漏洞列表 352231
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-62521
ChurchCRM has unauthenticated RCE in its Install Wizard
CRITICAL 10.0 2025-12-17
ChurchCRM CRM churchcrm churchcrm
CVE NVD
CVE-2025-14081
Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Profile Privacy Setting Bypass
MEDIUM 4.3 2025-12-17
ultimatemember Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
CVE NVD
CVE-2025-13537
Live Composer – Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
MEDIUM 6.4 2025-12-17
livecomposer Live Composer – Free WordPress Website Builder
CVE NVD
CVE-2025-13217
Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value'
MEDIUM 6.4 2025-12-17
ultimatemember Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
CVE NVD
CVE-2025-13326
Mattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App Store
LOW 3.9 2025-12-17
Mattermost Mattermost mattermost mattermost_desktop
CVE NVD
CVE-2025-13324
Lack of Invalidation of Legacy Remote Cluster Invite Tokens After Confirmation
LOW 3.7 2025-12-17
Mattermost Mattermost mattermost mattermost_server
CVE NVD
CVE-2025-13321
Mattermost Desktop App logging sensitive information and fails to clear data on server deletion
LOW 3.3 2025-12-17
Mattermost Mattermost mattermost mattermost_desktop
CVE NVD
CVE-2025-12689
DoS in Calls plugin via malformed UTF-8 in WebSocket request
MEDIUM 6.5 2025-12-17
Mattermost Mattermost mattermost mattermost_server
CVE NVD
CVE-2025-20393
Cisco Secure Email和Cisco Secure Email and Web Manager 安全漏洞
CRITICAL 10.0 2025-12-17
Cisco Cisco Secure Email Cisco Cisco Secure Email +43个
CVE NVD +1
CVE-2025-26381
OpenBlue Mobile Web Application configuration issue for optional for OpenBlue Workplace (formerly FM Systems)
MEDIUM 6.5 2025-12-17
Johnson Controls OpenBlue Workplace (formerly FM Systems)
CVE NVD
CVE-2025-43873
iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - setFaultDebounce
HIGH 8.7 2025-12-17
Johnson Control iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2
CVE NVD
CVE-2025-14727
NGINX Ingress Controller vulnerability
HIGH 8.7 2025-12-17
F5 NGINX Ingress Controller f5 nginx_ingress_controller
CVE NVD
CVE-2025-44005
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create c...
CRITICAL 10.0 2025-12-17
smallstep Step-CA smallstep Step-CA
CVE NVD
CVE-2025-14266
Ercom Cryptobox 安全漏洞
LOW 0.6 2025-12-17
Ercom Cryptobox
CVE NVD +1
CVE-2025-61736
iSTAR- Improper Validation of Certificate Expiration
HIGH 7.1 2025-12-17
Johnson Controls iSTAReX, iSTAR Edge, iSTAR Ultra LT, iSTAR Ultra , iSTAR Ultra SE
CVE NVD
CVE-2025-14097
Remote Code Execution Vulnerability in Radiometer Products
HIGH 7.2 2025-12-17
Radiometer Medical Aps ABL90 FLEX and ABL90 FLEX PLUS Analyzers Radiometer Medical Aps ABL800 BASIC and ABL800 FLEX Analyzers +1个
CVE NVD
CVE-2025-14096
Credential Disclosure vulnerability in Radiometer Products
HIGH 8.4 2025-12-17
Radiometer Medical Aps ABL90 FLEX and ABL90 FLEX PLUS Analyzers Radiometer Medical Aps ABL90 FLEX and ABL90 FLEX PLUS Analyzers +4个
CVE NVD
CVE-2025-62690
Open redirect in error page when link opened in new tab
LOW 3.1 2025-12-17
Mattermost Mattermost mattermost mattermost_server
CVE NVD
CVE-2025-13352
Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking
LOW 3.0 2025-12-17
Mattermost Mattermost mattermost mattermost_server
CVE NVD
CVE-2025-62190
CSRF Allows Call Initiation and Message Delivery
MEDIUM 4.3 2025-12-17
Mattermost Mattermost mattermost mattermost_server
CVE NVD