漏洞列表 355639
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-59373
A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Contr...
HIGH 8.5 2025-11-25
ASUS MyASUS
CVE NVD
CVE-2025-65951
Inside Track / Entropy Derby Timelock Encryption Bypassed via Pre-Computed VDF Output Leakage
HIGH 8.7 2025-11-25
mescuwa entropy-derby
CVE NVD
CVE-2025-65944
Sentry-Javascript deals with leaked sensitive headers when `sendDefaultPii` is set to `true`
MEDIUM 5.1 2025-11-25
getsentry sentry-javascript
CVE NVD
CVE-2025-64761
OpenBao Privileged Operator Identity Group Root Escalation
HIGH 7.5 2025-11-25
openbao openbao openbao openbao
CVE NVD
CVE-2025-9803
Improper Authentication in lunary-ai/lunary
CRITICAL 9.3 2025-11-25
lunary-ai lunary-ai/lunary lunary lunary
CVE NVD
CVE-2025-51741
An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthe...
HIGH 7.5 2025-11-25
interviewx echo interviewx echo
CVE NVD
CVE-2025-51742
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList...
CRITICAL 9.8 2025-11-25
jishenghua jsherp
CVE NVD
CVE-2025-51743
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpo...
CRITICAL 9.8 2025-11-25
jishenghua jsherp
CVE NVD
CVE-2025-51744
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fas...
CRITICAL 9.8 2025-11-25
jishenghua jsherp
CVE NVD
CVE-2025-51745
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fast...
CRITICAL 9.8 2025-11-25
jishenghua jsherp
CVE NVD
CVE-2025-51746
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is v...
CRITICAL 9.8 2025-11-25
jishenghua jsherp
CVE NVD
CVE-2025-60739
Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.e...
CRITICAL 9.6 2025-11-25
ilevia eve_x1_server_firmware
CVE NVD
CVE-2025-61167
SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css...
MEDIUM 6.5 2025-11-25
sigb pmb
CVE NVD
CVE-2025-61168
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary c...
CRITICAL 9.8 2025-11-25
sigb pmb
CVE NVD
CVE-2025-63729
An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to...
CRITICAL 9.0 2025-11-25
syrotech sy-gpon-1110-wdont_firmware
CVE NVD
CVE-2025-63735
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name...
MEDIUM 6.1 2025-11-25
ruckuswireless ruckus_unleashed
CVE NVD
CVE-2025-64049
A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5...
MEDIUM 4.8 2025-11-25
redaxo redaxo
CVE NVD
CVE-2025-64050
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20....
HIGH 7.2 2025-11-25
redaxo redaxo
CVE NVD
CVE-2025-64061
Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to ...
MEDIUM 4.3 2025-11-25
primakon project_contract_management
CVE NVD
CVE-2025-64062
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but la...
HIGH 8.8 2025-11-25
primakon project_contract_management
CVE NVD