D01EXPLOIT OFFICIAL
10 записей с упоминанием · 8 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
21Наблюдать | CVE-2025-15691Эксплойта нет | WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Formsunknown · wpfunnels · CWE-863 | Средняя5,3 | — | 0,2 % | 4 сент. 2026 г. |
34Наблюдать | CVE-2025-15662Эксплойта нет | Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgeryunknown · printcart web to print product designer for woocommerce · CWE-918 | Высокая8,6 | — | 0,4 % | 27 июл. 2026 г. |
21Наблюдать | CVE-2025-10268Эксплойта нет | Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenticated Folder Content Disclosure via Path Traversalunknown · printcart web to print product designer for woocommerce · CWE-22 | Средняя5,3 | — | 0,4 % | 26 июн. 2026 г. |
17Наблюдать | CVE-2025-13408Эксплойта нет | Foxtool All-in-One: Contact chat button, Custom login, Media optimize images <= 2.5.2 - Cross-Site Request Forgery to Google OAuth Connectionfoxtheme · foxtool all-in-one: contact chat button, custom login, media optimize images · CWE-352 | Средняя4,3 | — | 0,2 % | 12 дек. 2025 г. |
39Наблюдать | CVE-2025-12158Эксплойта нет | Simple User Capabilities <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalationtanvirahmed1984 · simple user capabilities · CWE-862 | Критическая9,8 | — | 0,5 % | 4 нояб. 2025 г. |
21Наблюдать | CVE-2025-12157Эксплойта нет | Simple User Capabilities <= 1.0 - Missing Authorization to Unauthenticated Capability Resettanvirahmed1984 · simple user capabilities · CWE-862 | Средняя5,3 | — | 0,3 % | 4 нояб. 2025 г. |
21Наблюдать | CVE-2025-11881Эксплойта нет | AppPresser – Mobile App Framework <= 4.5.0 - Missing Authorization to Unauthenticated Limited Sensitive Information Exposurescottopolis · apppresser – mobile app framework · CWE-862 | Средняя5,3 | — | 0,3 % | 30 окт. 2025 г. |
21Наблюдать | CVE-2025-10486Эксплойта нет | Content Writer <= 3.6.8 - Unauthenticated Information Exposure via Log Filesteadycontent · content writer · CWE-532 | Средняя5,3 | — | 0,3 % | 15 окт. 2025 г. |
21Наблюдать | CVE-2025-10212Эксплойта нет | SiteAlert (Formerly WP Health) <= 1.9.8 - Missing Authorization to Unauthenticated Site Health Information Exposuresitealert · sitealert (formerly wp health) · CWE-862 | Средняя5,3 | — | 0,4 % | 3 окт. 2025 г. |
16Наблюдать | CVE-2025-10735Эксплойта нет | Block For Mailchimp – Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side Request Forgerybplugins · block for mailchimp – add email subscription forms and collect leads · CWE-918 | Средняя4,0 | — | 0,3 % | 1 окт. 2025 г. |
- CVE-2025-1569121Наблюдать
WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms
СредняяCVSS 5,3Эксплойта нетEPSS 0 %unknown · wpfunnels4 сент. 2026 г.
- CVE-2025-1566234Наблюдать
Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %unknown · printcart web to print product designer for woocommerce27 июл. 2026 г.
- CVE-2025-1026821Наблюдать
Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenticated Folder Content Disclosure via Path Traversal
СредняяCVSS 5,3Эксплойта нетEPSS 0 %unknown · printcart web to print product designer for woocommerce26 июн. 2026 г.
- CVE-2025-1340817Наблюдать
Foxtool All-in-One: Contact chat button, Custom login, Media optimize images <= 2.5.2 - Cross-Site Request Forgery to Google OAuth Connection
СредняяCVSS 4,3Эксплойта нетEPSS 0 %foxtheme · foxtool all-in-one: contact chat button, custom login, media optimize images12 дек. 2025 г.
- CVE-2025-1215839Наблюдать
Simple User Capabilities <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %tanvirahmed1984 · simple user capabilities4 нояб. 2025 г.
- CVE-2025-1215721Наблюдать
Simple User Capabilities <= 1.0 - Missing Authorization to Unauthenticated Capability Reset
СредняяCVSS 5,3Эксплойта нетEPSS 0 %tanvirahmed1984 · simple user capabilities4 нояб. 2025 г.
- CVE-2025-1188121Наблюдать
AppPresser – Mobile App Framework <= 4.5.0 - Missing Authorization to Unauthenticated Limited Sensitive Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 0 %scottopolis · apppresser – mobile app framework30 окт. 2025 г.
- CVE-2025-1048621Наблюдать
Content Writer <= 3.6.8 - Unauthenticated Information Exposure via Log File
СредняяCVSS 5,3Эксплойта нетEPSS 0 %steadycontent · content writer15 окт. 2025 г.
- CVE-2025-1021221Наблюдать
SiteAlert (Formerly WP Health) <= 1.9.8 - Missing Authorization to Unauthenticated Site Health Information Exposure
СредняяCVSS 5,3Эксплойта нетEPSS 0 %sitealert · sitealert (formerly wp health)3 окт. 2025 г.
- CVE-2025-1073516Наблюдать
Block For Mailchimp – Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side Request Forgery
СредняяCVSS 4,0Эксплойта нетEPSS 0 %bplugins · block for mailchimp – add email subscription forms and collect leads1 окт. 2025 г.