快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 352871
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-11164 |
Mavix Education <= 1.0 - Missing Authorization to Authenticated (Subscriber+) 'Creativ Demo Importer' Plugin Activation
|
MEDIUM | 4.3 | 2025-12-13 |
creativthemes Mavix Education
|
CVE NVD | |
| CVE-2025-11707 |
Login Lockdown & Protection <= 2.14 - IP Block Bypass
|
MEDIUM | 5.3 | 2025-12-13 |
webfactory Login Lockdown & Protection
|
CVE NVD | |
| CVE-2025-14440 |
JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
|
CRITICAL | 9.8 | 2025-12-13 |
jayarsiech JAY Login & Register
|
CVE NVD | |
| CVE-2025-14508 |
MediaCommander – Bring Folders to Media, Posts, and Pages <= 2.3.1 - Missing Authorization to Authenticated (Author+) Media Folder Deletion
|
MEDIUM | 6.5 | 2025-12-13 |
yalogica MediaCommander – Bring Folders to Media, Posts, and Pages
|
CVE NVD | |
| CVE-2025-14539 |
Shortcode Loader <= 1.0 - Unauthenticated Arbitrary Shortcode Execution via 'code' Parameter
|
MEDIUM | 5.4 | 2025-12-13 |
rang501 Shortcode Ajax
|
CVE NVD | |
| CVE-2025-8617 |
YITH WooCommerce Quick View <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode
|
MEDIUM | 6.4 | 2025-12-13 |
yithemes YITH WooCommerce Quick View
|
CVE NVD | |
| CVE-2025-14367 |
Easy Theme Options <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Import
|
MEDIUM | 5.3 | 2025-12-13 |
corsonr Easy Theme Options
|
CVE NVD | |
| CVE-2025-7058 |
Kingcabs <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter
|
MEDIUM | 6.4 | 2025-12-13 |
sparklewpthemes Kingcabs
|
CVE NVD | |
| CVE-2025-12076 |
Social Media Auto Publish <= 3.6.5 - Reflected Cross-Site Scripting via PostMessage
|
MEDIUM | 6.1 | 2025-12-13 |
f1logic Social Media Auto Publish
|
CVE NVD | |
| CVE-2025-13093 |
Devs CRM – Manage tasks, attendance and teams all together <= 1.1.8 - Missing Authorization to Unauthenticated Lead Tag Update
|
MEDIUM | 5.3 | 2025-12-13 |
ajitdas Devs CRM – Manage tasks, attendance and teams all together
|
CVE NVD | |
| CVE-2025-13077 |
افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce <= 1.3.5 - Unauthenticated Time-Based Blind SQL Injection
|
HIGH | 7.5 | 2025-12-13 |
payamito افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce
|
CVE NVD | |
| CVE-2025-14451 |
Solutions Ad Manager <= 1.0.0 - Unauthenticated Open Redirect via 'sam-redirect-to' Parameter
|
MEDIUM | 4.7 | 2025-12-13 |
solutionsbysteve Solutions Ad Manager
|
CVE NVD | |
| CVE-2025-9218 |
rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function
|
LOW | 3.7 | 2025-12-13 |
rtcamp rtMedia for WordPress, BuddyPress and bbPress
|
CVE NVD | |
| CVE-2025-14288 |
Gallery Blocks with Lightbox <= 3.3.0 - Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification
|
MEDIUM | 4.3 | 2025-12-13 |
gallerycreator Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery
|
CVE NVD | |
| CVE-2025-13705 |
Custom Frames <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Parameter
|
MEDIUM | 6.4 | 2025-12-13 |
blakelong Custom Frames
|
CVE NVD | |
| CVE-2025-14476 |
Doubly <= 1.0.46 - Authenticated (Subscriber+) PHP Object Injection via ZIP File Import
|
HIGH | 8.8 | 2025-12-13 |
unitecms Doubly – Cross Domain Copy Paste for WordPress
|
CVE NVD | |
| CVE-2025-14475 |
Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via 'shortcode_name' Parameter
|
HIGH | 8.1 | 2025-12-13 |
nenad-obradovic Extensive VC Addons for WPBakery page builder
|
CVE NVD | |
| CVE-2025-14462 |
Lucky Draw Contests <= 4.2 - Cross-Site Request Forgery to Plugin Settings Update
|
MEDIUM | 4.3 | 2025-12-13 |
owais4377 Lucky Draw Contests
|
CVE NVD | |
| CVE-2025-11376 |
Colibri Page Builder <= 1.0.335 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-12-13 |
extendthemes Colibri Page Builder
|
CVE NVD | |
| CVE-2025-13094 |
WP3D Model Import Viewer <= 1.0.7 - Authenticated (Contributor+) Arbitrary File Upload
|
HIGH | 8.8 | 2025-12-13 |
wp3d WP3D Model Import Viewer
|
CVE NVD |