智新資通管理系統

內部服務申請 ・ VPN 管理 ・ 憑證管理 ・ 資安通報

CVE 資安通報
每 4 小時更新 ・ 近 120 天
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2019-25598 6.2 MSSQL HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability th... HeidiSQL Portable 10.1.0.5464 包含拒絕服務漏洞,允許本... 2026-03-22
CVE-2026-32710 8.5 MySQL MSSQL MariaDB server is a community developed fork of MySQL server. An authentica... MariaDB 伺服器是社群開發的 MySQL 伺服器分支。經過驗證的... 2026-03-20
CVE-2025-58112 8.8 MSSQL Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034)... Microsoft Dynamics 365 Customer Engagement (on-premises... 2026-03-18
CVE-2026-22730 8.8 MySQL A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressi... Spring AI 的 MariaDBFilterExpressionConverter 中存在一... 2026-03-18
CVE-2026-32628 8.8 MySQL MSSQL AnythingLLM is an application that turns pieces of content into context tha... AnythingLLM 是一個將內容片段轉換為上下文的應用程序,任... 2026-03-16
CVE-2016-20026 嚴重 9.8 Apache ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apac... ZKTeco ZKBioSecurity 3.0 在捆綁的 Apache Tomcat 伺服器... 2026-03-16
CVE-2026-4105 6.7 Linux OS A flaw was found in systemd. The systemd-machined service contains an Impro... systemd 中發現一個缺陷。由於 RegisterMachine D-Bus(桌... 2026-03-13
CVE-2026-3497 N/A - Linux OS Vulnerability in the OpenSSH GSSAPI delta included in various Linux distrib... 各種 Linux 發行版中所包含的 OpenSSH GSSAPI 增量中的漏洞... 2026-03-12
CVE-2026-3968 6.3 Oracle A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This... AutohomeCorp 霜之哀傷中已發現高達 1.0 的漏洞。這會影響... 2026-03-12
CVE-2026-31979 8.8 Linux OS Himmelblau is an interoperability suite for Microsoft Azure Entra ID and In... Himmelblau 是 Microsoft Azure Entra ID 和 Intune 的互通... 2026-03-11
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-4105 6.7 Linux OS A flaw was found in systemd. The systemd-machined service contains an Impro... systemd 中發現一個缺陷。由於 RegisterMachine D-Bus(桌... 2026-03-13
CVE-2026-3497 N/A - Linux OS Vulnerability in the OpenSSH GSSAPI delta included in various Linux distrib... 各種 Linux 發行版中所包含的 OpenSSH GSSAPI 增量中的漏洞... 2026-03-12
CVE-2026-31979 8.8 Linux OS Himmelblau is an interoperability suite for Microsoft Azure Entra ID and In... Himmelblau 是 Microsoft Azure Entra ID 和 Intune 的互通... 2026-03-11
CVE-2026-32063 7.1 Linux OS OpenClaw version 2026.2.19-2 prior to 2026.2.21 contains a command injectio... 2026.2.21 之前的 OpenClaw 版本 2026.2.19-2 在 systemd... 2026-03-11
CVE-2025-69651 5.5 Linux OS GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an in... GNU Binutils 至 2.46 readelf 包含一個漏洞,在處理具有格... 2026-03-06
CVE-2026-28372 7.4 Linux OS telnetd in GNU inetutils through 2.7 allows privilege escalation that can b... GNU inetutils 到 2.7 中的 telnetd 允許權限升級,可以透... 2026-02-27
CVE-2025-0577 4.8 Linux OS An insufficient entropy vulnerability was found in glibc. The getrandom and... glibc 中發現熵不足漏洞。如果在 fork 之後再次呼叫 getran... 2026-02-18
CVE-2025-32063 6.8 Linux OS There is a misconfiguration vulnerability inside the Infotainment ECU manuf... BOSCH 製造的資訊娛樂 ECU 內部存在配置錯誤漏洞。此漏洞發... 2026-02-15
CVE-2026-23162 7.8 Linux OS In the Linux kernel, the following vulnerability has been resolved: drm/xe... 在Linux核心中,以下漏洞已解決: drm/xe/nvm:修復輔助添... 2026-02-14
CVE-2026-23115 4.7 Linux OS In the Linux kernel, the following vulnerability has been resolved: serial... 在Linux核心中,以下漏洞已解決: 序列:修復未設定 tty->... 2026-02-14
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2016-20026 嚴重 9.8 Apache ZKTeco ZKBioSecurity 3.0 contains hardcoded credentials in the bundled Apac... ZKTeco ZKBioSecurity 3.0 在捆綁的 Apache Tomcat 伺服器... 2026-03-16
