快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 352749
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-14385 |
WP Recipe Maker <= 10.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
|
MEDIUM | 6.4 | 2025-12-17 |
brechtvds WP Recipe Maker
|
CVE NVD | |
| CVE-2025-13880 |
WP Social Ninja - Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 4.0.1 - Missing Authorization to Unauthenticated Plugin's Settings Disclosure And Modification
|
MEDIUM | 6.5 | 2025-12-17 |
adreastrian WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets
|
CVE NVD | |
| CVE-2025-13861 |
HTML Forms – Simple WordPress Forms Plugin <= 1.6.0 - Unauthenticated Stored Cross-Site Scripting
|
MEDIUM | 6.1 | 2025-12-17 |
linksoftware HTML Forms – Simple WordPress Forms Plugin
|
CVE NVD | |
| CVE-2025-59374 |
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with un...
|
CRITICAL | 9.3 | 2025-12-17 |
ASUS live update
asus live_update
|
CVE NVD | |
| CVE-2025-11775 |
An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability ...
|
MEDIUM | 4.8 | 2025-12-17 |
ASUS Armoury Crate
|
CVE NVD | |
| CVE-2025-11901 |
An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B4...
|
HIGH | 7.0 | 2025-12-17 |
ASUS B460 series
ASUS B560 series
+11个
|
CVE NVD | |
| CVE-2025-64700 |
Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malic...
|
MEDIUM | 5.1 | 2025-12-17 |
GROWI, Inc. GROWI
|
CVE NVD | |
| CVE-2025-14305 |
Acer|ListCheck.exe - Local Privilege Escalation
|
HIGH | 8.5 | 2025-12-17 |
Acer ListCheck.exe
|
CVE NVD | |
| CVE-2025-14304 |
ASRock, ASRockRack, ASRockInd|Motherboard - Protection Mechanism Failure
|
HIGH | 7.0 | 2025-12-17 |
ASRock Intel 500 chipset motherboard
ASRockRack Intel 500 chipset motherboard
+10个
|
CVE NVD | |
| CVE-2025-13977 |
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-12-17 |
wpdevteam Essential Addons for Elementor – Popular Elementor Templates & Widgets
|
CVE NVD | |
| CVE-2025-14303 |
MSI|Motherboard - Protection Mechanism Failure
|
HIGH | 7.0 | 2025-12-17 |
MSI Intel 600 chipset motherboard
MSI Intel 700 chipset motherboard
|
CVE NVD | |
| CVE-2025-14302 |
GIGABYTE|Motherboard - Protection Mechanism Failure
|
HIGH | 7.0 | 2025-12-17 |
GIGABYTE intel 600 chipset Motherboard
GIGABYTE intel 700 chipset Motherboard
+4个
|
CVE NVD | |
| CVE-2025-14801 |
xiweicheng TMS create createComment cross site scripting
|
MEDIUM | 4.8 | 2025-12-17 |
xiweicheng TMS
xiweicheng TMS
+27个
|
CVE NVD | |
| CVE-2025-11369 |
Essential Blocks <= 5.7.2 - Missing Authorization To Authenticated (Author+) Information Disclosure
|
MEDIUM | 4.3 | 2025-12-17 |
wpdevteam Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
|
CVE NVD | |
| CVE-2025-11009 |
Information Disclosure Vulnerability in GT Designer3
|
MEDIUM | 5.1 | 2025-12-17 |
Mitsubishi Electric Corporation GT Designer3 Version1 (GOT2000)
Mitsubishi Electric Corporation GT Designer3 Version1 (GOT1000)
|
CVE NVD | |
| CVE-2025-53524 |
Fuji Electric Monitouch V-SFT-6 Out-of-bounds Write
|
HIGH | 8.4 | 2025-12-17 |
Fuji Electric Monitouch V-SFT-6
|
CVE NVD | |
| CVE-2025-14700 |
Improper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
|
CRITICAL | 9.9 | 2025-12-17 |
Arcadia Technology, LLC Crafty Controller
craftycontrol crafty_controller
|
CVE NVD | |
| CVE-2025-14701 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Crafty Controller
|
HIGH | 7.1 | 2025-12-17 |
Arcadia Technology, LLC Crafty Controller
craftycontrol crafty_controller
|
CVE NVD | |
| CVE-2022-23851 |
Netaxis API Orchestrator 安全漏洞
|
CRITICAL | 9.8 | 2025-12-17 |
netaxis api_orchestrator
|
CVE NVD +1 | |
| CVE-2024-29370 |
In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denia...
|
MEDIUM | 5.3 | 2025-12-17 |
python-jose_project python-jose
|
CVE NVD |