智新資通管理系統

內部服務申請 ・ VPN 管理 ・ 憑證管理 ・ 資安通報

CVE 資安通報
每 4 小時更新 ・ 近 120 天
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2019-25598 6.2 MSSQL HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability th... HeidiSQL Portable 10.1.0.5464 包含拒絕服務漏洞,允許本... 2026-03-22
CVE-2026-32710 8.5 MySQL MSSQL MariaDB server is a community developed fork of MySQL server. An authentica... MariaDB 伺服器是社群開發的 MySQL 伺服器分支。經過驗證的... 2026-03-20
CVE-2025-58112 8.8 MSSQL Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034)... Microsoft Dynamics 365 Customer Engagement (on-premises... 2026-03-18
CVE-2026-22730 8.8 MySQL A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressi... Spring AI 的 MariaDBFilterExpressionConverter 中存在一... 2026-03-18
CVE-2026-32628 8.8 MySQL MSSQL AnythingLLM is an application that turns pieces of content into context tha... AnythingLLM 是一個將內容片段轉換為上下文的應用程序,任... 2026-03-16
CVE-2016-20026 嚴重 9.8 Apache ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apac... ZKTeco ZKBioSecurity 3.0 在捆綁的 Apache Tomcat 伺服器... 2026-03-16
CVE-2026-4105 6.7 Linux OS A flaw was found in systemd. The systemd-machined service contains an Impro... systemd 中發現一個缺陷。由於 RegisterMachine D-Bus(桌... 2026-03-13
CVE-2026-3497 N/A - Linux OS Vulnerability in the OpenSSH GSSAPI delta included in various Linux distrib... 各種 Linux 發行版中所包含的 OpenSSH GSSAPI 增量中的漏洞... 2026-03-12
CVE-2026-31979 8.8 Linux OS Himmelblau is an interoperability suite for Microsoft Azure Entra ID and In... Himmelblau 是 Microsoft Azure Entra ID 和 Intune 的互通... 2026-03-11
CVE-2026-32063 7.1 Linux OS OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injectio... 2026.2.21 之前的 OpenClaw 版本 2026.2.19-2 在 systemd... 2026-03-11
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-4105 6.7 Linux OS A flaw was found in systemd. The systemd-machined service contains an Impro... systemd 中發現一個缺陷。由於 RegisterMachine D-Bus(桌... 2026-03-13
CVE-2026-3497 N/A - Linux OS Vulnerability in the OpenSSH GSSAPI delta included in various Linux distrib... 各種 Linux 發行版中所包含的 OpenSSH GSSAPI 增量中的漏洞... 2026-03-12
CVE-2026-31979 8.8 Linux OS Himmelblau is an interoperability suite for Microsoft Azure Entra ID and In... Himmelblau 是 Microsoft Azure Entra ID 和 Intune 的互通... 2026-03-11
CVE-2026-32063 7.1 Linux OS OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injectio... 2026.2.21 之前的 OpenClaw 版本 2026.2.19-2 在 systemd... 2026-03-11
CVE-2025-69651 5.5 Linux OS GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an in... GNU Binutils 至 2.46 readelf 包含一個漏洞,在處理具有格... 2026-03-06
CVE-2026-28372 7.4 Linux OS telnetd in GNU inetutils through 2.7 allows privilege escalation that can b... GNU inetutils 到 2.7 中的 telnetd 允許權限升級,可以透... 2026-02-27
CVE-2025-0577 4.8 Linux OS An insufficient entropy vulnerability was found in glibc. The getrandom and... glibc 中發現熵不足漏洞。如果在 fork 之後再次呼叫 getran... 2026-02-18
CVE-2025-32063 6.8 Linux OS There is a misconfiguration vulnerability inside the Infotainment ECU manuf... BOSCH 製造的資訊娛樂 ECU 內部存在配置錯誤漏洞。此漏洞發... 2026-02-15
CVE-2026-23162 7.8 Linux OS In the Linux kernel, the following vulnerability has been resolved: drm/xe... 在Linux核心中,以下漏洞已解決: drm/xe/nvm:修復輔助添... 2026-02-14
CVE-2026-23115 4.7 Linux OS In the Linux kernel, the following vulnerability has been resolved: serial... 在Linux核心中,以下漏洞已解決: 序列:修復未設定 tty->... 2026-02-14
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2016-20026 嚴重 9.8 Apache ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apac... ZKTeco ZKBioSecurity 3.0 在捆綁的 Apache Tomcat 伺服器... 2026-03-16
CVE-2026-24734 7.5 Apache Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tom... Apache Tomcat Native、Apache Tomcat 中的不正確輸入驗證... 2026-02-17
CVE-2026-24733 3.7 Apache Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not... Apache Tomcat 中的不正確輸入驗證漏洞。 Tomcat 沒有將... 2026-02-17
CVE-2025-66614 嚴重 9.1 Apache Improper Input Validation vulnerability. This issue affects Apache Tomcat:... 不正確的輸入驗證漏洞。 此問題影響 Apache Tomcat:從 11... 2026-02-17
CVE-2026-26214 7.4 Apache Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and pr... Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android)... 2026-02-12
CVE-2026-23901 2.5 Apache Observable Timing Discrepancy vulnerability in Apache Shiro. This issue af... Apache Shiro 中可觀察到的時序差異漏洞。 此問題影響 Apa... 2026-02-10
CVE-2026-22444 7.1 Apache The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient in... Apache Solr 8.6 到 9.10.0 的「建立核心」API 對某些 API... 2026-01-21
CVE-2026-22022 8.2 Apache Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule B... 由於這些元件中的輸入驗證不夠嚴格,依賴 Solr 的「基於規... 2026-01-21
