漏洞列表 360566
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-70033
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was disco
MEDIUM 5.4 2026-03-09
未知
NVD
CVE-2025-70037
An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in linagora Twake v
MEDIUM 6.1 2026-03-09
linagora twake
NVD
CVE-2025-15568
A command injection vulnerability was identified in the web module of Archer AXE75 v1.6/v1.0 router.
UNKNOWN N/A 2026-03-09
未知
NVD
CVE-2026-3588
A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to e
HIGH 7.5 2026-03-09
未知
NVD
CVE-2026-25866
MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The appl
HIGH 7.8 2026-03-09
未知
NVD
CVE-2025-70060
An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was disco
MEDIUM 5.4 2026-03-09
ymfe yapi
NVD
CVE-2025-70050
An issue pertaining to CWE-312: Cleartext Storage of Sensitive Information was discovered in lesspas
MEDIUM 6.5 2026-03-09
lesspass lesspass
NVD
CVE-2025-70048
An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Ne
HIGH 7.5 2026-03-09
nexus nexusinterface
NVD
CVE-2025-70047
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusIn
HIGH 7.5 2026-03-09
nexus nexusinterface
NVD
CVE-2025-70046
An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discove
CRITICAL 9.8 2026-03-09
miazzy oa-font-service
NVD
CVE-2025-70042
An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube
CRITICAL 9.8 2026-03-09
未知
NVD
CVE-2025-70040
An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in L
MEDIUM 5.3 2026-03-09
未知
NVD
CVE-2024-14027
In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fr
UNKNOWN N/A 2026-03-09
未知
NVD
CVE-2025-70250
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/form
HIGH 7.5 2026-03-09
dlink dir-513_firmware
NVD
CVE-2025-70243
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/form
HIGH 7.5 2026-03-09
dlink dir-513_firmware
NVD
CVE-2025-70238
Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/form
HIGH 7.5 2026-03-09
dlink dir-513_firmware
NVD
CVE-2025-70059
An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.
HIGH 7.5 2026-03-09
ymfe yapi
NVD
CVE-2025-69648
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafte
MEDIUM 6.2 2026-03-09
gnu binutils
NVD
CVE-2025-69647
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafte
MEDIUM 6.2 2026-03-09
gnu binutils
NVD
CVE-2026-3089
Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. I
UNKNOWN N/A 2026-03-09
未知
NVD