智新資通管理系統

內部服務申請 ・ VPN 管理 ・ 憑證管理 ・ 資安通報

CVE 資安通報
每 4 小時更新 ・ 近 120 天
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2025-15560 8.8 MSSQL An authenticated attacker with minimal permissions can exploit a SQL inject... 具有最小權限的經過驗證的攻擊者可以利用 WorkTime 伺服器... 2026-02-19
CVE-2026-24734 7.5 Apache Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tom... Apache Tomcat Native、Apache Tomcat 中的不正確輸入驗證... 2026-02-17
CVE-2026-24733 3.7 Apache Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not... Apache Tomcat 中的不正確輸入驗證漏洞。 Tomcat 沒有將... 2026-02-17
CVE-2025-66614 嚴重 9.1 Apache Improper Input Validation vulnerability. This issue affects Apache Tomcat:... 不正確的輸入驗證漏洞。 此問題影響 Apache Tomcat:從 11... 2026-02-17
CVE-2026-26214 7.4 Apache Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and pr... Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android)... 2026-02-12
CVE-2026-23901 2.5 Apache Observable Timing Discrepancy vulnerability in Apache Shiro. This issue af... Apache Shiro 中可觀察到的時序差異漏洞。 此問題影響 Apa... 2026-02-10
CVE-2025-59095 N/A - MSSQL The program libraries (DLL) and binaries used by exos 9300 contain multiple... exos 9300 所使用的程式庫 (DLL) 和二進位檔案包含多個硬編... 2026-01-26
CVE-2025-59093 N/A - MSSQL Exos 9300 instances are using a randomly generated database password to con... Exos 9300 執行個體使用隨機產生的資料庫密碼連接到設定的... 2026-01-26
CVE-2026-22444 7.1 Apache The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient in... Apache Solr 8.6 到 9.10.0 的「建立核心」API 對某些 API... 2026-01-21
CVE-2026-22022 8.2 Apache Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule B... 由於這些元件中的輸入驗證不夠嚴格,依賴 Solr 的「基於規... 2026-01-21
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2025-40223 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: most:... 在Linux核心中,以下漏洞已解決: 大多數:usb:修正 hdm_... 2025-12-04
CVE-2025-40222 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: tty: s... 在Linux核心中,以下漏洞已解決: tty: 序列: sh-sci: 修... 2025-12-04
CVE-2025-40221 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: media:... 在Linux核心中,以下漏洞已解決: 媒體:pci:mg4b:修復... 2025-12-04
CVE-2025-40220 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: fuse:... 在Linux核心中,以下漏洞已解決: 熔斷器:修復從熔斷器工... 2025-12-04
CVE-2025-40219 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: PCI/IO... 在Linux核心中,以下漏洞已解決: PCI/IOV:啟用/停用 SR-... 2025-12-04
CVE-2025-40218 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: mm/dam... 在Linux核心中,以下漏洞已解決: mm/damon/vaddr: 不要重... 2025-12-04
CVE-2025-40217 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: pidfs:... 在Linux核心中,以下漏洞已解決: pidfs:驗證可擴充 ioct... 2025-12-04
CVE-2025-40216 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: io_uri... 在Linux核心中,以下漏洞已解決: io_uring/rsrc:不依賴... 2025-12-04
CVE-2025-40215 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: xfrm:... 在Linux核心中,以下漏洞已解決: xfrm:刪除 x->tunnel... 2025-12-04
CVE-2025-40214 N/A - Linux OS In the Linux kernel, the following vulnerability has been resolved: af_uni... 在Linux核心中,以下漏洞已解決: af_unix:在unix_add_ed... 2025-12-04
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-24734 7.5 Apache Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tom... Apache Tomcat Native、Apache Tomcat 中的不正確輸入驗證... 2026-02-17
CVE-2026-24733 3.7 Apache Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not... Apache Tomcat 中的不正確輸入驗證漏洞。 Tomcat 沒有將... 2026-02-17
CVE-2025-66614 嚴重 9.1 Apache Improper Input Validation vulnerability. This issue affects Apache Tomcat:... 不正確的輸入驗證漏洞。 此問題影響 Apache Tomcat:從 11... 2026-02-17
CVE-2026-26214 7.4 Apache Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android) version 3.0.8 and pr... Galaxy FDS Android SDK (XiaoMi/galaxy-fds-sdk-android)... 2026-02-12
CVE-2026-23901 2.5 Apache Observable Timing Discrepancy vulnerability in Apache Shiro. This issue af... Apache Shiro 中可觀察到的時序差異漏洞。 此問題影響 Apa... 2026-02-10
CVE-2026-22444 7.1 Apache The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient in... Apache Solr 8.6 到 9.10.0 的「建立核心」API 對某些 API... 2026-01-21
