快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 353043
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-12826 |
Custom Post Type UI <= 1.18.0 - Missing Authorization to Unauthenticated (Previously Administrator+) Custom Post Type Modification
|
MEDIUM | 4.8 | 2025-12-04 |
webdevstudios Custom Post Type UI
|
CVE NVD | |
| CVE-2025-12782 |
Beaver Builder – WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Builder Status Tampering
|
MEDIUM | 4.3 | 2025-12-04 |
beaverbuilder Beaver Builder Page Builder – Drag and Drop Website Builder
fastlinemedia beaver_builder
|
CVE NVD | |
| CVE-2025-13513 |
Clik stats <= 0.8 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF']
|
MEDIUM | 6.1 | 2025-12-04 |
codejunkie Clik stats
|
CVE NVD | |
| CVE-2025-11727 |
Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration - Powered by Codisto <= 1.3.65 - Unauthenticated Stored Cross-Site Scripting
|
HIGH | 7.2 | 2025-12-04 |
codisto Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto
|
CVE NVD | |
| CVE-2025-11379 |
WebP Express <= 0.25.9 - Unauthenticated Information Exposure
|
MEDIUM | 5.3 | 2025-12-04 |
roselldk WebP Express
|
CVE NVD | |
| CVE-2025-29268 |
ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
|
CRITICAL | 9.8 | 2025-12-04 |
allnet all-rut22gw_firmware
|
CVE NVD | |
| CVE-2025-29269 |
ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the co...
|
CRITICAL | 9.8 | 2025-12-04 |
allnet all-rut22gw_firmware
|
CVE NVD | |
| CVE-2025-53963 |
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH ...
|
CRITICAL | 9.8 | 2025-12-04 |
thermofisher ion_torrent_onetouch_2_firmware
|
CVE NVD | |
| CVE-2025-54303 |
The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are st...
|
CRITICAL | 9.8 | 2025-12-04 |
thermofisher torrent_suite_software
|
CVE NVD | |
| CVE-2025-54304 |
An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are po...
|
CRITICAL | 9.8 | 2025-12-04 |
thermofisher ion_torrent_onetouch_2_firmware
|
CVE NVD | |
| CVE-2025-54305 |
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. One of the mid...
|
HIGH | 7.8 | 2025-12-04 |
thermofisher torrent_suite_software
|
CVE NVD | |
| CVE-2025-54306 |
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code ...
|
HIGH | 7.2 | 2025-12-04 |
thermofisher torrent_suite_software
|
CVE NVD | |
| CVE-2025-54307 |
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. The /configure...
|
HIGH | 8.8 | 2025-12-04 |
thermofisher torrent_suite_software
|
CVE NVD | |
| CVE-2025-55948 |
This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-bas...
|
HIGH | 7.3 | 2025-12-04 |
yzcheng90 x-springboot
|
CVE NVD | |
| CVE-2025-56427 |
Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitiv...
|
HIGH | 7.5 | 2025-12-04 |
composio composio
|
CVE NVD | |
| CVE-2025-57210 |
Incorrect access control in the component ApiPayController.java of platform v1.0.0 allows attackers ...
|
HIGH | 7.5 | 2025-12-04 |
fuyang_lipengjun platform
|
CVE NVD | |
| CVE-2025-57212 |
Incorrect access control in the component ApiOrderService.java of platform v1.0.0 allows attackers t...
|
HIGH | 7.5 | 2025-12-04 |
fuyang_lipengjun platform
|
CVE NVD | |
| CVE-2025-57213 |
Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attacke...
|
HIGH | 7.5 | 2025-12-04 |
fuyang_lipengjun platform
|
CVE NVD | |
| CVE-2025-59788 |
Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextclo...
|
MEDIUM | 6.4 | 2025-12-04 |
Nextcloud Nextcloud
|
CVE NVD | |
| CVE-2025-61148 |
An Insecure Direct Object Reference (IDOR) vulnerability in the EduplusCampus 3.0.1 Student Payment ...
|
MEDIUM | 6.5 | 2025-12-04 |
edupluscampus edupluscampus
|
CVE NVD |