| CVE-2025-15444 |
Crypt::Sodium::XS libsodium椭圆曲线点验证漏洞 |
严重 |
9.8 |
2026-01-06 |
| CVE-2025-15385 |
TECNO Boomplayer认证绕过漏洞 |
严重 |
9.8 |
2026-01-06 |
| CVE-2025-15382 |
wolfSSH wolfSSH_CleanPath堆缓冲区越界读取漏洞 |
高危 |
8.1 |
2026-01-06 |
| CVE-2025-15364 |
WordPress Download Manager插件特权提升漏洞 |
高危 |
7.3 |
2026-01-06 |
| CVE-2025-15001 |
WordPress FS Registration Password插件账户接管漏洞 |
严重 |
9.8 |
2026-01-06 |
| CVE-2025-14997 |
WordPress BuddyPress Xprofile插件任意文件删除漏洞 |
高危 |
8.8 |
2026-01-06 |
| CVE-2025-14996 |
WordPress AS Password Field插件账户接管漏洞 |
严重 |
9.8 |
2026-01-06 |
| CVE-2025-14979 |
AirVPN Eddie MacOS本地提权漏洞 |
高危 |
7.8 |
2026-01-06 |
| CVE-2025-14942 |
wolfSSH密钥交换状态机漏洞可导致密码明文泄露 |
严重 |
9.8 |
2026-01-06 |
| CVE-2025-14552 |
MediaPress WordPress插件存储型XSS漏洞 |
中危 |
6.4 |
2026-01-06 |
| CVE-2025-14441 |
WordPress Popupkit插件未授权删除订阅者漏洞 |
中危 |
4.3 |
2026-01-06 |
| CVE-2025-14438 |
Xagio SEO插件pixabayDownloadImage函数SSRF漏洞 |
中危 |
6.4 |
2026-01-06 |
| CVE-2025-14371 |
WordPress Taxonomy Manager AI插件权限绕过漏洞 |
中危 |
4.3 |
2026-01-06 |
| CVE-2025-14153 |
WordPress Page Expire Popup SQL注入漏洞 |
中危 |
6.5 |
2026-01-06 |
| CVE-2025-14120 |
WordPress URL Image Importer插件SVG上传存储型XSS漏洞 |
中危 |
6.4 |
2026-01-06 |
| CVE-2025-14034 |
WordPress WooCommerce支持系统插件未授权访问漏洞 |
中危 |
5.3 |
2026-01-06 |
| CVE-2025-14026 |
Forcepoint One DLP Client Python ctypes限制绕过漏洞 |
高危 |
7.8 |
2026-01-06 |
| CVE-2025-13964 |
LearnPress WordPress LMS插件未授权修改数据漏洞 |
中危 |
5.3 |
2026-01-06 |
| CVE-2025-13812 |
| GamiPress WordPress插件未授权敏感信息泄露漏洞 |
中危 |
4.3 |
2026-01-06 |
| CVE-2025-13766 |
MasterStudy LMS WordPress插件权限绕过漏洞 |
中危 |
5.4 |
2026-01-06 |
| CVE-2025-13746 |
| ForumWP插件存储型XSS漏洞 |
中危 |
6.4 |
2026-01-06 |
| CVE-2025-13744 |
GitHub Enterprise Server Filter组件存储型XSS漏洞 (CVE-202... |
中危 |
5.4 |
2026-01-06 |
| CVE-2025-13652 |
WordPress CBX Bookmark插件orderby参数SQL注入漏洞 |
中危 |
6.5 |
2026-01-06 |
| CVE-2025-13409 |
WordPress Form Vibes插件SQL注入漏洞 |
中危 |
4.9 |
2026-01-06 |
| CVE-2025-13215 |
WordPress Phlox主题插件信息泄露漏洞 |
中危 |
5.3 |
2026-01-06 |
| CVE-2025-12793 |
ASUS Software Manager Agent DLL劫持漏洞导致本地权限提升 |
高危 |
7.8 |
2026-01-06 |
| CVE-2025-12067 |
WordPress Table Field插件存储型XSS漏洞 |
中危 |
6.4 |
2026-01-06 |
| CVE-2025-11723 |
WordPress Simply Schedule Appointments插件硬编码Salt敏感信... |
中危 |
6.5 |
2026-01-06 |
| CVE-2025-11370 |
Depicter WordPress插件未授权数据修改漏洞 |
中危 |
5.3 |
2026-01-06 |
| CVE-2024-31088 |
| AdsPlace'r WordPress插件DOM型XSS漏洞 |
中危 |
6.5 |
2026-01-06 |