CVE-2026-21962 嚴重 10 Apache Oracle Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-... Oracle HTTP Server、Oracle Fusion Middleware 的 Oracle... 2026-01-20
CVE-2025-29847 7.5 Apache A vulnerability in Apache Linkis. Problem Description When using the JDBC... Apache Linkis 中的漏洞。 問題描述 使用 JDBC 引擎和資料... 2026-01-19
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-32710 8.5 MySQL MSSQL MariaDB server is a community developed fork of MySQL server. An authentica... MariaDB 伺服器是社群開發的 MySQL 伺服器分支。經過驗證的... 2026-03-20
CVE-2026-22730 8.8 MySQL A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressi... Spring AI 的 MariaDBFilterExpressionConverter 中存在一... 2026-03-18
CVE-2026-3494 4.3 MySQL In MariaDB server version through 11.8.5, when server audit plugin is enabl... 在 MariaDB 伺服器版本至 11.8.5 中,當使用配置有 QUERY_D... 2026-03-03
CVE-2026-21952 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:解析器... 2026-01-20
CVE-2026-21950 6.5 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21949 6.5 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21948 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21941 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21937 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:DDL)... 2026-01-20
CVE-2026-21936 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoD... Oracle MySQL(元件:InnoDB)的 MySQL Server 產品中存在... 2026-01-20
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2025-13494 5.3 PHP The SSP Debug plugin for WordPress is vulnerable to Sensitive Information E... WordPress 的 SSP 偵錯外掛程式在 1.0.0 及之前的所有版本... 2025-12-05
CVE-2025-66509 嚴重 9.8 PHP LaraDashboard is an all-In-one solution to start a Laravel Application. In... LaraDashboard 是啟動 Laravel 應用程式的一體化解決方案。... 2025-12-04
CVE-2025-66571 N/A - PHP UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vuln... UNA CMS 版本 9.0.0-RC1 - 14.0.0-RC4 在 BxBaseMenuSetAcl... 2025-12-04
CVE-2025-65657 6.5 PHP FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Up... FeehiCMS 2.1.1 版透過廣告管理中的無限檔上傳實現遠端程式... 2025-12-02
CVE-2025-65380 6.5 PHP PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/i... PHPGurukul 計費系統 1.0 在 admin/index.php 端點容易受到... 2025-12-02
CVE-2025-65379 6.5 PHP PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/... PHPGurukul Billing System 1.0 在 /admin/password-recove... 2025-12-02
CVE-2025-13516 8.1 Linux OS Apache PHP The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Un... SureMail – WordPress 的 SMTP 和電子郵件日誌外掛程式在 1... 2025-12-02
CVE-2025-9191 6.3 PHP The Houzez theme for WordPress is vulnerable to PHP Object Injection in all... WordPress 的 Houzez 主題在 4.1.6 及之前的所有版本中都容... 2025-11-26
CVE-2025-66026 6.1 PHP REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site... REDAXO 是一個以 PHP 為基礎的 CMS。在版本 5.20.1 之前,M... 2025-11-26
CVE-2025-66263 7.5 PHP Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electroni... 透過 DB Electronica Telecomunicazioni S.p.A. Mozart FM... 2025-11-26
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2019-25598 6.2 MSSQL HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability th... HeidiSQL Portable 10.1.0.5464 包含拒絕服務漏洞,允許本... 2026-03-22
CVE-2025-58112 8.8 MSSQL Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034)... Microsoft Dynamics 365 Customer Engagement (on-premises... 2026-03-18
CVE-2026-32628 8.8 MySQL MSSQL AnythingLLM is an application that turns pieces of content into context tha... AnythingLLM 是一個將內容片段轉換為上下文的應用程序,任... 2026-03-16
CVE-2025-15560 8.8 MSSQL An authenticated attacker with minimal permissions can exploit a SQL inject... 具有最小權限的經過驗證的攻擊者可以利用 WorkTime 伺服器... 2026-02-19
CVE-2025-59095 N/A - MSSQL The program libraries (DLL) and binaries used by exos 9300 contain multiple... exos 9300 所使用的程式庫 (DLL) 和二進位檔案包含多個硬編... 2026-01-26
CVE-2025-59093 N/A - MSSQL Exos 9300 instances are using a randomly generated database password to con... Exos 9300 執行個體使用隨機產生的資料庫密碼連接到設定的... 2026-01-26
CVE-2025-64298 8.4 MSSQL NMIS/BioDose V22.02 and previous version installations where the embedded M... 使用嵌入式 Microsoft SQLServer Express 的 NMIS/BioDose... 2025-12-02
CVE-2025-62575 8.3 MSSQL NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server da... NMIS/BioDose V22.02 及之前的版本依賴 Microsoft SQL Serv... 2025-12-02
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-21975 4.5 Oracle Vulnerability in the Java VM component of Oracle Database Server. Supporte... Oracle 資料庫伺服器的 Java VM 元件中的漏洞。 受影響的... 2026-01-20
CVE-2026-21939 7 Oracle Vulnerability in the SQLcl component of Oracle Database Server. Supported... Oracle 資料庫伺服器的 SQLcl 元件中的漏洞。 受影響的受... 2026-01-20