快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 353571
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-64762 |
authkit-nextjs may let session cookies be cached in CDNs
|
HIGH | 8.0 | 2025-11-21 |
workos authkit-nextjs
workos authkit-nextjs
|
CVE NVD | |
| CVE-2025-64751 |
OpenFGA Improper Policy Enforcement
|
MEDIUM | 5.8 | 2025-11-21 |
openfga openfga
openfga helm_charts
+1个
|
CVE NVD | |
| CVE-2025-62372 |
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
|
HIGH | 8.3 | 2025-11-21 |
vllm-project vllm
vllm vllm
+1个
|
CVE NVD | |
| CVE-2025-62426 |
vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs`
|
MEDIUM | 6.5 | 2025-11-21 |
vllm-project vllm
vllm vllm
+1个
|
CVE NVD | |
| CVE-2025-62164 |
VLLM deserialization vulnerability leading to DoS and potential RCE
|
HIGH | 8.8 | 2025-11-21 |
vllm-project vllm
vllm vllm
+1个
|
CVE NVD | |
| CVE-2025-64755 |
@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File Writes
|
HIGH | 8.7 | 2025-11-21 |
anthropics claude-code
anthropic claude_code
|
CVE NVD | |
| CVE-2025-13485 |
itsourcecode Online File Management System ajax.php sql injection
|
MEDIUM | 6.9 | 2025-11-21 |
itsourcecode Online File Management System
admerc file_management_system
|
CVE NVD | |
| CVE-2025-13484 |
Campcodes Complete Online Beauty Parlor Management System customer-list.php cross site scripting
|
MEDIUM | 4.8 | 2025-11-20 |
Campcodes Complete Online Beauty Parlor Management System
campcodes online_beauty_parlor_management_system
|
CVE NVD | |
| CVE-2025-62459 |
Microsoft Defender Portal Spoofing Vulnerability
|
HIGH | 8.3 | 2025-11-20 |
Microsoft Microsoft 365 Defender Portal
microsoft 365_defender_portal
|
CVE NVD | |
| CVE-2025-64660 |
Microsoft Visual Studio Code 访问控制错误漏洞
|
HIGH | 8.0 | 2025-11-20 |
Microsoft Visual Studio Code
microsoft visual_studio_code
|
CVE NVD +1 | |
| CVE-2025-62207 |
Azure Monitor Elevation of Privilege Vulnerability
|
HIGH | 8.6 | 2025-11-20 |
Microsoft Azure Monitor Control Service
microsoft azure_monitor
|
CVE NVD | |
| CVE-2025-49752 |
Azure Bastion Elevation of Privilege Vulnerability
|
CRITICAL | 10.0 | 2025-11-20 |
Microsoft Azure Bastion Developer
microsoft azure_bastion_developer
|
CVE NVD | |
| CVE-2025-59245 |
Microsoft SharePoint Online Elevation of Privilege Vulnerability
|
CRITICAL | 9.8 | 2025-11-20 |
Microsoft Microsoft SharePoint Online
microsoft sharepoint_online
|
CVE NVD | |
| CVE-2025-64655 |
Dynamics OmniChannel SDK Storage Containers Elevation of Privilege Vulnerability
|
HIGH | 8.8 | 2025-11-20 |
Microsoft Dynamics OmniChannel SDK Storage Containers
microsoft dynamics_omnichannel_sdk_storage_containers
|
CVE NVD | |
| CVE-2025-36072 |
IBM webMethods Integration Deserialization
|
HIGH | 8.8 | 2025-11-20 |
IBM webMethods Integration
ibm webmethods_integration
+2个
|
CVE NVD | |
| CVE-2025-13087 |
Command Injection in Opto22 Groov REST API
|
HIGH | 7.5 | 2025-11-20 |
Opto22 GRV-EPIC-PR1
Opto22 GRV-EPIC-PR2
+3个
|
CVE NVD | |
| CVE-2025-36153 |
IBM Concert Cross-Site Scripting
|
MEDIUM | 6.1 | 2025-11-20 |
IBM Concert
ibm concert
|
CVE NVD | |
| CVE-2025-36158 |
IBM Concert Information Disclosure
|
MEDIUM | 5.1 | 2025-11-20 |
IBM Concert
ibm concert
|
CVE NVD | |
| CVE-2025-36159 |
IBM Concert Improper Log Neutralization
|
MEDIUM | 6.2 | 2025-11-20 |
IBM Concert
ibm concert
|
CVE NVD | |
| CVE-2025-36160 |
IBM Concert Information Disclosure
|
MEDIUM | 5.3 | 2025-11-20 |
IBM Concert
ibm concert
|
CVE NVD |