CVE-2025 第4页
CVE-2025-1595: EasyCVR <=2.1.2 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1595: EasyCVR <=2.1.2 - Information Disclosure

漏洞标题 CVE-2025-1595: EasyCVR <=2.1.2 - Information Disclosure 漏洞描述 A vulnerability has been found in Anhui Xufan Information Technology EasyCVR up to 2.7.0 and classified...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月25日 15:18
70
CVE-2025-27817: Apache Kafka 客户端任意文件读取-渗透云记 - 专注于网络安全与技术分享

CVE-2025-27817: Apache Kafka 客户端任意文件读取

漏洞标题 CVE-2025-27817: Apache Kafka 客户端任意文件读取 漏洞描述 允许未经身份验证的攻击者利用该漏洞实现任意文件读取,大多数据处理中间件或流式处理框架,如:Apache Spark Structured ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月29日 22:11
70
CVE-2025-25034: SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-25034: SugarCRM – Unauthenticated Remote Code Execution via PHP Object Injection

漏洞标题 CVE-2025-25034: SugarCRM - Unauthenticated Remote Code Execution via PHP Object Injection 漏洞描述 A PHP object injection vulnerability exists in SugarCRM versions prior t...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月3日 22:43
70
CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload

漏洞标题 CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload 漏洞描述 The Migration, Backup, Staging – WPvivid Backu...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月25日 13:33
70
CVE-2025-6851: WordPress Broken Link Notifier < 1.3.1 - Unauthenticated SSRF-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6851: WordPress Broken Link Notifier < 1.3.1 - Unauthenticated SSRF

漏洞标题 CVE-2025-6851: WordPress Broken Link Notifier < 1.3.1 - Unauthenticated SSRF 漏洞描述 The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月30日 16:29
70
CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection

漏洞标题 CVE-2025-2010: WordPress JobWP Plugin <= 2.3.9 - SQL Injection 漏洞描述 The JobWP - Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is v...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月31日 21:55
70
CVE-2025-34027: Versa Concerto API Path Based - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34027: Versa Concerto API Path Based – Authentication Bypass

漏洞标题 CVE-2025-34027: Versa Concerto API Path Based - Authentication Bypass 漏洞描述 Authentication bypass in the Versa Concerto API, caused by URL decoding inconsistencies. It ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月18日 23:15
70
CVE-2025-59474: Jenkins Sidepanel - Unauthorized Agent/Queue Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-59474: Jenkins Sidepanel – Unauthorized Agent/Queue Exposure

漏洞标题 CVE-2025-59474: Jenkins Sidepanel - Unauthorized Agent/Queue Exposure 漏洞描述 Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in th...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年11月15日 20:00
70
CVE-2025-34143: ETQ Reliance - Authentication Bypass via Trailing Space-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34143: ETQ Reliance – Authentication Bypass via Trailing Space

漏洞标题 CVE-2025-34143: ETQ Reliance - Authentication Bypass via Trailing Space 漏洞描述 An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform....
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年7月7日 02:49
70
CVE-2025-53770: Microsoft SharePoint Server - Remote Code Execution (ToolShell)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-53770: Microsoft SharePoint Server – Remote Code Execution (ToolShell)

漏洞标题 CVE-2025-53770: Microsoft SharePoint Server - Remote Code Execution (ToolShell) 漏洞描述 Deserialization of untrusted data in on-premises Microsoft SharePoint Server allow...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年2月25日 19:52
70
CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4302: Stop User Enumeration WordPress plugin – Authentication Bypass

漏洞标题 CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass 漏洞描述 Stop User Enumeration WordPress plugin < 1.7.3 contains an authentication bypass ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月14日 15:02
70
(CVE-2025-10210) ChanCMS Search功能SQL注入漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2025-10210) ChanCMS Search功能SQL注入漏洞

漏洞标题 (CVE-2025-10210) ChanCMS Search功能SQL注入漏洞 漏洞描述 (CVE-2025-10210) ChanCMS Search功能SQL注入漏洞 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月1日 19:21
70
CVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows – Log File Exposure

漏洞标题 CVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File Exposure 漏洞描述 Twonky Server 8.5.2 contains a broken access control vulnerability caused by bypassin...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月21日 01:38
70
CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1974-k8s: Ingress-Nginx Controller – Unauthenticated Remote Code Execution

漏洞标题 CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution 漏洞描述 A security issue was discovered in ingress-nginx where the `auth-tls-match-cn`...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月4日 02:00
70
CVE-2025-41646: RevPi Webstatus <= v2.4.5 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-41646: RevPi Webstatus <= v2.4.5 - Authentication Bypass

漏洞标题 CVE-2025-41646: RevPi Webstatus <= v2.4.5 - Authentication Bypass 漏洞描述 An unauthorized remote attacker can bypass the authentication of the affected software packag...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月27日 11:43
70
CVE-2025-8943: Flowise < 3.0.1 - Remote Command Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-8943: Flowise < 3.0.1 - Remote Command Execution

漏洞标题 CVE-2025-8943: Flowise < 3.0.1 - Remote Command Execution 漏洞描述 The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to s...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年7月5日 21:21
70