CVE-2026-24734 7.5 Apache Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tom... Apache Tomcat Native、Apache Tomcat 中的不正確輸入驗證... 2026-02-17
CVE-2026-24733 3.7 Apache Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not... Apache Tomcat 中的不正確輸入驗證漏洞。 Tomcat 沒有將... 2026-02-17
CVE-2025-66614 嚴重 9.1 Apache Improper Input Validation vulnerability. This issue affects Apache Tomcat:... 不正確的輸入驗證漏洞。 此問題影響 Apache Tomcat:從 11... 2026-02-17
CVE-2026-26214 7.4 Apache Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and pr... Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android)... 2026-02-12
CVE-2026-23901 2.5 Apache Observable Timing Discrepancy vulnerability in Apache Shiro. This issue af... Apache Shiro 中可觀察到的時序差異漏洞。 此問題影響 Apa... 2026-02-10
CVE-2026-22444 7.1 Apache The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient in... Apache Solr 8.6 到 9.10.0 的「建立核心」API 對某些 API... 2026-01-21
CVE-2026-22022 8.2 Apache Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule B... 由於這些元件中的輸入驗證不夠嚴格,依賴 Solr 的「基於規... 2026-01-21
CVE-2026-21962 嚴重 10 Apache Oracle Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-... Oracle HTTP Server、Oracle Fusion Middleware 的 Oracle... 2026-01-20
CVE-2025-29847 7.5 Apache A vulnerability in Apache Linkis. Problem Description When using the JDBC... Apache Linkis 中的漏洞。 問題描述 使用 JDBC 引擎和資料... 2026-01-19
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-32710 8.5 MySQL MSSQL MariaDB server is a community developed fork of MySQL server. An authentica... MariaDB 伺服器是社群開發的 MySQL 伺服器分支。經過驗證的... 2026-03-20
CVE-2026-22730 8.8 MySQL A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressi... Spring AI 的 MariaDBFilterExpressionConverter 中存在一... 2026-03-18
CVE-2026-3494 4.3 MySQL In MariaDB server version through 11.8.5, when server audit plugin is enabl... 在 MariaDB 伺服器版本至 11.8.5 中,當使用配置有 QUERY_D... 2026-03-03
CVE-2026-21952 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:解析器... 2026-01-20
CVE-2026-21950 6.5 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21949 6.5 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21948 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21941 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21937 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:DDL)... 2026-01-20
CVE-2026-21936 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoD... Oracle MySQL(元件:InnoDB)的 MySQL Server 產品中存在... 2026-01-20
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2025-63062 7.6 PHP Improper Control of Filename for Include/Require Statement in PHP Program (... AndonDesign UDesign Core u-design-core 中對 PHP 程式中... 2025-12-09
CVE-2025-63036 7.5 PHP Improper Control of Filename for Include/Require Statement in PHP Program (... DFDevelopment Ronneby 主題核心 ronneby-core 中對 PHP 程... 2025-12-09
CVE-2025-63003 7.5 PHP Improper Control of Filename for Include/Require Statement in PHP Program (... Fuelthemes 中的 PHP 程式中包含/要求語句的檔案名稱控制不... 2025-12-09
CVE-2025-60912 3.3 MySQL PHP phpIPAM v1.7.3 contains a Cross-Site Request Forgery (CSRF) vulnerability i... phpIPAM v1.7.3 在資料庫匯出功能中包含跨站請求偽造 (CSRF... 2025-12-08
CVE-2020-36877 N/A - PHP ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remo... ReQuest Serious Play F3 Media Server 7.0.3 包含未經驗證... 2025-12-05
CVE-2025-14091 7.3 PHP A weakness has been identified in TrippWasTaken PHP-Guitar-Shop up to 6ce08... TrippWasTaken PHP-Guitar-Shop 中已發現一個漏洞,版本號... 2025-12-05