CVE-2026-22022 8.2 Apache Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule B... 由於這些元件中的輸入驗證不夠嚴格,依賴 Solr 的「基於規... 2026-01-21
CVE-2026-21962 嚴重 10 Apache Oracle Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-... Oracle HTTP Server、Oracle Fusion Middleware 的 Oracle... 2026-01-20
CVE-2025-29847 7.5 Apache A vulnerability in Apache Linkis. Problem Description When using the JDBC... Apache Linkis 中的漏洞。 問題描述 使用 JDBC 引擎和資料... 2026-01-19
CVE-2025-60021 嚴重 9.8 Apache Remote command injection vulnerability in heap profiler builtin service in... 所有平台上的 Apache bRPC((所有版本 < 1.15.0))中的堆... 2026-01-16
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-21941 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:最佳化... 2026-01-20
CVE-2026-21937 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:DDL)... 2026-01-20
CVE-2026-21936 4.9 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoD... Oracle MySQL(元件:InnoDB)的 MySQL Server 產品中存在... 2026-01-20
CVE-2026-21929 5.3 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:解析器... 2026-01-20
CVE-2021-47761 7.8 MySQL MilleGPG5 5.7.2 contains a local privilege escalation vulnerability that al... MilleGPG5 5.7.2 包含本地權限提升漏洞,允許經過驗證的使... 2026-01-15
CVE-2026-21856 7.2 MySQL The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to... 塔科夫資料管理器是管理塔科夫物品資料的工具。在提交 9bdb... 2026-01-07
CVE-2025-67745 7.1 MySQL MyHoard is a daemon for creating, managing and restoring MySQL backups. Sta... MyHoard 是一個用於建立、管理和還原 MySQL 備份的守護程式... 2025-12-18
CVE-2025-58173 8.8 MySQL PHP MSSQL FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1... FreshRSS 是一個自架的 RSS 提要聚合器。在版本 1.23.0 到... 2025-12-16
CVE-2025-10289 5.9 MySQL The Filter & Grids plugin for WordPress is vulnerable to SQL Injection via... WordPress 的 Filter & Grids 外掛程式在 3.2.0 及之前的所... 2025-12-13
CVE-2025-67510 嚴重 9.4 MySQL PHP Neuron is a PHP framework for creating and orchestrating AI Agents. In vers... Neuron 是一個用於創建和編排 AI 代理的 PHP 框架。在2.8.1... 2025-12-10
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2024-44662 6.5 PHP PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via th... PHPGurukul Online Shopping Portal 2.0 容易透過管理頁面... 2025-11-17
CVE-2024-44660 6.5 PHP PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via th... PHPGurukul Online Shopping Portal 2.0 容易透過 login.ph... 2025-11-17
CVE-2024-44658 6.5 PHP PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection v... PHPGurukul 投訴管理系統 2.0 容易透過 subcategory.php 中... 2025-11-17
CVE-2024-44655 6.1 PHP PHPGurukul Complaint Management System 2.0 is vulnerable to Cross Site Scri... PHPGurukul 投訴管理系統 2.0 容易透過 user-search.php 中... 2025-11-17
CVE-2024-44654 6.5 PHP PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection v... PHPGurukul 投訴管理系統 2.0 容易透過 reset-password.php... 2025-11-17
CVE-2024-44657 6.5 PHP PHPGurukul Complaint Management System 2.0 is vulnerable to SQL Injection v... PHPGurukul 投訴管理系統 2.0 容易透過 Between-date-userr... 2025-11-17
CVE-2025-62519 7.2 PHP phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an... phpMyFAQ 是一個開源常見問題解答 Web 應用程式。在版本 4.... 2025-11-17
CVE-2024-44648 6.5 PHP PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminrem... PHPGurukul Small CRM 3.0 容易受到透過 quote-details.php... 2025-11-17
CVE-2024-44647 6.1 PHP PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via th... PHPGurukul Small CRM 3.0 容易透過manage-tickets.php 中... 2025-11-17
CVE-2024-44644 6.5 PHP PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and... PHPGurukul Small CRM 3.0 很容易透過manage-tickets.php... 2025-11-17
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2025-15560 8.8 MSSQL An authenticated attacker with minimal permissions can exploit a SQL inject... 具有最小權限的經過驗證的攻擊者可以利用 WorkTime 伺服器... 2026-02-19
CVE-2025-59095 N/A - MSSQL The program libraries (DLL) and binaries used by exos 9300 contain multiple... exos 9300 所使用的程式庫 (DLL) 和二進位檔案包含多個硬編... 2026-01-26
