漏洞列表 352547
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-14442
Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File
MEDIUM 5.3 2025-12-12
ays-pro Secure Copy Content Protection and Content Locking
CVE NVD
CVE-2025-14065
Simple Bike Rental <= 1.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Booking Data Exposure
MEDIUM 5.3 2025-12-12
rodolforizzo76 Simple Bike Rental
CVE NVD
CVE-2025-12835
WooMulti <= 1.7 - Subscriber+ Arbitrary File Deletion
HIGH 7.3 2025-12-12
Unknown WooMulti
CVE NVD
CVE-2025-12841
Bookit < 2.5.1 – Unauthenticated Settings Update
MEDIUM 5.3 2025-12-12
Unknown Bookit
CVE NVD
CVE-2025-26866
Apache HugeGraph-Server: RAFT and deserialization vulnerability
HIGH 8.8 2025-12-12
Apache Software Foundation Apache HugeGraph-Server apache hugegraph
CVE NVD
CVE-2025-58137
Apache Fineract: IDOR via self-service API
HIGH 8.1 2025-12-12
Apache Software Foundation Apache Fineract apache fineract
CVE NVD
CVE-2025-12348
Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Action Scheduler Task Execution
MEDIUM 5.3 2025-12-12
icegram Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce
CVE NVD
CVE-2025-13993
MailerLite – Signup forms (official) <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
MEDIUM 5.5 2025-12-12
mailerlite MailerLite – Signup forms (official)
CVE NVD
CVE-2025-14074
PDF for Contact Form 7 + Drag and Drop Template Builder <= 6.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Duplication
MEDIUM 5.3 2025-12-12
addonsorg PDF for Contact Form 7 + Drag and Drop Template Builder
CVE NVD
CVE-2025-58130
Apache Fineract: Server Key not masked
CRITICAL 9.1 2025-12-12
Apache Software Foundation Apache Fineract apache fineract
CVE NVD
CVE-2025-23408
Apache Fineract: weak password policy
HIGH 8.5 2025-12-12
Apache Software Foundation Apache Fineract apache fineract
CVE NVD
CVE-2025-40829
A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applicat...
HIGH 7.3 2025-12-12
Siemens Simcenter Femap siemens simcenter_femap
CVE NVD
CVE-2025-12960
Simple CSV Table <= 1.0.1 - Directory Traversal to Authenticated (Contributor+) Arbitrary File Read
MEDIUM 6.5 2025-12-12
iworks Simple CSV Table
CVE NVD
CVE-2025-67731
Servify Express 资源管理错误漏洞
HIGH 8.7 2025-12-12
Aarondoran servify-express
CVE NVD +1
CVE-2025-67730
Frappe authenticated users can execute XSS through form description fields
MEDIUM 5.1 2025-12-12
frappe lms frappe learning
CVE NVD
CVE-2025-14169
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.5 - Unauthenticated SQL Injection
HIGH 7.5 2025-12-12
amans2k FunnelKit – Funnel Builder for WooCommerce Checkout
CVE NVD
CVE-2025-10583
WP Fastest Cache Premium <= 1.7.4 - Missing Authorization to Authenticated (Subscriber+) Blind Server-Side Request Forgery
LOW 3.5 2025-12-12
emrevona WP Fastest Cache
CVE NVD
CVE-2025-13891
Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing
MEDIUM 6.5 2025-12-12
wpchill Image Gallery – Photo Grid & Video Gallery
CVE NVD
CVE-2025-14049
VikRentItems Flexible Rental Management System <= 1.2.0 - Reflected Cross-Site Scripting via 'delto' Parameter
MEDIUM 6.1 2025-12-12
e4jvikwp VikRentItems Flexible Rental Management System
CVE NVD
CVE-2025-4970
BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload
MEDIUM 5.5 2025-12-12
bannersky BSK PDF Manager
CVE NVD