漏洞列表 354145
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-13054
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MEDIUM 6.4 2025-11-19
cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
CVE NVD
CVE-2025-12710
Pet-Manager – Petfinder <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via kwm-petfinder Shortcode
MEDIUM 6.4 2025-11-19
kwmanagement Pet-Manager – Petfinder
CVE NVD
CVE-2025-12751
WSChat – WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
MEDIUM 4.3 2025-11-19
elextensions WSChat – WordPress Live Chat
CVE NVD
CVE-2025-12842
Booking Plugin for WordPress Appointments – Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending
MEDIUM 5.3 2025-11-19
timeslotplugins Booking Plugin for WordPress Appointments – Time Slot
CVE NVD
CVE-2025-12426
Quiz Maker <= 6.7.0.80 - Unauthenticated Sensitive Information Exposure
MEDIUM 5.3 2025-11-19
ays-pro Quiz Maker ays-pro quiz_maker
CVE NVD
CVE-2025-12349
Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue Trigger
MEDIUM 5.3 2025-11-19
icegram Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce
CVE NVD
CVE-2025-12427
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename
MEDIUM 5.3 2025-11-19
yithemes YITH WooCommerce Wishlist
CVE NVD
CVE-2025-6251
Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-19
wproyal Royal Addons for Elementor – Addons and Templates Kit for Elementor
CVE NVD
CVE-2025-12770
New User Approve <= 3.0.9 - Unauthenticated Sensitive Information Disclosure via Type Juggling
MEDIUM 5.3 2025-11-19
saadiqbal New User Approve
CVE NVD
CVE-2025-12777
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion
MEDIUM 5.3 2025-11-19
yithemes YITH WooCommerce Wishlist
CVE NVD
CVE-2025-13051
Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem privileges
CRITICAL 9.3 2025-11-19
ASUSTOR ABP and AES
CVE NVD
CVE-2025-13225
Tanium addressed an arbitrary file deletion vulnerability in TanOS.
MEDIUM 5.6 2025-11-19
Tanium TanOS tanium tanos
CVE NVD
CVE-2025-12852
DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker t...
HIGH 8.4 2025-11-19
NEC Corporation RakurakuMusen Start EX
CVE NVD
CVE-2025-51661
A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes wh...
HIGH 7.5 2025-11-19
lanol filecodebox
CVE NVD
CVE-2025-51662
A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBo...
MEDIUM 5.4 2025-11-19
lanol filecodebox
CVE NVD
CVE-2025-51663
A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers...
HIGH 7.5 2025-11-19
lanol filecodebox
CVE NVD
CVE-2025-63205
Bridgetech probes 安全漏洞
HIGH 7.5 2025-11-19
bridgetech vb220_firmware bridgetech vb120_firmware +3个
CVE NVD +1
CVE-2025-63206
An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware v...
CRITICAL 9.8 2025-11-19
dasannetworks ds2924_firmware dasannetworks ds2924_firmware
CVE NVD
CVE-2025-63207
The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broke...
CRITICAL 9.8 2025-11-19
rvr tex30lcd\/s_firmware rvr tex50lcd\/s_firmware +9个
CVE NVD
CVE-2025-63208
An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-...
HIGH 7.5 2025-11-19
bridgetech vb288_firmware
CVE NVD