— | أبريل 3, 2026 |
| CVE-2026-22665 |
prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to inconsisten…
|
HIGH |
8.1
|
— | أبريل 3, 2026 |
| CVE-2026-25044 |
Budibase is an open-source low-code platform. Prior to version 3.33.4, the bash automation step exec…
|
HIGH |
8.8
|
— | أبريل 3, 2026 |
| CVE-2026-27655 |
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802…
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Pe…
|
HIGH |
7.3
|
— | أبريل 3, 2026 |
| CVE-2026-28703 |
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802…
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Ma…
|
HIGH |
7.3
|
— | أبريل 3, 2026 |
| CVE-2026-28754 |
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802…
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Di…
|
HIGH |
7.3
|
— | أبريل 3, 2026 |
| CVE-2026-28756 |
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802…
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Pe…
|
HIGH |
7.3
|
— | أبريل 3, 2026 |
| CVE-2026-32173 |
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information o…
|
HIGH |
8.6
|
— | أبريل 3, 2026 |
| CVE-2026-29782 |
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior t…
|
HIGH |
7.2
|
⚡ ✅ | أبريل 2, 2026 |
| CVE-2026-33613 |
Due to the improper neutralisation of special elements used in an…
Due to the improper neutralisation of special elements used in an OS command, a remote attacker can …
|
HIGH |
7.2
|
— | أبريل 2, 2026 |
| CVE-2026-33614 |
An unauthenticated remote attacker can exploit an unauthenticated…
An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the…
|
HIGH |
7.5
|
— | أبريل 2, 2026 |
| CVE-2026-33616 |
An unauthenticated remote attacker can exploit an unauthenticated…
An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability …
|
HIGH |
7.5
|
— | أبريل 2, 2026 |
| CVE-2026-33951 |
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.…
|
HIGH |
7.5
|
— | أبريل 2, 2026 |
| CVE-2026-34121 |
An authentication bypass vulnerability within the HTTP handling of the DS configuration service in T…
|
HIGH |
8.8
|
— | أبريل 2, 2026 |
| CVE-2026-34426 |
OpenClaw versions prior to commit b57b680 contain an approval bypass vulnerability due to inconsiste…
|
HIGH |
7.6
|
✅ | أبريل 2, 2026 |
| CVE-2026-34576 |
Postiz is an AI social media scheduling tool. Prior to version 2.21.3, the POST /public/v1/upload-fr…
|
HIGH |
7.7
|
⚡ | أبريل 2, 2026 |
| CVE-2026-34728 |
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::…
|
HIGH |
8.7
|
⚡ | أبريل 2, 2026 |
| CVE-2026-34742 |
The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol …
|
HIGH |
8.1
|
✅ | أبريل 2, 2026 |
| CVE-2026-34752 |
Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a heade…
|
HIGH |
7.5
|
⚡ | أبريل 2, 2026 |
🤖 تحليل AI متاح
يتضمن تحليل الذكاء الاصطناعي: الوصف العربي، التأثير السعودي، خطوات المعالجة، خريطة الامتثال (NCA، SAMA، ISO 27001) وتقنيات MITRE ATT&CK.
🔴 الثغرات الحرجة الأخيرة
CVE-2026-20133
أبريل 20, 2026
CVE-2026-20128
أبريل 20, 2026
CVE-2026-20122
أبريل 20, 2026
CVE-2025-48700
أبريل 20, 2026
CVE-2025-32975
أبريل 20, 2026
💡 نصائح البحث
CVE-2024-12345
بحث بمعرّف محدد
apache
بحث بالمنتج
remote code execution
بحث بنوع الثغرة
log4j
بحث بالاسم المشهور
📡 مصادر البيانات
NVD (NIST) · CIRCL
CISA KEV · ThreatFox
Feodo Tracker · AlienVault OTX
يتم التحديث تلقائياً يومياً