快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 353262
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-12814 |
SiteSEO – SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Reset
|
MEDIUM | 5.3 | 2025-11-19 |
softaculous SiteSEO – SEO Simplified
|
CVE NVD | |
| CVE-2025-12822 |
WP Login and Register using JWT <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) API Key Exposure
|
MEDIUM | 4.3 | 2025-11-19 |
cyberlord92 WP Login and Register using JWT
|
CVE NVD | |
| CVE-2025-12359 |
Responsive Lightbox & Gallery <= 2.5.3 - Authenticated (Author+) Server-Side Request Forgery
|
MEDIUM | 5.4 | 2025-11-19 |
dfactory Responsive Lightbox & Gallery
|
CVE NVD | |
| CVE-2025-12174 |
Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update
|
MEDIUM | 6.5 | 2025-11-19 |
wpwax Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings
|
CVE NVD | |
| CVE-2025-12878 |
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wfop_phone Shortcode
|
MEDIUM | 6.4 | 2025-11-19 |
amans2k FunnelKit – Funnel Builder for WooCommerce Checkout
|
CVE NVD | |
| CVE-2025-13145 |
WP Import – Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import
|
HIGH | 7.2 | 2025-11-19 |
smackcoders WP Import – Ultimate CSV XML Importer for WordPress
|
CVE NVD | |
| CVE-2025-12646 |
Community Events <= 1.5.4 - Unauthenticated SQL Injection
|
HIGH | 7.5 | 2025-11-19 |
jackdewey Community Events
|
CVE NVD | |
| CVE-2025-13054 |
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
|
MEDIUM | 6.4 | 2025-11-19 |
cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor
|
CVE NVD | |
| CVE-2025-12710 |
Pet-Manager – Petfinder <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via kwm-petfinder Shortcode
|
MEDIUM | 6.4 | 2025-11-19 |
kwmanagement Pet-Manager – Petfinder
|
CVE NVD | |
| CVE-2025-12751 |
WSChat – WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
|
MEDIUM | 4.3 | 2025-11-19 |
elextensions WSChat – WordPress Live Chat
|
CVE NVD | |
| CVE-2025-12842 |
Booking Plugin for WordPress Appointments – Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending
|
MEDIUM | 5.3 | 2025-11-19 |
timeslotplugins Booking Plugin for WordPress Appointments – Time Slot
|
CVE NVD | |
| CVE-2025-12426 |
Quiz Maker <= 6.7.0.80 - Unauthenticated Sensitive Information Exposure
|
MEDIUM | 5.3 | 2025-11-19 |
ays-pro Quiz Maker
ays-pro quiz_maker
|
CVE NVD | |
| CVE-2025-12349 |
Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue Trigger
|
MEDIUM | 5.3 | 2025-11-19 |
icegram Email Subscribers & Newsletters – Powerful Email Marketing, Post Notification & Newsletter Plugin for WordPress & WooCommerce
|
CVE NVD | |
| CVE-2025-12427 |
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename
|
MEDIUM | 5.3 | 2025-11-19 |
yithemes YITH WooCommerce Wishlist
|
CVE NVD | |
| CVE-2025-6251 |
Royal Elementor Addons and Templates <= 1.7.1036 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-19 |
wproyal Royal Addons for Elementor – Addons and Templates Kit for Elementor
|
CVE NVD | |
| CVE-2025-12770 |
New User Approve <= 3.0.9 - Unauthenticated Sensitive Information Disclosure via Type Juggling
|
MEDIUM | 5.3 | 2025-11-19 |
saadiqbal New User Approve
|
CVE NVD | |
| CVE-2025-12777 |
YITH WooCommerce Wishlist <= 4.10.0 - Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion
|
MEDIUM | 5.3 | 2025-11-19 |
yithemes YITH WooCommerce Wishlist
|
CVE NVD | |
| CVE-2025-13051 |
Windows service used an uncontrolled search path element will cause unauthorized code execution with localsystem privileges
|
CRITICAL | 9.3 | 2025-11-19 |
ASUSTOR ABP and AES
|
CVE NVD | |
| CVE-2025-13225 |
Tanium addressed an arbitrary file deletion vulnerability in TanOS.
|
MEDIUM | 5.6 | 2025-11-19 |
Tanium TanOS
tanium tanos
|
CVE NVD | |
| CVE-2025-12852 |
DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker t...
|
HIGH | 8.4 | 2025-11-19 |
NEC Corporation RakurakuMusen Start EX
|
CVE NVD |