快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 353571
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-11764 |
Shortcodes Bootstrap <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
fastmover Shortcodes Bootstrap
|
CVE NVD | |
| CVE-2025-10938 |
UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure
|
MEDIUM | 6.5 | 2025-11-21 |
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
|
CVE NVD | |
| CVE-2025-11771 |
Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO <= 2.4.6 - Missing Authentication to Unauthenticated Presale Update
|
MEDIUM | 5.3 | 2025-11-21 |
beycanpress Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO
|
CVE NVD | |
| CVE-2025-11003 |
UiPress lite <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
|
CVE NVD | |
| CVE-2025-11799 |
Affiliate AI Lite <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
rustaurius Affiliate AI Lite
|
CVE NVD | |
| CVE-2025-11456 |
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload
|
CRITICAL | 9.8 | 2025-11-21 |
elextensions ELEX WordPress HelpDesk & Customer Ticketing System
elula wsdesk
|
CVE NVD | |
| CVE-2025-12881 |
Return Refund and Exchange For WooCommerce <= 4.5.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read
|
MEDIUM | 5.4 | 2025-11-21 |
wpswings Return Refund and Exchange For WooCommerce
|
CVE NVD | |
| CVE-2025-11815 |
UiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.08 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update
|
MEDIUM | 4.3 | 2025-11-21 |
admintwentytwenty UiPress lite | Effortless custom dashboards, admin themes and pages
|
CVE NVD | |
| CVE-2025-13159 |
Flo Forms – Easy Drag & Drop Form Builder <= 1.0.43 - Unauthenticated Stored Cross-Site Scripting via SVG Upload
|
HIGH | 7.1 | 2025-11-21 |
flothemesplugins Flo Forms – Easy Drag & Drop Form Builder
|
CVE NVD | |
| CVE-2025-13134 |
AuthorSure <= 2.3 - Cross-Site Request Forgery to Stored Cross-Site Scripting
|
MEDIUM | 6.1 | 2025-11-21 |
powerblogservice AuthorSure
|
CVE NVD | |
| CVE-2025-12135 |
WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting
|
HIGH | 7.2 | 2025-11-21 |
iqonicdesign WPBookit
|
CVE NVD | |
| CVE-2025-11885 |
EchBay Admin Security <= 1.3.0 - Reflected Cross-Site Scripting
|
MEDIUM | 6.1 | 2025-11-21 |
itvn9online EchBay Admin Security
|
CVE NVD | |
| CVE-2025-13142 |
Custom Post Type <= 1.0 - Cross-Site Request Forgery to Custom Post Type Deletion
|
MEDIUM | 4.3 | 2025-11-21 |
farvehandleren Custom Post Type
|
CVE NVD | |
| CVE-2025-11768 |
Islamic Phrases <= 2.12.2015 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
darto Islamic Phrases
|
CVE NVD | |
| CVE-2025-11770 |
BrightTALK WordPress Shortcode <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
billybigpotatoes BrightTALK WordPress Shortcode
|
CVE NVD | |
| CVE-2025-11767 |
Tips Shortcode <= 0.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
fpcorso Tips Shortcode
|
CVE NVD | |
| CVE-2025-12894 |
Import WP – Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure
|
MEDIUM | 5.3 | 2025-11-21 |
jcollings Import WP – Export and Import CSV and XML files to WordPress
|
CVE NVD | |
| CVE-2025-11801 |
AudioTube <= 0.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
davidangel AudioTube
|
CVE NVD | |
| CVE-2025-12138 |
URL Image Importer <= 1.0.6 - Authenticated (Author+) Arbitrary File Upload
|
HIGH | 8.8 | 2025-11-21 |
bww URL Image Importer
|
CVE NVD | |
| CVE-2025-11765 |
Stock Tools <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
|
MEDIUM | 6.4 | 2025-11-21 |
developdaly Stock Tools
|
CVE NVD |