快速搜索提示:
按厂商查询(如:microsoft)|
按产品查询(如:microsoft sql_server)
漏洞列表 355639
| CVE ID | 标题 | 严重程度 | CVSS | 发布时间 | 受影响产品 | 数据源 | 操作 |
|---|---|---|---|---|---|---|---|
| CVE-2025-66073 |
WordPress WP Webhooks plugin <= 3.3.8 - PHP Object Injection vulnerability
|
MEDIUM | 6.5 | 2025-11-21 |
Cozmoslabs WP Webhooks
|
CVE NVD | |
| CVE-2025-66072 |
WordPress UsersWP plugin <= 1.2.47 - Broken Access Control vulnerability
|
CRITICAL | 9.8 | 2025-11-21 |
Stiofan UsersWP
|
CVE NVD | |
| CVE-2025-66071 |
WordPress Custom Order Numbers for WooCommerce plugin <= 1.11.0 - Broken Access Control vulnerability
|
CRITICAL | 9.8 | 2025-11-21 |
tychesoftwares Custom Order Numbers for WooCommerce
|
CVE NVD | |
| CVE-2025-66069 |
WordPress PPOM for WooCommerce plugin <= 33.0.16 - Broken Access Control vulnerability
|
MEDIUM | 4.3 | 2025-11-21 |
Themeisle PPOM for WooCommerce
|
CVE NVD | |
| CVE-2025-66067 |
WordPress Funnel Builder by FunnelKit plugin <= 3.13.1.2 - Cross Site Scripting (XSS) vulnerability
|
MEDIUM | 5.4 | 2025-11-21 |
FunnelKit Funnel Builder by FunnelKit
|
CVE NVD | |
| CVE-2025-66066 |
WordPress Envo Extra plugin <= 1.9.11 - Cross Site Scripting (XSS) vulnerability
|
MEDIUM | 6.1 | 2025-11-21 |
EnvoThemes Envo Extra
|
CVE NVD | |
| CVE-2025-66065 |
WordPress Gutenverse plugin <= 3.2.1 - Broken Access Control vulnerability
|
MEDIUM | 5.3 | 2025-11-21 |
Jegstudio Gutenverse
|
CVE NVD | |
| CVE-2025-66064 |
WordPress Giveaways and Contests by RafflePress plugin <= 1.12.20 - Cross Site Request Forgery (CSRF) vulnerability
|
MEDIUM | 5.3 | 2025-11-21 |
Syed Balkhi Giveaways and Contests by RafflePress
|
CVE NVD | |
| CVE-2025-66063 |
WordPress WP Google Review Slider plugin <= 17.4 - Broken Access Control vulnerability
|
MEDIUM | 5.4 | 2025-11-21 |
jgwhite33 WP Google Review Slider
|
CVE NVD | |
| CVE-2025-66062 |
WordPress WP YouTube Lyte plugin <= 1.7.28 - Open Redirection vulnerability
|
LOW | 3.7 | 2025-11-21 |
Frank Goossens WP YouTube Lyte
|
CVE NVD | |
| CVE-2025-66061 |
WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Cross Site Request Forgery (CSRF) vulnerability
|
MEDIUM | 4.3 | 2025-11-21 |
Craig Hewitt Seriously Simple Podcasting
castos seriously_simple_podcasting
|
CVE NVD | |
| CVE-2025-66060 |
WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Broken Access Control vulnerability
|
MEDIUM | 5.3 | 2025-11-21 |
Craig Hewitt Seriously Simple Podcasting
castos seriously_simple_podcasting
|
CVE NVD | |
| CVE-2025-66059 |
WordPress Seriously Simple Podcasting plugin <= 3.13.0 - Sensitive Data Exposure vulnerability
|
MEDIUM | 5.3 | 2025-11-21 |
Craig Hewitt Seriously Simple Podcasting
castos seriously_simple_podcasting
|
CVE NVD | |
| CVE-2025-66057 |
WordPress Bold Page Builder plugin <= 5.5.2 - Cross Site Scripting (XSS) vulnerability
|
MEDIUM | 6.3 | 2025-11-21 |
boldthemes Bold Page Builder
|
CVE NVD | |
| CVE-2025-66056 |
WordPress Uncanny Automator plugin < 6.10.0 - Sensitive Data Exposure vulnerability
|
MEDIUM | 4.3 | 2025-11-21 |
Uncanny Owl Uncanny Automator
|
CVE NVD | |
| CVE-2025-66055 |
WordPress Email Subscribers & Newsletters plugin <= 5.9.10 - PHP Object Injection vulnerability
|
HIGH | 7.2 | 2025-11-21 |
Icegram Email Subscribers & Newsletters
|
CVE NVD | |
| CVE-2025-66053 |
WordPress Enfold theme <= 7.1.2 - Cross Site Scripting (XSS) vulnerability
|
MEDIUM | 6.5 | 2025-11-21 |
Kriesi Enfold
|
CVE NVD | |
| CVE-2025-10039 |
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client'
|
MEDIUM | 4.3 | 2025-11-21 |
elextensions ELEX WordPress HelpDesk & Customer Ticketing System
elula wsdesk
|
CVE NVD | |
| CVE-2025-12935 |
FluentCRM - Marketing Automation For WordPress <= 2.9.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluentcrm_content' Shortcode
|
MEDIUM | 6.4 | 2025-11-21 |
techjewel FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
|
CVE NVD | |
| CVE-2025-10054 |
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Role Removal
|
MEDIUM | 5.3 | 2025-11-21 |
elextensions ELEX WordPress HelpDesk & Customer Ticketing System
elula wsdesk
|
CVE NVD |