漏洞列表 354145
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-13303
code-projects Courier Management System search-edit.php sql injection
MEDIUM 5.3 2025-11-17
code-projects Courier Management System carmelogarcia courier_management_system
CVE NVD
CVE-2025-64766
NixOS has hardcoded credentials in Onlyoffice module
MEDIUM 5.3 2025-11-17
NixOS nixpkgs NixOS nixpkgs
CVE NVD
CVE-2025-13302
code-projects Courier Management System add-new-officer.php sql injection
MEDIUM 5.1 2025-11-17
code-projects Courier Management System carmelogarcia courier_management_system
CVE NVD
CVE-2025-13301
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-36118
IBM Storage Virtualize Information Disclosure
HIGH 7.5 2025-11-17
IBM Storage Virtualize IBM Storage Virtualize +6个
CVE NVD
CVE-2025-13300
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-36299
IBM Planning Analytics Information Disclosure
MEDIUM 4.3 2025-11-17
IBM IBM Planning Analytics Local ibm planning_analytics_local +1个
CVE NVD
CVE-2025-13299
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-13298
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-13297
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-34323
Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules
HIGH 8.5 2025-11-17
Nagios Log Server nagios log_server +1个
CVE NVD
CVE-2025-34322
Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries
HIGH 8.6 2025-11-17
Nagios Log Server nagios log_server +1个
CVE NVD
CVE-2025-55059
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
MEDIUM 4.8 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-55058
CWE-20 Improper Input Validation
MEDIUM 4.5 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-55057
Multiple CWE-352 Cross-Site Request Forgery (CSRF)
MEDIUM 4.5 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-64756
glob CLI: Command injection via -c/--cmd executes matches with shell:true
HIGH 7.5 2025-11-17
isaacs node-glob isaacs node-glob +1个
CVE NVD
CVE-2025-55056
Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scri...
MEDIUM 4.8 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-55055
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
MEDIUM 6.8 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-64758
@dependencytrack/frontend Vulnerable to Persistent Cross-Site-Scripting via Welcome Message
MEDIUM 4.8 2025-11-17
DependencyTrack frontend
CVE NVD
CVE-2025-64342
ESF-IDF's ESP32 Bluetooth Controller Has an Invalid Access Address Vulnerability
MEDIUM 6.9 2025-11-17
espressif esp-idf espressif esp-idf +3个
CVE NVD