漏洞列表 352547
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-14399
Download Plugins and Themes from Dashboard <= 1.9.6 - Cross-Site Request Forgery to Bulk Plugin/Theme Archival
MEDIUM 4.3 2025-12-17
wpcodefactory Download Plugins and Themes in ZIP from Dashboard
CVE NVD
CVE-2025-12496
Zephyr Project Manager <= 3.3.203 - Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery
MEDIUM 4.9 2025-12-17
dylanjkotze Zephyr Project Manager
CVE NVD
CVE-2025-11924
Ninja Forms – The Contact Form Builder That Grows With You <= 3.13.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure via Unscoped Bearer Token
HIGH 7.5 2025-12-17
kstover Ninja Forms – The Contact Form Builder That Grows With You ninjaforms ninja_forms
CVE NVD
CVE-2025-13750
Converter for Media <= 6.3.2 - Missing Authorization to Authenticated (Subscriber+) Optimized Image Deletion via regenerate-attachment REST Endpoint
MEDIUM 4.3 2025-12-17
mateuszgbiorczyk Converter for Media – Optimize images | Convert WebP & AVIF
CVE NVD
CVE-2025-14061
Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Post Deletion
MEDIUM 5.3 2025-12-17
wplegalpages Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent
CVE NVD
CVE-2025-14817
TECNO Pova6 Pro 5G 安全漏洞
MEDIUM 6.5 2025-12-17
TECNO Tecno Pova6 Pro 5G transsion hios
CVE NVD +1
CVE-2025-14154
Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting
MEDIUM 6.1 2025-12-17
wordplus Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss
CVE NVD
CVE-2025-14385
WP Recipe Maker <= 10.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MEDIUM 6.4 2025-12-17
brechtvds WP Recipe Maker
CVE NVD
CVE-2025-13880
WP Social Ninja - Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 4.0.1 - Missing Authorization to Unauthenticated Plugin's Settings Disclosure And Modification
MEDIUM 6.5 2025-12-17
adreastrian WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets
CVE NVD
CVE-2025-13861
HTML Forms – Simple WordPress Forms Plugin <= 1.6.0 - Unauthenticated Stored Cross-Site Scripting
MEDIUM 6.1 2025-12-17
linksoftware HTML Forms – Simple WordPress Forms Plugin
CVE NVD
CVE-2025-59374
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with un...
CRITICAL 9.3 2025-12-17
ASUS live update asus live_update
CVE NVD
CVE-2025-11775
An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability ...
MEDIUM 4.8 2025-12-17
ASUS Armoury Crate
CVE NVD
CVE-2025-11901
An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B4...
HIGH 7.0 2025-12-17
ASUS B460 series ASUS B560 series +11个
CVE NVD
CVE-2025-64700
Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malic...
MEDIUM 5.1 2025-12-17
GROWI, Inc. GROWI
CVE NVD
CVE-2025-14305
Acer|ListCheck.exe - Local Privilege Escalation
HIGH 8.5 2025-12-17
Acer ListCheck.exe
CVE NVD
CVE-2025-14304
ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure
HIGH 7.0 2025-12-17
ASRock Intel 500 chipset motherboard ASRockRack Intel 500 chipset motherboard +10个
CVE NVD
CVE-2025-13977
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-12-17
wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets
CVE NVD
CVE-2025-14303
MSI|Motherboard - Protection Mechanism Failure
HIGH 7.0 2025-12-17
MSI Intel 600 chipset motherboard MSI Intel 700 chipset motherboard
CVE NVD
CVE-2025-14302
GIGABYTE|Motherboard - Protection Mechanism Failure
HIGH 7.0 2025-12-17
GIGABYTE intel 600 chipset Motherboard GIGABYTE intel 700 chipset Motherboard +4个
CVE NVD
CVE-2025-14801
xiweicheng TMS create createComment cross site scripting
MEDIUM 4.8 2025-12-17
xiweicheng TMS xiweicheng TMS +27个
CVE NVD