CVE-2025-59093 N/A - MSSQL Exos 9300 instances are using a randomly generated database password to con... Exos 9300 執行個體使用隨機產生的資料庫密碼連接到設定的... 2026-01-26
CVE-2025-64298 8.4 MSSQL NMIS/BioDose V22.02 and previous version installations where the embedded M... 使用嵌入式 Microsoft SQLServer Express 的 NMIS/BioDose... 2025-12-02
CVE-2025-62575 8.3 MSSQL NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server da... NMIS/BioDose V22.02 及之前的版本依賴 Microsoft SQL Serv... 2025-12-02
CVE-2025-10703 N/A - Apache MySQL Oracle Improper Control of Generation of Code ('Code Injection') vulnerability in... Progress DataDirect Connect for JDBC 驅動程式、Progress... 2025-11-19
CVE-2025-10702 N/A - Apache MySQL Oracle Improper Control of Generation of Code ('Code Injection') vulnerability in... Progress DataDirect Connect for JDBC 驅動程式、Progress... 2025-11-19
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2026-21975 4.5 Oracle Vulnerability in the Java VM component of Oracle Database Server. Supporte... Oracle 資料庫伺服器的 Java VM 元件中的漏洞。 受影響的... 2026-01-20
CVE-2026-21939 7 Oracle Vulnerability in the SQLcl component of Oracle Database Server. Supported... Oracle 資料庫伺服器的 SQLcl 元件中的漏洞。 受影響的受... 2026-01-20
CVE-2026-21931 5.4 Oracle Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX... Oracle APEX 的 Oracle APEX 範例應用程式產品(元件:Broo... 2026-01-20
CVE-2026-21930 2.3 Oracle Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Sys... Oracle Systems 的 Oracle ZFS 儲存設備套件產品(元件:檔... 2026-01-20
CVE-2026-21929 5.3 MySQL MSSQL Oracle Vulnerability in the MySQL Server product of Oracle MySQL (component: Serve... Oracle MySQL 的 MySQL Server 產品(元件:伺服器:解析器... 2026-01-20
CVE-2026-21928 5.3 Linux OS Oracle Vulnerability in the Oracle Solaris product of Oracle Systems (component: K... Oracle Systems 的 Oracle Solaris 產品(元件:核心)存在... 2026-01-20
CVE-2026-21927 5.8 Oracle Vulnerability in the Oracle Solaris product of Oracle Systems (component: D... Oracle Systems 的 Oracle Solaris 產品中存在漏洞(元件:... 2026-01-20
CVE-2026-21926 7.5 Oracle Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (co... Oracle Siebel CRM 的 Siebel CRM 部署產品(元件:伺服器... 2026-01-20
CVE-2026-21925 4.8 Oracle Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM... Oracle Java SE、Oracle GraalVM for JDK、Oracle Java SE... 2026-01-20
CVE-2026-21924 5.4 Oracle Vulnerability in the Oracle Utilities Application Framework product of Orac... Oracle Utilities Applications 的 Oracle Utilities Appli... 2026-01-20
CVE 編號 嚴重性 分數 產品 描述 發布日期
CVE-2025-13637 4.3 Chrome Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7... 143.0.7499.41 之前的 Google Chrome 中的「下載」實施不當... 2025-12-02
CVE-2025-13636 4.3 Chrome Inappropriate implementation in Split View in Google Chrome prior to 143.0.... 143.0.7499.41 之前的 Google Chrome 中的分割畫面視圖實施... 2025-12-02
CVE-2025-13635 4.4 Chrome Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7... 143.0.7499.41 之前的 Google Chrome 中的下載中的不當實施... 2025-12-02
CVE-2025-13634 4.4 Chrome Inappropriate implementation in Downloads in Google Chrome on Windows prior... 143.0.7499.41 之前的 Windows 上的 Google Chrome 下載中... 2025-12-02
CVE-2025-13633 8.8 Chrome Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.... 143.0.7499.41 之前的 Google Chrome 中的數位憑證中的釋放... 2025-12-02
CVE-2025-13632 5.4 Chrome Inappropriate implementation in DevTools in Google Chrome prior to 143.0.74... 143.0.7499.41 之前的 Google Chrome 中的 DevTools 中的不... 2025-12-02
CVE-2025-13631 8.8 Chrome Inappropriate implementation in Google Updater in Google Chrome on Mac prio... 143.0.7499.41 之前的 Mac 版 Google Chrome 中的 Google... 2025-12-02
CVE-2025-13630 8.8 Chrome Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remo... 143.0.7499.41 之前的 Google Chrome V8 中的類型混淆允許... 2025-12-02
CVE-2025-13230 8.8 Chrome Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remo... 142.0.7444.59 之前的 Google Chrome V8 中的類型混淆允許... 2025-11-18
CVE-2025-13229 8.8 Chrome Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remo... 142.0.7444.59 之前的 Google Chrome V8 中的類型混淆允許... 2025-11-18