CVE 列表 – 发现高风险与在野利用漏洞

聚合 NVD、CVE 及多源情报,深度解析 RCE 等高危风险。系统集成 CVSS 与 EPSS 模型,动态追踪 Exploit 资源与 PoC 公开状态,研判可利用性。结合官方补丁与修复方案,优化漏洞管理优先级,缩短响应周期,保障资产安全。

分配机构(CNA / 来源):[email protected] 移除此筛选

显示 2212407441 条结果
CVE 描述 最高 CVSS EPSS % 公开时间 更新时间
CVE-2026-27425 Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2026-27419 Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. 9.9 0.36% 2026-07-02 2026-07-02
CVE-2026-27414 Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. 8.8 0.29% 2026-07-02 2026-07-02
CVE-2026-27412 Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. 8.1 0.28% 2026-07-02 2026-07-02
CVE-2026-27408 Unauthenticated Cross Site Scripting (XSS) in NativeChurch <= 4.8.8.2 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2026-27404 Unauthenticated Cross Site Scripting (XSS) in LMS <= 9.7 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2026-27402 Unauthenticated Cross Site Scripting (XSS) in Kids Life | Children School WordPress <= 5.2 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2026-27060 Contributor PHP Object Injection in ARMember Premium <= 7.0 versions. 8.8 0.29% 2026-07-02 2026-07-02
CVE-2025-69156 Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2025-69155 Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2025-69154 Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2025-69153 Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2025-69152 Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. 7.1 0.18% 2026-07-02 2026-07-02
CVE-2025-69134 Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. 7.5 0.30% 2026-07-02 2026-07-02
CVE-2025-69133 Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions. 7.5 0.40% 2026-07-02 2026-07-02
CVE-2025-69094 Subscriber SQL Injection in Unicamp <= 2.2.2 versions. 8.5 0.28% 2026-07-02 2026-07-02
CVE-2025-58902 Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. 8.1 0.28% 2026-07-02 2026-07-02
CVE-2026-57736 Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51. 7.4 0.18% 2026-07-01 2026-07-01
CVE-2026-57723 Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12. 7.4 0.12% 2026-07-01 2026-07-01
CVE-2026-57692 Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2. 9.8 0.29% 2026-07-01 2026-07-01
cvelogic Threat Intelligence