CVE-2025 第35页
CVE-2025-47204: Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-47204: Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting

漏洞标题 CVE-2025-47204: Bootstrap Multiselect <= 1.1.2 - Cross-Site Scripting 漏洞描述 A PHP script in the source code release echoes arbitrary POST data. If a developer adopts...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月7日 12:00
40
CVE-2025-12055: MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2025-12055: MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 – Path Traversal

漏洞标题 CVE-2025-12055: MPDV Mikrolab GmbH HYDRA X, MIP 2 & FEDRA 2 - Path Traversal 漏洞描述 MPDV Mikrolab GmbH HYDRA X, MIP 2, and FEDRA 2 <= Maintenance Pack 36 with Ser...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月27日 09:39
40
CVE-2025-25062: Backdrop CMS - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-25062: Backdrop CMS – Cross-Site Scripting

漏洞标题 CVE-2025-25062: Backdrop CMS - Cross-Site Scripting 漏洞描述 An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't suf...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年6月13日 16:47
40
CVE-2025-47445: WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download-渗透云记 - 专注于网络安全与技术分享

CVE-2025-47445: WordPress Eventin (Themewinter) ≤ 4.0.26 – Arbitrary File Download

漏洞标题 CVE-2025-47445: WordPress Eventin (Themewinter) ≤ 4.0.26 - Arbitrary File Download 漏洞描述 Themewinter Eventin contains a path traversal caused by relative path manipula...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年6月30日 09:50
40
CVE-2025-2777: SysAid On-Prem <= 23.3.40 - XML External Entity-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2777: SysAid On-Prem <= 23.3.40 - XML External Entity

漏洞标题 CVE-2025-2777: SysAid On-Prem <= 23.3.40 - XML External Entity 漏洞描述 SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月20日 16:21
40
CVE-2025-1562: Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1562: Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit – Broken Access Control

漏洞标题 CVE-2025-1562: Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit - Broken Access Control 漏洞描述 The Recover WooCommerc...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月5日 11:08
40
CVE-2025-27112: Navidrome <=0.54.5 - Authentication Bypass in Subsonic API-渗透云记 - 专注于网络安全与技术分享

CVE-2025-27112: Navidrome <=0.54.5 - Authentication Bypass in Subsonic API

漏洞标题 CVE-2025-27112: Navidrome <=0.54.5 - Authentication Bypass in Subsonic API 漏洞描述 Navidrome is an open source web-based music collection server and streamer. Starting...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月10日 03:14
40
CVE-2025-1098: Ingress-Nginx Controller - Configuration Injection via Unsanitized Mirror Annotations-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1098: Ingress-Nginx Controller – Configuration Injection via Unsanitized Mirror Annotations

漏洞标题 CVE-2025-1098: Ingress-Nginx Controller - Configuration Injection via Unsanitized Mirror Annotations 漏洞描述 A security issue was discovered in ingress-nginx https-//gith...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月22日 05:08
40
CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1974-k8s: Ingress-Nginx Controller – Unauthenticated Remote Code Execution

漏洞标题 CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution 漏洞描述 A security issue was discovered in ingress-nginx where the `auth-tls-match-cn`...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月17日 17:57
40
Adobe Commerce/Magento SessionReaper /customer/address_file/upload 文件上传漏洞(CVE-2025-54236)-渗透云记 - 专注于网络安全与技术分享

Adobe Commerce/Magento SessionReaper /customer/address_file/upload 文件上传漏洞(CVE-2025-54236)

漏洞标题 Adobe Commerce/Magento SessionReaper /customer/address_file/upload 文件上传漏洞(CVE-2025-54236) 漏洞描述 Adobe Commerce是一款由Adobe公司开发的电子商务平台,广泛应用于全...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月11日 20:21
40
CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload

漏洞标题 CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload 漏洞描述 The Migration, Backup, Staging – WPvivid Backu...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月7日 00:31
40
CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4302: Stop User Enumeration WordPress plugin – Authentication Bypass

漏洞标题 CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass 漏洞描述 Stop User Enumeration WordPress plugin < 1.7.3 contains an authentication bypass ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月4日 10:07
40
CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4302: Stop User Enumeration WordPress plugin – Authentication Bypass

漏洞标题 CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass 漏洞描述 Stop User Enumeration WordPress plugin < 1.7.3 contains an authentication bypass ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月15日 18:05
30
CVE-2025-6970: WordPress Events Manager <= 7.0.3 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6970: WordPress Events Manager <= 7.0.3 - SQL Injection

漏洞标题 CVE-2025-6970: WordPress Events Manager <= 7.0.3 - SQL Injection 漏洞描述 The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年7月31日 20:52
30
CVE-2025-44137: MapTiler Tileserver-php v2.0 - Unauthenticated File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2025-44137: MapTiler Tileserver-php v2.0 – Unauthenticated File Read

漏洞标题 CVE-2025-44137: MapTiler Tileserver-php v2.0 - Unauthenticated File Read 漏洞描述 MapTiler Tileserver-php v2.0 contains a directory traversal caused by improper sanitizati...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月19日 09:05
30
CVE-2025-4380: Ads Pro Plugin <= 4.89 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4380: Ads Pro Plugin <= 4.89 - Local File Inclusion

漏洞标题 CVE-2025-4380: Ads Pro Plugin <= 4.89 - Local File Inclusion 漏洞描述 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerabl...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月11日 08:58
30