CVE-2025-12851 8.1 PHP The My auctions allegro plugin for WordPress is vulnerable to Local File In... WordPress 的「我的拍賣 allegro」外掛程式在 3.6.32 及之... 2025-12-05
CVE-2025-13494 5.3 PHP The SSP Debug plugin for WordPress is vulnerable to Sensitive Information E... WordPress 的 SSP 偵錯外掛程式在 1.0.0 及之前的所有版本... 2025-12-05
CVE-2025-66509 嚴重 9.8 PHP LaraDashboard is an all-In-one solution to start a Laravel Application. In... LaraDashboard 是啟動 Laravel 應用程式的一體化解決方案。... 2025-12-04
CVE-2025-66571 N/A - PHP UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vuln... UNA CMS 版本 9.0.0-RC1 - 14.0.0-RC4 在 BxBaseMenuSetAcl... 2025-12-04
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2019-25598 6.2 MSSQL HeidiSQL Portable 10.1.0.5464 contains a denial of service vulnerability th... HeidiSQL Portable 10.1.0.5464 包含拒絕服務漏洞,允許本... 2026-03-22
CVE-2025-58112 8.8 MSSQL Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034)... Microsoft Dynamics 365 Customer Engagement (on-premises... 2026-03-18
CVE-2026-32628 8.8 MySQL MSSQL AnythingLLM is an application that turns pieces of content into context tha... AnythingLLM 是一個將內容片段轉換為上下文的應用程序,任... 2026-03-16
CVE-2025-15560 8.8 MSSQL An authenticated attacker with minimal permissions can exploit a SQL inject... 具有最小權限的經過驗證的攻擊者可以利用 WorkTime 伺服器... 2026-02-19
CVE-2025-59095 N/A - MSSQL The program libraries (DLL) and binaries used by exos 9300 contain multiple... exos 9300 所使用的程式庫 (DLL) 和二進位檔案包含多個硬編... 2026-01-26
CVE-2025-59093 N/A - MSSQL Exos 9300 instances are using a randomly generated database password to con... Exos 9300 執行個體使用隨機產生的資料庫密碼連接到設定的... 2026-01-26
CVE-2025-64298 8.4 MSSQL NMIS/BioDose V22.02 and previous version installations where the embedded M... 使用嵌入式 Microsoft SQLServer Express 的 NMIS/BioDose... 2025-12-02
CVE-2025-62575 8.3 MSSQL NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server da... NMIS/BioDose V22.02 及之前的版本依賴 Microsoft SQL Serv... 2025-12-02
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-3968 6.3 Oracle A vulnerability has been found in AutohomeCorp frostmourne up to 1.0. This... AutohomeCorp 霜之哀傷中已發現高達 1.0 的漏洞。這會影響... 2026-03-12
CVE-2026-21975 4.5 Oracle Vulnerability in the Java VM component of Oracle Database Server. Supporte... Oracle 資料庫伺服器的 Java VM 元件中的漏洞。 受影響的... 2026-01-20
CVE-2026-21962 嚴重 10 Apache Oracle Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-... Oracle HTTP Server、Oracle Fusion Middleware 的 Oracle... 2026-01-20
CVE-2026-21960 6.5 Oracle Vulnerability in the Oracle Applications DBA product of Oracle E-Business S... Oracle E-Business Suite(元件:Java utils)的 Oracle 應... 2026-01-20
CVE-2026-21947 3.1 Oracle Vulnerability in Oracle Java SE (component: JavaFX). Supported versions th... Oracle Java SE(元件:JavaFX)中的漏洞。 受影響的支援... 2026-01-20
CVE-2026-21945 7.5 Oracle Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM... Oracle Java SE、Oracle GraalVM for JDK、Oracle Java SE... 2026-01-20
CVE-2026-21939 7 Oracle Vulnerability in the SQLcl component of Oracle Database Server. Supported... Oracle 資料庫伺服器的 SQLcl 元件中的漏洞。 受影響的受... 2026-01-20
CVE-2026-21933 6.1 Oracle Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM... Oracle Java SE、Oracle GraalVM for JDK、Oracle Java SE... 2026-01-20
CVE-2026-21932 7.4 Oracle Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM... Oracle Java SE、Oracle GraalVM for JDK、Oracle Java SE... 2026-01-20
CVE-2026-21925 4.8 Oracle Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM... Oracle Java SE、Oracle GraalVM for JDK、Oracle Java SE... 2026-01-20