CVE-2025 第41页
CVE-2025-34152: Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via `time` Parameter-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34152: Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via `time` Parameter

漏洞标题 CVE-2025-34152: Shenzhen Aitemi M300 Wi-Fi Repeater – Unauthenticated Remote Command Execution via `time` Parameter 漏洞描述 An unauthenticated OS command injection vulne...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月11日 01:22
20
CVE-2025-55523: Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download-渗透云记 - 专注于网络安全与技术分享

CVE-2025-55523: Agent-Zero 0.8.0 – 0.9.4 – Arbitrary File Download

漏洞标题 CVE-2025-55523: Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download 漏洞描述 Agent-Zero v0.8.0 - 0.9.4 contains a path traversal caused by improper validation in /api/downl...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月16日 02:25
30
CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload

漏洞标题 CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload 漏洞描述 The Migration, Backup, Staging – WPvivid Backu...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月7日 17:22
50
CVE-2025-47646: PSW Front-end Login & Registration 1.13 - Weak Password Recovery-渗透云记 - 专注于网络安全与技术分享

CVE-2025-47646: PSW Front-end Login & Registration 1.13 – Weak Password Recovery

漏洞标题 CVE-2025-47646: PSW Front-end Login & Registration 1.13 - Weak Password Recovery 漏洞描述 PSW Front-end Login & Registration plugin for WordPress contains a weak p...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年11月23日 11:12
30
CVE-2025-2129: Mage AI - Insecure Default Authentication Setup-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2129: Mage AI – Insecure Default Authentication Setup

漏洞标题 CVE-2025-2129: Mage AI - Insecure Default Authentication Setup 漏洞描述 A vulnerability was found in Mage AI 0.9.75. It has been classified as problematic. This affects an...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月30日 09:34
20
CVE-2025-49001: Dataease JWT 认证绕过漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2025-49001: Dataease JWT 认证绕过漏洞

漏洞标题 CVE-2025-49001: Dataease JWT 认证绕过漏洞 漏洞描述 CVE-2025-49001 是由于JWT校验机制错误导致攻击者可伪造JWT令牌绕过身份验证流程 fofa: body="/js/index-0.0.0-dataease.js...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月3日 09:16
50
CVE-2025-49002: DataEase 远程代码执行漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2025-49002: DataEase 远程代码执行漏洞

漏洞标题 CVE-2025-49002: DataEase 远程代码执行漏洞 漏洞描述 CVE-2025-49002 是由于H2数据库模块没有严格过滤用户输入的JDBC连接参数,可使用大小写绕过补丁。攻击者可利用这些漏洞实现未授...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月22日 23:15
60
CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure

漏洞标题 CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure 漏洞描述 Vito Peleg Atarim <= 4.2 contains an insertion of sensitive information into sent data vulne...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年10月14日 08:59
30
CVE-2025-37164: HPE OneView - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-37164: HPE OneView – Remote Code Execution

漏洞标题 CVE-2025-37164: HPE OneView - Remote Code Execution 漏洞描述 HPE OneView contains a remote code execution vulnerability, letting remote attackers execute arbitrary code, e...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月26日 08:38
50
CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1974-k8s: Ingress-Nginx Controller – Unauthenticated Remote Code Execution

漏洞标题 CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution 漏洞描述 A security issue was discovered in ingress-nginx where the `auth-tls-match-cn`...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月19日 13:18
40
CVE-2025-24752: Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-24752: Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting

漏洞标题 CVE-2025-24752: Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting 漏洞描述 A Cross-Site Scripting (XSS) vulnerability exists in Essential Addons for Elemen...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月25日 10:09
40
CVE-2025-4009: Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4009: Evertz SDVN 3080ipx-10G – Unauthenticated Arbitrary Command Injection

漏洞标题 CVE-2025-4009: Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection 漏洞描述 The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月18日 01:53
30
CVE-2025-34026: Versa Concerto Actuator Endpoint - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34026: Versa Concerto Actuator Endpoint – Authentication Bypass

漏洞标题 CVE-2025-34026: Versa Concerto Actuator Endpoint - Authentication Bypass 漏洞描述 An authentication bypass vulnerability affected the Spring Boot Actuator endpoints in Ver...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月5日 13:40
30
CVE-2025-1097: Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-tls-match-cn` Annotation-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1097: Ingress-Nginx Controller – Configuration Injection via Unsanitized `auth-tls-match-cn` Annotation

漏洞标题 CVE-2025-1097: Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-tls-match-cn` Annotation 漏洞描述 A security issue was discovered in ingress-nginx ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月17日 11:30
30
CVE-2025-24514: Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` Annotation-渗透云记 - 专注于网络安全与技术分享

CVE-2025-24514: Ingress-Nginx Controller – Configuration Injection via Unsanitized `auth-url` Annotation

漏洞标题 CVE-2025-24514: Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` Annotation 漏洞描述 A security issue was discovered in ingress-nginx https-//...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年11月30日 15:04
10
CVE-2025-59474: Jenkins Sidepanel - Unauthorized Agent/Queue Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-59474: Jenkins Sidepanel – Unauthorized Agent/Queue Exposure

漏洞标题 CVE-2025-59474: Jenkins Sidepanel - Unauthorized Agent/Queue Exposure 漏洞描述 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in th...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年11月11日 22:03
30