快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 354145
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-64408 |
Apache Causeway: Java deserialization vulnerability to authenticated attackers
|
MEDIUM | 6.3 | 2025-11-19 |
Apache Software Foundation Apache Causeway
apache causeway
+1个
|
CVE NVD | |
| CVE-2025-12472 |
Remote Code Execution in Looker due to Improperly Validated Directory Deletion
|
HIGH | 7.1 | 2025-11-19 |
Google Cloud Looker
|
CVE NVD | |
| CVE-2025-58412 |
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in For...
|
MEDIUM | 4.2 | 2025-11-19 |
Fortinet FortiADC
fortinet fortiadc
+1个
|
CVE NVD | |
| CVE-2025-11230 |
Denial of service vulnerability in HAProxy mjson library
|
HIGH | 7.5 | 2025-11-19 |
HAProxy Technologies HAProxy Community Edition
haproxy aloha_appliance
+7个
|
CVE NVD | |
| CVE-2025-11446 |
Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manage...
|
HIGH | 7.3 | 2025-11-19 |
upKeeper Solutions upKeeper Manager
upkeeper upkeeper_manager
|
CVE NVD | |
| CVE-2025-13035 |
Code Snippets <= 3.9.1 - Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains
|
HIGH | 8.0 | 2025-11-19 |
codesnippetspro Code Snippets
|
CVE NVD | |
| CVE-2025-13206 |
GiveWP - Donation Plugin and Fundraising Platform <= 4.13.0 - Unauthenticated Stored Cross-Site Scripting via 'name'
|
HIGH | 7.2 | 2025-11-19 |
stellarwp GiveWP – Donation Plugin and Fundraising Platform
givewp givewp
|
CVE NVD | |
| CVE-2025-12484 |
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers <= 1.12.19 - Unauthenticated Stored Cross-Site Scripting
|
HIGH | 7.2 | 2025-11-19 |
smub Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
|
CVE NVD | |
| CVE-2025-11243 |
Allocation of Resources Without Limits or Throttling in Shelly Pro 4PM
|
HIGH | 8.3 | 2025-11-19 |
Shelly Pro 4PM
|
CVE NVD | |
| CVE-2025-12056 |
Out-of-bounds Read in Shelly Pro 3EM
|
HIGH | 8.3 | 2025-11-19 |
Shelly Pro 3EM
|
CVE NVD | |
| CVE-2025-12535 |
SureForms <= 1.13.1 - Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution
|
MEDIUM | 5.3 | 2025-11-19 |
brainstormforce SureForms – Contact Form, Custom Form Builder, Calculator & More
|
CVE NVD | |
| CVE-2025-13085 |
SiteSEO – SEO Simplified <= 1.3.2 - Insecure Direct Object Reference to Sensitive Post Meta Disclosure
|
MEDIUM | 4.3 | 2025-11-19 |
softaculous SiteSEO – SEO Simplified
|
CVE NVD | |
| CVE-2025-12057 |
WavePlayer < 3.8.0 - Unauthenticated Arbitrary File Upload
|
CRITICAL | 9.8 | 2025-11-19 |
Unknown WavePlayer
|
CVE NVD | |
| CVE-2025-12814 |
SiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Reset
|
MEDIUM | 5.3 | 2025-11-19 |
softaculous SiteSEO – SEO Simplified
|
CVE NVD | |
| CVE-2025-12822 |
WP Login and Register using JWT <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) API Key Exposure
|
MEDIUM | 4.3 | 2025-11-19 |
cyberlord92 WP Login and Register using JWT
|
CVE NVD | |
| CVE-2025-12359 |
Responsive Lightbox & Gallery <= 2.5.3 - Authenticated (Author+) Server-Side Request Forgery
|
MEDIUM | 5.4 | 2025-11-19 |
dfactory Responsive Lightbox & Gallery
|
CVE NVD | |
| CVE-2025-12174 |
Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update
|
MEDIUM | 6.5 | 2025-11-19 |
wpwax Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings
|
CVE NVD | |
| CVE-2025-12878 |
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wfop_phone Shortcode
|
MEDIUM | 6.4 | 2025-11-19 |
amans2k FunnelKit – Funnel Builder for WooCommerce Checkout
|
CVE NVD | |
| CVE-2025-13145 |
WP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import
|
HIGH | 7.2 | 2025-11-19 |
smackcoders WP Import – Ultimate CSV XML Importer for WordPress
|
CVE NVD | |
| CVE-2025-12646 |
Community Events <= 1.5.4 - Unauthenticated SQL Injection
|
HIGH | 7.5 | 2025-11-19 |
jackdewey Community Events
|
CVE NVD |