快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 352348
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2026-24140 |
MyTube has Mass Assignment via Settings Management
|
LOW | 2.7 | 2026-01-23 |
franklioxygen MyTube
|
CVE NVD | |
| CVE-2026-24139 |
MyTube Allows Unauthorized Database Export by Guest Users
|
HIGH | 8.7 | 2026-01-23 |
franklioxygen MyTube
|
CVE NVD | |
| CVE-2026-24474 |
Dioxus Components has JavaScript injection via user-supplied IDs
|
MEDIUM | 5.3 | 2026-01-23 |
DioxusLabs components
|
CVE NVD | |
| CVE-2026-24136 |
Saleor has an Insecure Direct Object Reference (IDOR) in GraphQL API
|
HIGH | 8.7 | 2026-01-23 |
saleor saleor
saleor saleor
+1个
|
CVE NVD | |
| CVE-2026-24128 |
XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages
|
MEDIUM | 6.5 | 2026-01-23 |
xwiki xwiki-platform
xwiki xwiki-platform
+1个
|
CVE NVD | |
| CVE-2026-24127 |
Typemill has Reflected XSS via login error view template
|
MEDIUM | 5.4 | 2026-01-23 |
typemill typemill
|
CVE NVD | |
| CVE-2026-1386 |
Arbitrary Host File Overwrite via Symlink in Firecracker Jailer
|
MEDIUM | 6.0 | 2026-01-23 |
AWS Firecracker
|
CVE NVD | |
| CVE-2025-14947 |
All-in-One Video Gallery <= 4.6.4 - Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion
|
MEDIUM | 6.5 | 2026-01-23 |
plugins360 All-in-One Video Gallery
|
CVE NVD | |
| CVE-2026-24423 |
SmarterTools SmarterMail < Build 9511 Unauthenticated RCE via ConnectToHub API
|
CRITICAL | 9.3 | 2026-01-23 |
SmarterTools SmarterMail
|
CVE NVD | |
| CVE-2021-47906 |
BloofoxCMS 0.5.2.1 - 'text' Stored Cross Site Scripting
|
MEDIUM | 5.1 | 2026-01-23 |
BloofoxCMS BloofoxCMS
|
CVE NVD | |
| CVE-2021-47905 |
MyBB Delete Account Plugin 1.4 - Cross-Site Scripting
|
MEDIUM | 5.1 | 2026-01-23 |
vintagedaddyo MyBB Delete Account Plugin
|
CVE NVD | |
| CVE-2021-47904 |
PhreeBooks 5.2.3 - Remote Code Execution
|
HIGH | 8.7 | 2026-01-23 |
Phreesoft PhreeBooks
|
CVE NVD | |
| CVE-2021-47903 |
LiteSpeed Web Server Enterprise 5.4.11 - Command Injection
|
HIGH | 8.6 | 2026-01-23 |
LiteSpeed Technologies Inc LiteSpeed Web Server Enterprise
|
CVE NVD | |
| CVE-2021-47899 |
YetiShare File Hosting Script 5.1.0 Remote File Upload SSRF Vulnerability
|
MEDIUM | 6.9 | 2026-01-23 |
Mfscripts YetiShare File Hosting Script
|
CVE NVD | |
| CVE-2021-47898 |
Epson USB Display 1.6.0.0 Unquoted Service Path Vulnerability
|
HIGH | 8.5 | 2026-01-23 |
Epson America, Inc. Epson USB Display
|
CVE NVD | |
| CVE-2021-47897 |
PEEL Shopping 9.3.0 - 'address' Stored Cross-Site Scripting
|
MEDIUM | 5.1 | 2026-01-23 |
PEEL eCommerce PEEL Shopping
|
CVE NVD | |
| CVE-2021-47896 |
PDFCOMPLETE Corporate Edition 4.1.45 - 'pdfcDispatcher' Unquoted Service Path
|
HIGH | 8.5 | 2026-01-23 |
PDF Complete, Inc. PDFCOMPLETE Corporate Edition
|
CVE NVD | |
| CVE-2021-47895 |
Nsauditor 3.2.2.0 - 'Event Description' Denial of Service
|
MEDIUM | 6.7 | 2026-01-23 |
Nsauditor Nsauditor
|
CVE NVD | |
| CVE-2021-47894 |
Managed Switch Port Mapping Tool 2.85.2 - Denial of Service
|
MEDIUM | 6.7 | 2026-01-23 |
Northwest Performance Software, Inc. Managed Switch Port Mapping Tool
|
CVE NVD | |
| CVE-2021-47893 |
AgataSoft PingMaster Pro 2.1 - Denial of Service
|
MEDIUM | 6.7 | 2026-01-23 |
Agatasoft AgataSoft PingMaster Pro
|
CVE NVD |