快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 353262
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-13141 |
HT Mega – Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection
|
MEDIUM | 6.4 | 2025-11-21 |
devitemsllc HT Mega – Absolute Addons For Elementor
|
CVE NVD | |
| CVE-2025-13149 |
Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories <= 4.9.1 - Authenticated (Author+) Missing Authorization to Post/Page Status Modification
|
MEDIUM | 4.3 | 2025-11-21 |
publishpress Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories
|
CVE NVD | |
| CVE-2025-11826 |
WP Company Info <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
|
MEDIUM | 6.4 | 2025-11-21 |
bdeleasa WP Company Info
|
CVE NVD | |
| CVE-2025-11973 |
简数采集器 <= 2.6.3 - Authenticated (Admin+) Arbitrary File Read
|
MEDIUM | 4.9 | 2025-11-21 |
zhengdon 简数采集器
|
CVE NVD | |
| CVE-2025-12039 |
BigBuy Dropshipping Connector for WooCommerce <= 2.0.5 - Unauthenticated IP Spoofing to phpinfo() Exposure
|
MEDIUM | 5.3 | 2025-11-21 |
devsmip BigBuy Dropshipping Connector for WooCommerce
|
CVE NVD | |
| CVE-2025-11803 |
WPSite Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
wpfanyi WPSite Shortcode
|
CVE NVD | |
| CVE-2025-11800 |
Surbma | MiniCRM Shortcode <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
surbma Surbma | MiniCRM Shortcode
|
CVE NVD | |
| CVE-2025-11985 |
Realty Portal <= 0.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
|
HIGH | 8.8 | 2025-11-21 |
nootheme Realty Portal
|
CVE NVD | |
| CVE-2025-11802 |
Bulma Shortcodes <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
bartboy011 Bulma Shortcodes
|
CVE NVD | |
| CVE-2025-11773 |
Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.6 - Missing Authorization to Authenticated (Subscriber+) Contract Address Update
|
MEDIUM | 4.3 | 2025-11-21 |
beycanpress Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO
|
CVE NVD | |
| CVE-2025-11763 |
Display Pages Shortcode <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
rustybadrobot Display Pages Shortcode
|
CVE NVD | |
| CVE-2025-13135 |
HotelRunner Booking Widget <= 5.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
integrationshotelrunner HotelRunner Booking Widget
|
CVE NVD | |
| CVE-2025-11764 |
Shortcodes Bootstrap <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
fastmover Shortcodes Bootstrap
|
CVE NVD | |
| CVE-2025-10938 |
UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
|
MEDIUM | 6.5 | 2025-11-21 |
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
|
CVE NVD | |
| CVE-2025-11771 |
Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.6 - Missing Authentication to Unauthenticated Presale Update
|
MEDIUM | 5.3 | 2025-11-21 |
beycanpress Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO
|
CVE NVD | |
| CVE-2025-11003 |
UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
|
CVE NVD | |
| CVE-2025-11799 |
Affiliate AI Lite <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
rustaurius Affiliate AI Lite
|
CVE NVD | |
| CVE-2025-11456 |
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload
|
CRITICAL | 9.8 | 2025-11-21 |
elextensions ELEX WordPress HelpDesk & Customer Ticketing System
elula wsdesk
|
CVE NVD | |
| CVE-2025-12881 |
Return Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read
|
MEDIUM | 5.4 | 2025-11-21 |
wpswings Return Refund and Exchange For WooCommerce
|
CVE NVD | |
| CVE-2025-11815 |
UiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
|
MEDIUM | 4.3 | 2025-11-21 |
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
|
CVE NVD |