CVE-2025 第11页
CVE-2025-68645: Zimbra Collaboration - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2025-68645: Zimbra Collaboration – Local File Inclusion

漏洞标题 CVE-2025-68645: Zimbra Collaboration - Local File Inclusion 漏洞描述 Zimbra Collaboration (ZCS) 10.0 and 10.1 contain a local file inclusion caused by improper handling of...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年11月23日 02:38
40
CVE-2025-54249: Adobe Experience Manager ≤ 6.5.23.0 – SSRF-渗透云记 - 专注于网络安全与技术分享

CVE-2025-54249: Adobe Experience Manager ≤ 6.5.23.0 – SSRF

漏洞标题 CVE-2025-54249: Adobe Experience Manager ≤ 6.5.23.0 – SSRF 漏洞描述 Adobe Experience Manager versions 6.5.23.0 and earlier are affected by a Server-Side Request Forgery ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月27日 00:06
70
CVE-2025-59474: Jenkins Sidepanel - Unauthorized Agent/Queue Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-59474: Jenkins Sidepanel – Unauthorized Agent/Queue Exposure

漏洞标题 CVE-2025-59474: Jenkins Sidepanel - Unauthorized Agent/Queue Exposure 漏洞描述 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in th...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年11月15日 20:00
60
CVE-2025-53833: LaRecipe < 2.8.1 Remote Code Execution via SSTI-渗透云记 - 专注于网络安全与技术分享

CVE-2025-53833: LaRecipe < 2.8.1 Remote Code Execution via SSTI

漏洞标题 CVE-2025-53833: LaRecipe < 2.8.1 Remote Code Execution via SSTI 漏洞描述 LaRecipe is an application that allows users to create documentation with Markdown inside a Lar...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月4日 01:10
10
CVE-2025-27225: TRUfusion Enterprise <= 7.10.4.0 - Admin Contact Portal-渗透云记 - 专注于网络安全与技术分享

CVE-2025-27225: TRUfusion Enterprise <= 7.10.4.0 - Admin Contact Portal

漏洞标题 CVE-2025-27225: TRUfusion Enterprise <= 7.10.4.0 - Admin Contact Portal 漏洞描述 TRUfusion Enterprise versions 7.10.4.0 and earlier contained a vulnerability that allow...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月23日 11:34
50
CVE-2025-6970: WordPress Events Manager <= 7.0.3 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6970: WordPress Events Manager <= 7.0.3 - SQL Injection

漏洞标题 CVE-2025-6970: WordPress Events Manager <= 7.0.3 - SQL Injection 漏洞描述 The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月15日 22:17
00
CVE-2025-44136: MapTiler Tileserver-php v2.0 - Unauthenticated XSS-渗透云记 - 专注于网络安全与技术分享

CVE-2025-44136: MapTiler Tileserver-php v2.0 – Unauthenticated XSS

漏洞标题 CVE-2025-44136: MapTiler Tileserver-php v2.0 - Unauthenticated XSS 漏洞描述 MapTiler Tileserver-php v2.0 contains a reflected XSS caused by unencoded reflection of the GET...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月1日 21:36
50
CVE-2025-2748: Kentico Xperience CMS - Unauthenticated Stored XSS-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2748: Kentico Xperience CMS – Unauthenticated Stored XSS

漏洞标题 CVE-2025-2748: Kentico Xperience CMS - Unauthenticated Stored XSS 漏洞描述 The Kentico Xperience application does not fully validate or filter files uploaded via the multi...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年11月15日 08:57
30
CVE-2025-4009: Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4009: Evertz SDVN 3080ipx-10G – Unauthenticated Arbitrary Command Injection

漏洞标题 CVE-2025-4009: Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection 漏洞描述 The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月15日 05:15
20
CVE-2025-47204: Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-47204: Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting

漏洞标题 CVE-2025-47204: Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting 漏洞描述 A PHP script in the source code release echoes arbitrary POST data. If a developer adopts...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月4日 08:44
20
CVE-2025-6403: Code-Projects School Fees Payment System 1.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6403: Code-Projects School Fees Payment System 1.0 – SQL Injection

漏洞标题 CVE-2025-6403: Code-Projects School Fees Payment System 1.0 - SQL Injection 漏洞描述 A vulnerability was found in code-projects School Fees Payment System 1.0. It has been...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月9日 10:19
00
CVE-2025-31489: MinIO - Incomplete Signature Validation for Unsigned-Trailer Uploads-渗透云记 - 专注于网络安全与技术分享

CVE-2025-31489: MinIO – Incomplete Signature Validation for Unsigned-Trailer Uploads

漏洞标题 CVE-2025-31489: MinIO - Incomplete Signature Validation for Unsigned-Trailer Uploads 漏洞描述 MinIO is a High Performance Object Storage released under GNU Affero General ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年10月25日 14:52
00
CVE-2025-6058: WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6058: WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload

漏洞标题 CVE-2025-6058: WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload 漏洞描述 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missi...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月29日 02:18
30
CVE-2025-1974: CVE-2025-1974-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1974: CVE-2025-1974

漏洞标题 CVE-2025-1974: CVE-2025-1974 漏洞描述 shodan: ssl:"ingress-nginx" port:8443 Kubernetes ingress-nginx是云原生计算基金会(Cloud Native Computing Foundation)开源...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月7日 10:50
30
CVE-2025-52970: Fortinet FortiWeb - Authentication Bypass to Admin Privilege-渗透云记 - 专注于网络安全与技术分享

CVE-2025-52970: Fortinet FortiWeb – Authentication Bypass to Admin Privilege

漏洞标题 CVE-2025-52970: Fortinet FortiWeb - Authentication Bypass to Admin Privilege 漏洞描述 A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, vers...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年6月18日 08:45
10
CVE-2025-1302: JSONPath Plus < 10.3.0 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1302: JSONPath Plus < 10.3.0 - Remote Code Execution

漏洞标题 CVE-2025-1302: JSONPath Plus < 10.3.0 - Remote Code Execution 漏洞描述 Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE)...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月3日 20:00
30