快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 355639
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-59373 |
A local privilege escalation vulnerability exists in
the restore mechanism of
ASUS System Contr...
|
HIGH | 8.5 | 2025-11-25 |
ASUS MyASUS
|
CVE NVD | |
| CVE-2025-65951 |
Inside Track / Entropy Derby Timelock Encryption Bypassed via Pre-Computed VDF Output Leakage
|
HIGH | 8.7 | 2025-11-25 |
mescuwa entropy-derby
|
CVE NVD | |
| CVE-2025-65944 |
Sentry-Javascript deals with leaked sensitive headers when `sendDefaultPii` is set to `true`
|
MEDIUM | 5.1 | 2025-11-25 |
getsentry sentry-javascript
|
CVE NVD | |
| CVE-2025-64761 |
OpenBao Privileged Operator Identity Group Root Escalation
|
HIGH | 7.5 | 2025-11-25 |
openbao openbao
openbao openbao
|
CVE NVD | |
| CVE-2025-9803 |
Improper Authentication in lunary-ai/lunary
|
CRITICAL | 9.3 | 2025-11-25 |
lunary-ai lunary-ai/lunary
lunary lunary
|
CVE NVD | |
| CVE-2025-51741 |
An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthe...
|
HIGH | 7.5 | 2025-11-25 |
interviewx echo
interviewx echo
|
CVE NVD | |
| CVE-2025-51742 |
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList...
|
CRITICAL | 9.8 | 2025-11-25 |
jishenghua jsherp
|
CVE NVD | |
| CVE-2025-51743 |
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpo...
|
CRITICAL | 9.8 | 2025-11-25 |
jishenghua jsherp
|
CVE NVD | |
| CVE-2025-51744 |
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fas...
|
CRITICAL | 9.8 | 2025-11-25 |
jishenghua jsherp
|
CVE NVD | |
| CVE-2025-51745 |
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fast...
|
CRITICAL | 9.8 | 2025-11-25 |
jishenghua jsherp
|
CVE NVD | |
| CVE-2025-51746 |
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is v...
|
CRITICAL | 9.8 | 2025-11-25 |
jishenghua jsherp
|
CVE NVD | |
| CVE-2025-60739 |
Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.e...
|
CRITICAL | 9.6 | 2025-11-25 |
ilevia eve_x1_server_firmware
|
CVE NVD | |
| CVE-2025-61167 |
SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css...
|
MEDIUM | 6.5 | 2025-11-25 |
sigb pmb
|
CVE NVD | |
| CVE-2025-61168 |
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary c...
|
CRITICAL | 9.8 | 2025-11-25 |
sigb pmb
|
CVE NVD | |
| CVE-2025-63729 |
An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to...
|
CRITICAL | 9.0 | 2025-11-25 |
syrotech sy-gpon-1110-wdont_firmware
|
CVE NVD | |
| CVE-2025-63735 |
A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name...
|
MEDIUM | 6.1 | 2025-11-25 |
ruckuswireless ruckus_unleashed
|
CVE NVD | |
| CVE-2025-64049 |
A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5...
|
MEDIUM | 4.8 | 2025-11-25 |
redaxo redaxo
|
CVE NVD | |
| CVE-2025-64050 |
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20....
|
HIGH | 7.2 | 2025-11-25 |
redaxo redaxo
|
CVE NVD | |
| CVE-2025-64061 |
Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to ...
|
MEDIUM | 4.3 | 2025-11-25 |
primakon project_contract_management
|
CVE NVD | |
| CVE-2025-64062 |
The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but la...
|
HIGH | 8.8 | 2025-11-25 |
primakon project_contract_management
|
CVE NVD |