漏洞列表 353043
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-66307
Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure
MEDIUM 6.5 2025-12-01
getgrav grav getgrav grav-plugin-admin
CVE NVD
CVE-2025-66306
Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
MEDIUM 4.3 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66305
Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter
MEDIUM 6.9 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66304
Grav Exposes Password Hashes Leading to privilege escalation
MEDIUM 6.2 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66303
Grav is vulnerable to a DOS on the admin panel
MEDIUM 4.9 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66302
Grav vulnerable to Path Traversal allowing server files backup
MEDIUM 6.8 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66301
Grav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
HIGH 8.6 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66300
Grav is vulnerable to Arbitrary File Read
HIGH 8.5 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66299
Security Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMS
HIGH 8.8 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66298
Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms
HIGH 7.7 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66297
Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
HIGH 7.4 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66296
Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
HIGH 8.8 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66294
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
HIGH 8.7 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66295
Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption
HIGH 8.8 2025-12-01
getgrav grav getgrav grav +1个
CVE NVD
CVE-2025-66206
Frappe vulnerable to a path traversal allowing reading certain files
MEDIUM 6.8 2025-12-01
frappe frappe frappe frappe +1个
CVE NVD
CVE-2025-66205
Frappe has the possibility of SQL Injection due to improper validations
HIGH 7.1 2025-12-01
frappe frappe frappe frappe +1个
CVE NVD
CVE-2024-51999
NOT_EXTRACTED
LOW -1.0 2025-12-01
未知
CVE NVD
CVE-2025-58044
JumpServer has an Open Redirect Vulnerability
MEDIUM 5.5 2025-12-01
jumpserver jumpserver jumpserver jumpserver +1个
CVE NVD
CVE-2025-55749
The XWiki Jetty package (XJetty) allows accessing any application file through URL
HIGH 8.7 2025-12-01
xwiki xwiki-platform xwiki xwiki-platform +1个
CVE NVD
CVE-2025-12756
Insecure Direct Object Reference in Mattermost Boards Plugin Enables Unauthorised Comment Deletion
MEDIUM 4.3 2025-12-01
Mattermost Mattermost mattermost mattermost_server
CVE NVD