CVE-2025 第5页
CVE-2025-2712: Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2712: Yonyou UFIDA ERP-NC V5.0 – Cross-Site Scripting

漏洞标题 CVE-2025-2712: Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting 漏洞描述 Yonyou UFIDA ERP-NC V5.0 is vulnerable to reflected cross-site scripting (XSS) via the langcode par...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年2月9日 02:46
50
CVE-2025-54253: Adobe Experience Manager Forms - Insecure Deserialization-渗透云记 - 专注于网络安全与技术分享

CVE-2025-54253: Adobe Experience Manager Forms – Insecure Deserialization

漏洞标题 CVE-2025-54253: Adobe Experience Manager Forms - Insecure Deserialization 漏洞描述 Adobe Experience Manager versions 6.5.23 and earlier are affected by a Misconfiguration ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月15日 14:11
50
CVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-61757: Oracle Identity Manager REST WebServices – Authentication Bypass

漏洞标题 CVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication Bypass 漏洞描述 Vulnerability in the Identity Manager product of Oracle Fusion Middleware (compon...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月8日 05:17
50
CVE-2025-2747: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2747: Kentico Xperience 13 CMS – Staging Service Authentication Bypass (WT-2025-0006)

漏洞标题 CVE-2025-2747: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006) 漏洞描述 An authentication bypass vulnerability in Kentico Xperience allows ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年4月3日 10:51
50
CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1974-k8s: Ingress-Nginx Controller – Unauthenticated Remote Code Execution

漏洞标题 CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution 漏洞描述 A security issue was discovered in ingress-nginx where the `auth-tls-match-cn`...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月17日 00:59
50
CVE-2025-46818: Redis Lua Sandbox < 8.2.2 - Cross-User Escape-渗透云记 - 专注于网络安全与技术分享

CVE-2025-46818: Redis Lua Sandbox < 8.2.2 - Cross-User Escape

漏洞标题 CVE-2025-46818: Redis Lua Sandbox < 8.2.2 - Cross-User Escape 漏洞描述 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月12日 16:30
50
CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload

漏洞标题 CVE-2025-5961: WordPress WPvivid Backup & Migration Plugin <= 0.9.116 - Authenticated Arbitrary File Upload 漏洞描述 The Migration, Backup, Staging – WPvivid Backu...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月29日 08:47
50
CVE-2025-11749: WordPress AI Engine Plugin - Token Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-11749: WordPress AI Engine Plugin – Token Exposure

漏洞标题 CVE-2025-11749: WordPress AI Engine Plugin - Token Exposure 漏洞描述 Unauthenticated sensitive information exposure in AI Engine WordPress plugin <= 3.1.3 exposes beare...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年3月19日 15:17
50
CVE-2025-11371: Gladinet CentreStack & TrioFox - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2025-11371: Gladinet CentreStack & TrioFox – Local File Inclusion

漏洞标题 CVE-2025-11371: Gladinet CentreStack & TrioFox - Local File Inclusion 漏洞描述 In the default installation and configuration of Gladinet CentreStack and TrioFox, there...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年8月26日 06:08
50
CVE-2025-68613: n8n - Remote Code Execution via Expression Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-68613: n8n – Remote Code Execution via Expression Injection

漏洞标题 CVE-2025-68613: n8n - Remote Code Execution via Expression Injection 漏洞描述 n8n < 1.120.4, 1.121.1, 1.122.0 contains a remote code execution caused by insufficient is...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月2日 12:38
50
CVE-2025-0868: DocsGPT - Unauthenticated Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-0868: DocsGPT – Unauthenticated Remote Code Execution

漏洞标题 CVE-2025-0868: DocsGPT - Unauthenticated Remote Code Execution 漏洞描述 A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due t...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月16日 04:09
50
CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure

漏洞标题 CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure 漏洞描述 Vito Peleg Atarim <= 4.2 contains an insertion of sensitive information into sent data vulne...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月10日 08:16
50
CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-1974-k8s: Ingress-Nginx Controller – Unauthenticated Remote Code Execution

漏洞标题 CVE-2025-1974-k8s: Ingress-Nginx Controller - Unauthenticated Remote Code Execution 漏洞描述 A security issue was discovered in ingress-nginx where the `auth-tls-match-cn`...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年5月2日 06:45
50
CVE-2025-34045: WeiPHP 5.0 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34045: WeiPHP 5.0 – Path Traversal

漏洞标题 CVE-2025-34045: WeiPHP 5.0 - Path Traversal 漏洞描述 WeiPHP 5.0 contains a path traversal caused by insufficient input validation of the picUrl parameter in /public/index....
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年7月22日 04:17
50
CVE-2025-24514: Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` Annotation-渗透云记 - 专注于网络安全与技术分享

CVE-2025-24514: Ingress-Nginx Controller – Configuration Injection via Unsanitized `auth-url` Annotation

漏洞标题 CVE-2025-24514: Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` Annotation 漏洞描述 A security issue was discovered in ingress-nginx https-//...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年1月20日 02:48
50
CVE-2025-32969: XWiki REST API Query - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-32969: XWiki REST API Query – SQL Injection

漏洞标题 CVE-2025-32969: XWiki REST API Query - SQL Injection 漏洞描述 A SQL injection vulnerability exists in XWiki's REST API query endpoint. An unauthenticated attacker can...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年6月6日 18:58
50