漏洞列表 356851
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-9524
The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes...
MEDIUM 4.3 2025-11-11
Axis Communications AB AXIS OS
CVE NVD
CVE-2025-10714
AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead...
HIGH 8.4 2025-11-11
Axis Communications AB AXIS Optimizer
CVE NVD
CVE-2025-8108
An ACAP configuration file has improper permissions and lacks input validation, which could potentia...
MEDIUM 6.7 2025-11-11
Axis Communications AB AXIS OS axis axis_os
CVE NVD
CVE-2025-6779
An ACAP configuration file has improper permissions, which could allow command injection and potenti...
MEDIUM 6.7 2025-11-11
Axis Communications AB AXIS OS axis axis_os
CVE NVD
CVE-2025-6571
A 3rd-party component exposed its password in process arguments, allowing for low-privileged users t...
MEDIUM 6.0 2025-11-11
Axis Communications AB AXIS OS
CVE NVD
CVE-2025-5452
A malicious ACAP application can gain access to admin-level service account credentials used by legi...
MEDIUM 6.6 2025-11-11
Axis Communications AB AXIS OS axis axis_os
CVE NVD
CVE-2025-6298
ACAP applications can gain elevated privileges due to improper input validation, potentially leading...
MEDIUM 6.7 2025-11-11
Axis Communications AB AXIS OS axis axis_os
CVE NVD
CVE-2025-5718
The ACAP Application framework could allow privilege escalation through a symlink attack. This vulne...
MEDIUM 6.8 2025-11-11
Axis Communications AB AXIS OS axis axis_os
CVE NVD
CVE-2025-5454
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal at...
MEDIUM 6.4 2025-11-11
Axis Communications AB AXIS OS axis axis_os
CVE NVD
CVE-2025-4645
An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code ...
MEDIUM 6.7 2025-11-11
Axis Communications AB AXIS OS axis axis_os
CVE NVD
CVE-2025-11855
Age Restriction <= 3.0.2 - Subscriber+ Privilege Escalation
HIGH 7.5 2025-11-11
Unknown age-restriction
CVE NVD
CVE-2025-11307
WP Google Maps < 9.0.48 - Unauthenticated Stored XSS
HIGH 8.8 2025-11-11
Unknown WP Go Maps (formerly WP Google Maps)
CVE NVD
CVE-2025-11237
Make Email Customizer for WooCommerce <= 1.0.6 - Subscriber+ Arbitrary Options Update
MEDIUM 5.3 2025-11-11
Unknown Make Email Customizer for WooCommerce
CVE NVD
CVE-2025-12667
GitHub Gist Shortcode Plugin <= 0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
MEDIUM 6.4 2025-11-11
paul1999 GitHub Gist Shortcode Plugin
CVE NVD
CVE-2025-12651
Live Photos on WordPress <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MEDIUM 6.4 2025-11-11
eggemplo Live Photos on WordPress
CVE NVD
CVE-2025-12019
Featured Image <= 2.1 - Authenticated (Admin+) Stored Cross-Site Scripting
MEDIUM 4.4 2025-11-11
mervinpraison Featured Image mer.vin featured_image
CVE NVD
CVE-2025-11521
Astra Security Suite – Firewall & Malware Scan <= 0.2 - Unauthenticated Arbitrary File Upload
HIGH 8.1 2025-11-11
astrasecuritysuite Astra Security Suite – Firewall & Malware Scan
CVE NVD
CVE-2025-11999
Add Multiple Marker <= 1.2 - Missing Authorization to Unauthenticated Settings Update
MEDIUM 5.3 2025-11-11
krishaweb Add Multiple Marker
CVE NVD
CVE-2025-12662
Coon Google Maps <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MEDIUM 6.4 2025-11-11
andrico Coon Google Maps
CVE NVD
CVE-2025-11129
Include fussball.de Widgets <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'api' and 'type'
MEDIUM 6.4 2025-11-11
mheob Include Fussball.de Widgets
CVE NVD