快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 352231
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-62521 |
ChurchCRM has unauthenticated RCE in its Install Wizard
|
CRITICAL | 10.0 | 2025-12-17 |
ChurchCRM CRM
churchcrm churchcrm
|
CVE NVD | |
| CVE-2025-14081 |
Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Profile Privacy Setting Bypass
|
MEDIUM | 4.3 | 2025-12-17 |
ultimatemember Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
|
CVE NVD | |
| CVE-2025-13537 |
Live Composer – Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-12-17 |
livecomposer Live Composer – Free WordPress Website Builder
|
CVE NVD | |
| CVE-2025-13217 |
Ultimate Member <= 2.11.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value'
|
MEDIUM | 6.4 | 2025-12-17 |
ultimatemember Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
|
CVE NVD | |
| CVE-2025-13326 |
Mattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App Store
|
LOW | 3.9 | 2025-12-17 |
Mattermost Mattermost
mattermost mattermost_desktop
|
CVE NVD | |
| CVE-2025-13324 |
Lack of Invalidation of Legacy Remote Cluster Invite Tokens After Confirmation
|
LOW | 3.7 | 2025-12-17 |
Mattermost Mattermost
mattermost mattermost_server
|
CVE NVD | |
| CVE-2025-13321 |
Mattermost Desktop App logging sensitive information and fails to clear data on server deletion
|
LOW | 3.3 | 2025-12-17 |
Mattermost Mattermost
mattermost mattermost_desktop
|
CVE NVD | |
| CVE-2025-12689 |
DoS in Calls plugin via malformed UTF-8 in WebSocket request
|
MEDIUM | 6.5 | 2025-12-17 |
Mattermost Mattermost
mattermost mattermost_server
|
CVE NVD | |
| CVE-2025-20393 |
Cisco Secure Email和Cisco Secure Email and Web Manager 安全漏洞
|
CRITICAL | 10.0 | 2025-12-17 |
Cisco Cisco Secure Email
Cisco Cisco Secure Email
+43个
|
CVE NVD +1 | |
| CVE-2025-26381 |
OpenBlue Mobile Web Application configuration issue for optional for OpenBlue Workplace (formerly FM Systems)
|
MEDIUM | 6.5 | 2025-12-17 |
Johnson Controls OpenBlue Workplace (formerly FM Systems)
|
CVE NVD | |
| CVE-2025-43873 |
iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - setFaultDebounce
|
HIGH | 8.7 | 2025-12-17 |
Johnson Control iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2
|
CVE NVD | |
| CVE-2025-14727 |
NGINX Ingress Controller vulnerability
|
HIGH | 8.7 | 2025-12-17 |
F5 NGINX Ingress Controller
f5 nginx_ingress_controller
|
CVE NVD | |
| CVE-2025-44005 |
An attacker can bypass authorization checks and force a Step CA ACME or SCEP provisioner to create c...
|
CRITICAL | 10.0 | 2025-12-17 |
smallstep Step-CA
smallstep Step-CA
|
CVE NVD | |
| CVE-2025-14266 |
Ercom Cryptobox 安全漏洞
|
LOW | 0.6 | 2025-12-17 |
Ercom Cryptobox
|
CVE NVD +1 | |
| CVE-2025-61736 |
iSTAR- Improper Validation of Certificate Expiration
|
HIGH | 7.1 | 2025-12-17 |
Johnson Controls iSTAReX, iSTAR Edge, iSTAR Ultra LT, iSTAR Ultra , iSTAR Ultra SE
|
CVE NVD | |
| CVE-2025-14097 |
Remote Code Execution Vulnerability in Radiometer Products
|
HIGH | 7.2 | 2025-12-17 |
Radiometer Medical Aps ABL90 FLEX and ABL90 FLEX PLUS Analyzers
Radiometer Medical Aps ABL800 BASIC and ABL800 FLEX Analyzers
+1个
|
CVE NVD | |
| CVE-2025-14096 |
Credential Disclosure vulnerability in Radiometer Products
|
HIGH | 8.4 | 2025-12-17 |
Radiometer Medical Aps ABL90 FLEX and ABL90 FLEX PLUS Analyzers
Radiometer Medical Aps ABL90 FLEX and ABL90 FLEX PLUS Analyzers
+4个
|
CVE NVD | |
| CVE-2025-62690 |
Open redirect in error page when link opened in new tab
|
LOW | 3.1 | 2025-12-17 |
Mattermost Mattermost
mattermost mattermost_server
|
CVE NVD | |
| CVE-2025-13352 |
Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking
|
LOW | 3.0 | 2025-12-17 |
Mattermost Mattermost
mattermost mattermost_server
|
CVE NVD | |
| CVE-2025-62190 |
CSRF Allows Call Initiation and Message Delivery
|
MEDIUM | 4.3 | 2025-12-17 |
Mattermost Mattermost
mattermost mattermost_server
|
CVE NVD |