VulnScope — 以套件為主體的 CVE 查詢工具- CRITICAL9.8CVE-2025-24893⚠ KEVEPSS 93.7%XWiki Platform allows remote code execution as guest via SolrSearchMacros request
- CRITICAL9.8⚠ KEVEPSS 93.9%Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
- MEDIUM6.3⚠ KEVEPSS 0.94%Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability
- MEDIUM5.5⚠ KEVEPSS 2.6%Linux Kernel Use of Uninitialized Resource Vulnerability
- CRITICAL9.8⚠ KEVEPSS 30.8%firefox-esr - security update
- CRITICAL9.6⚠ KEVEPSS 1.0%Google Chromium V8 Type Confusion Vulnerability
- CRITICAL9.3⚠ KEVEPSS 90.5%RoundCube Webmail Cross-Site Scripting Vulnerability
- CRITICAL9.8⚠ KEVEPSS 94.4%Remote Code Execution (RCE) vulnerability in geoserver
- CRITICAL9.1⚠ KEVEPSS 93.9%Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
- CRITICAL9.8⚠ KEVEPSS 94.2%Magento Open Source affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability
- MEDIUM6.1⚠ KEVEPSS 64.5%roundcube - security update
- CRITICAL9.6⚠ KEVEPSS 6.6%chromium - security update
- CRITICAL9.6⚠ KEVEPSS 1.1%chromium - security update
- CRITICAL9.6⚠ KEVEPSS 0.57%chromium - security update
- CRITICAL9.8⚠ KEVEPSS 94.3%Apache HugeGraph-Server: Command execution in gremlin
- CRITICAL9.8⚠ KEVEPSS 80.0%GitLab Server-Side Request Forgery (SSRF) Vulnerability
- CRITICAL10.0⚠ KEVEPSS 94.5%GitLab Community and Enterprise Editions Remote Code Execution Vulnerability
- CRITICAL9.8⚠ KEVEPSS 93.4%Weak Password Recovery Mechanism for Forgotten Password in GitLab
- CRITICAL9.8⚠ KEVEPSS 94.4%Remote Code Execution Vulnerability in Packaging
- CRITICAL9.8⚠ KEVEPSS 94.4%apisix/batch-requests plugin allows overwriting the X-REAL-IP header
- CRITICAL9.8⚠ KEVEPSS 94.5%Arbitrary file read vulnerability through the Jenkins CLI can lead to RCE
- MEDIUM6.5⚠ KEVEPSS 0.05%webkit2gtk - security update
- CRITICAL9.6⚠ KEVEPSS 1.9%chromium - security update
- CRITICAL10.0⚠ KEVEPSS 94.4%Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
- MEDIUM5.4⚠ KEVEPSS 83.2%roundcube - security update