CVE-2025 第28页
CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1974-k8s: Ingress-Nginx Controller – Unauthenticated Remote Code Execution

漏洞标题 CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution 漏洞描述 A security issue was discovered in ingress-nginx where the `auth-tls-match-cn`...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年10月5日 20:00
40
CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4302: Stop User Enumeration WordPress plugin – Authentication Bypass

漏洞标题 CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass 漏洞描述 Stop User Enumeration WordPress plugin < 1.7.3 contains an authentication bypass ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月4日 10:07
40
CVE-2025-30567: WordPress WP01 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2025-30567: WordPress WP01 – Path Traversal

漏洞标题 CVE-2025-30567: WordPress WP01 - Path Traversal 漏洞描述 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wp01ru W...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月1日 03:07
40
CVE-2025-5605: WSO2 Management Console - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-5605: WSO2 Management Console – Authentication Bypass

漏洞标题 CVE-2025-5605: WSO2 Management Console - Authentication Bypass 漏洞描述 An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年7月14日 15:20
40
CVE-2025-30208: Vite - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2025-30208: Vite – Arbitrary File Read

漏洞标题 CVE-2025-30208: Vite - Arbitrary File Read 漏洞描述 Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月16日 05:57
40
CVE-2025-34040: Zhiyuan OA Platform - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34040: Zhiyuan OA Platform – Arbitrary File Upload

漏洞标题 CVE-2025-34040: Zhiyuan OA Platform - Arbitrary File Upload 漏洞描述 An arbitrary file upload vulnerability exists in the Zhiyuan OA platform 5.0, 5.1 - 5.6sp1, 6.0 - 6.1s...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月26日 08:17
40
CVE-2025-51586: PrestaShop - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-51586: PrestaShop – Information Disclosure

漏洞标题 CVE-2025-51586: PrestaShop - Information Disclosure 漏洞描述 User enumeration vulnerability in the AdminLogin controller in PrestaShop 1.7 through 8.2.2 allows remote atta...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月9日 16:06
40
(CVE-2025-4123) Grafana 路径遍历与开放重定向导致的跨站脚本漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2025-4123) Grafana 路径遍历与开放重定向导致的跨站脚本漏洞

漏洞标题 (CVE-2025-4123) Grafana 路径遍历与开放重定向导致的跨站脚本漏洞 漏洞描述 (CVE-2025-4123) Grafana 路径遍历与开放重定向导致的跨站脚本漏洞 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年7月11日 06:28
40
CVE-2025-32813: Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request-渗透云记 - 专注于网络安全与技术分享

CVE-2025-32813: Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request

漏洞标题 CVE-2025-32813: Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request 漏洞描述 An issue was discovered in Infoblox NETMRI before 7.6.1. Remote...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月29日 13:58
40
CVE-2025-4322: Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4322: Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

漏洞标题 CVE-2025-4322: Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover 漏洞描述 The Motors theme for WordPress is vulnerable to pri...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月29日 16:41
40
CVE-2025-6403: Code-Projects School Fees Payment System 1.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6403: Code-Projects School Fees Payment System 1.0 – SQL Injection

漏洞标题 CVE-2025-6403: Code-Projects School Fees Payment System 1.0 - SQL Injection 漏洞描述 A vulnerability was found in code-projects School Fees Payment System 1.0. It has been...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年2月19日 08:01
40
CVE-2025-51501: Microweber CMS2.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-51501: Microweber CMS2.0 – Cross-Site Scripting

漏洞标题 CVE-2025-51501: Microweber CMS2.0 - Cross-Site Scripting 漏洞描述 Reflected Cross-Site Scripting (XSS) in the `id` parameter of the `live_edit.module_settings` API endpoin...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月9日 12:56
40
CVE-2025-28906: Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-28906: Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

漏洞标题 CVE-2025-28906: Skitter Slideshow <= 2.5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting 漏洞描述 The Skitter Slideshow plugin for WordPress is vulnerabl...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月27日 10:07
40
CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)

漏洞标题 CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected) 漏洞描述 The WordPress Qwizcards plugin before version 3.95 does not sanitise and escape th...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月15日 11:54
40
CVE-2025-37164: HPE OneView - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-37164: HPE OneView – Remote Code Execution

漏洞标题 CVE-2025-37164: HPE OneView - Remote Code Execution 漏洞描述 HPE OneView contains a remote code execution vulnerability, letting remote attackers execute arbitrary code, e...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月5日 00:20
40
CVE-2025-58434: Flowise <= 3.0.5 - Account Takeover-渗透云记 - 专注于网络安全与技术分享

CVE-2025-58434: Flowise <= 3.0.5 - Account Takeover

漏洞标题 CVE-2025-58434: Flowise <= 3.0.5 - Account Takeover 漏洞描述 Flowise versions 3.0.5 and earlier had a vulnerability in the forgot-password endpoint, which returned vali...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月11日 07:49
40