漏洞列表 352871
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-58137
Apache Fineract: IDOR via self-service API
HIGH 8.1 2025-12-12
Apache Software Foundation Apache Fineract apache fineract
CVE NVD
CVE-2025-12348
Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Action Scheduler Task Execution
MEDIUM 5.3 2025-12-12
icegram Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce
CVE NVD
CVE-2025-13993
MailerLite – Signup forms (official) <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
MEDIUM 5.5 2025-12-12
mailerlite MailerLite – Signup forms (official)
CVE NVD
CVE-2025-14074
PDF for Contact Form 7 + Drag and Drop Template Builder <= 6.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Duplication
MEDIUM 5.3 2025-12-12
addonsorg PDF for Contact Form 7 + Drag and Drop Template Builder
CVE NVD
CVE-2025-58130
Apache Fineract: Server Key not masked
CRITICAL 9.1 2025-12-12
Apache Software Foundation Apache Fineract apache fineract
CVE NVD
CVE-2025-23408
Apache Fineract: weak password policy
HIGH 8.5 2025-12-12
Apache Software Foundation Apache Fineract apache fineract
CVE NVD
CVE-2025-40829
A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applicat...
HIGH 7.3 2025-12-12
Siemens Simcenter Femap siemens simcenter_femap
CVE NVD
CVE-2025-12960
Simple CSV Table <= 1.0.1 - Directory Traversal to Authenticated (Contributor+) Arbitrary File Read
MEDIUM 6.5 2025-12-12
iworks Simple CSV Table
CVE NVD
CVE-2025-67731
Servify Express 资源管理错误漏洞
HIGH 8.7 2025-12-12
Aarondoran servify-express
CVE NVD +1
CVE-2025-67730
Frappe authenticated users can execute XSS through form description fields
MEDIUM 5.1 2025-12-12
frappe lms frappe learning
CVE NVD
CVE-2025-14169
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.5 - Unauthenticated SQL Injection
HIGH 7.5 2025-12-12
amans2k FunnelKit – Funnel Builder for WooCommerce Checkout
CVE NVD
CVE-2025-10583
WP Fastest Cache Premium <= 1.7.4 - Missing Authorization to Authenticated (Subscriber+) Blind Server-Side Request Forgery
LOW 3.5 2025-12-12
emrevona WP Fastest Cache
CVE NVD
CVE-2025-13891
Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing
MEDIUM 6.5 2025-12-12
wpchill Image Gallery – Photo Grid & Video Gallery
CVE NVD
CVE-2025-14049
VikRentItems Flexible Rental Management System <= 1.2.0 - Reflected Cross-Site Scripting via 'delto' Parameter
MEDIUM 6.1 2025-12-12
e4jvikwp VikRentItems Flexible Rental Management System
CVE NVD
CVE-2025-4970
BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload
MEDIUM 5.5 2025-12-12
bannersky BSK PDF Manager
CVE NVD
CVE-2025-11876
Mailgun Subscriptions <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-12-12
jbrinley Mailgun Subscriptions
CVE NVD
CVE-2025-67728
Fireshare Public Uploads feature is vulnerable to OS Command Injection (RCE)
CRITICAL 9.8 2025-12-12
ShaneIsrael fireshare shaneisrael fireshare
CVE NVD
CVE-2025-67737
AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE
LOW 3.1 2025-12-12
AzuraCast AzuraCast
CVE NVD
CVE-2025-67727
Parse Server 安全漏洞
MEDIUM 6.9 2025-12-12
parse-community parse-server parseplatform parse-server +1个
CVE NVD +1
CVE-2025-12655
Hippoo Mobile App for WooCommerce <= 1.7.1 - Missing Authorization to Unauthenticated Limited File Write
MEDIUM 5.3 2025-12-12
hippooo Hippoo Mobile App for WooCommerce
CVE NVD