快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 352871
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-58137 |
Apache Fineract: IDOR via self-service API
|
HIGH | 8.1 | 2025-12-12 |
Apache Software Foundation Apache Fineract
apache fineract
|
CVE NVD | |
| CVE-2025-12348 |
Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Action Scheduler Task Execution
|
MEDIUM | 5.3 | 2025-12-12 |
icegram Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce
|
CVE NVD | |
| CVE-2025-13993 |
MailerLite – Signup forms (official) <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
|
MEDIUM | 5.5 | 2025-12-12 |
mailerlite MailerLite – Signup forms (official)
|
CVE NVD | |
| CVE-2025-14074 |
PDF for Contact Form 7 + Drag and Drop Template Builder <= 6.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Duplication
|
MEDIUM | 5.3 | 2025-12-12 |
addonsorg PDF for Contact Form 7 + Drag and Drop Template Builder
|
CVE NVD | |
| CVE-2025-58130 |
Apache Fineract: Server Key not masked
|
CRITICAL | 9.1 | 2025-12-12 |
Apache Software Foundation Apache Fineract
apache fineract
|
CVE NVD | |
| CVE-2025-23408 |
Apache Fineract: weak password policy
|
HIGH | 8.5 | 2025-12-12 |
Apache Software Foundation Apache Fineract
apache fineract
|
CVE NVD | |
| CVE-2025-40829 |
A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applicat...
|
HIGH | 7.3 | 2025-12-12 |
Siemens Simcenter Femap
siemens simcenter_femap
|
CVE NVD | |
| CVE-2025-12960 |
Simple CSV Table <= 1.0.1 - Directory Traversal to Authenticated (Contributor+) Arbitrary File Read
|
MEDIUM | 6.5 | 2025-12-12 |
iworks Simple CSV Table
|
CVE NVD | |
| CVE-2025-67731 |
Servify Express 资源管理错误漏洞
|
HIGH | 8.7 | 2025-12-12 |
Aarondoran servify-express
|
CVE NVD +1 | |
| CVE-2025-67730 |
Frappe authenticated users can execute XSS through form description fields
|
MEDIUM | 5.1 | 2025-12-12 |
frappe lms
frappe learning
|
CVE NVD | |
| CVE-2025-14169 |
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.5 - Unauthenticated SQL Injection
|
HIGH | 7.5 | 2025-12-12 |
amans2k FunnelKit – Funnel Builder for WooCommerce Checkout
|
CVE NVD | |
| CVE-2025-10583 |
WP Fastest Cache Premium <= 1.7.4 - Missing Authorization to Authenticated (Subscriber+) Blind Server-Side Request Forgery
|
LOW | 3.5 | 2025-12-12 |
emrevona WP Fastest Cache
|
CVE NVD | |
| CVE-2025-13891 |
Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing
|
MEDIUM | 6.5 | 2025-12-12 |
wpchill Image Gallery – Photo Grid & Video Gallery
|
CVE NVD | |
| CVE-2025-14049 |
VikRentItems Flexible Rental Management System <= 1.2.0 - Reflected Cross-Site Scripting via 'delto' Parameter
|
MEDIUM | 6.1 | 2025-12-12 |
e4jvikwp VikRentItems Flexible Rental Management System
|
CVE NVD | |
| CVE-2025-4970 |
BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload
|
MEDIUM | 5.5 | 2025-12-12 |
bannersky BSK PDF Manager
|
CVE NVD | |
| CVE-2025-11876 |
Mailgun Subscriptions <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-12-12 |
jbrinley Mailgun Subscriptions
|
CVE NVD | |
| CVE-2025-67728 |
Fireshare Public Uploads feature is vulnerable to OS Command Injection (RCE)
|
CRITICAL | 9.8 | 2025-12-12 |
ShaneIsrael fireshare
shaneisrael fireshare
|
CVE NVD | |
| CVE-2025-67737 |
AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE
|
LOW | 3.1 | 2025-12-12 |
AzuraCast AzuraCast
|
CVE NVD | |
| CVE-2025-67727 |
Parse Server 安全漏洞
|
MEDIUM | 6.9 | 2025-12-12 |
parse-community parse-server
parseplatform parse-server
+1个
|
CVE NVD +1 | |
| CVE-2025-12655 |
Hippoo Mobile App for WooCommerce <= 1.7.1 - Missing Authorization to Unauthenticated Limited File Write
|
MEDIUM | 5.3 | 2025-12-12 |
hippooo Hippoo Mobile App for WooCommerce
|
CVE NVD |