浏览 22+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-6535 | xxyopen/201206030 novel-plus User Management Module UserMapper.xml list sql injection | xxyopen | novel-plus | Medium | 6.3 | 2025-06-24 01:00:21 | Deep Dive |
| CVE-2025-6534 | xxyopen/201206030 novel-plus File FileController.java remove resource injection | xxyopen | novel-plus | Medium | 4.2 | 2025-06-24 00:31:05 | Deep Dive |
| CVE-2025-6533 | xxyopen/201206030 novel-plus CATCHA LoginController.java ajaxLogin authentication replay | xxyopen | novel-plus | Medium | 5.6 | 2025-06-24 00:00:13 | Deep Dive |
| CVE-2025-4019 | 20120630 Novel-Plus GeneratorController.java genCode missing authentication | 20120630 | Novel-Plus | High | 7.3 | 2025-04-28 12:00:08 | Deep Dive |
| CVE-2025-4018 | 20120630 Novel-Plus CrawlController.java addCrawlSource missing authentication | 20120630 | Novel-Plus | Medium | 5.3 | 2025-04-28 11:31:06 | Deep Dive |
| CVE-2025-4017 | 20120630 Novel-Plus LogController.java list improper authorization | 20120630 | Novel-Plus | Medium | 4.3 | 2025-04-28 11:00:08 | Deep Dive |
| CVE-2025-4016 | 20120630 Novel-Plus LogController.java deleteIndex improper authorization | 20120630 | Novel-Plus | Medium | 5.4 | 2025-04-28 10:31:06 | Deep Dive |
| CVE-2025-4015 | 20120630 Novel-Plus SessionController.java list missing authentication | 20120630 | Novel-Plus | Medium | 5.3 | 2025-04-28 10:00:09 | Deep Dive |
| CVE-2025-3856 | xxyopen Novel-Plus searchByPage sql injection | xxyopen | Novel-Plus | Medium | 6.3 | 2025-04-22 01:00:12 | Deep Dive |
| CVE-2025-3676 | xxyopen Novel-Plus books sql injection | xxyopen | Novel-Plus | Medium | 6.3 | 2025-04-16 08:00:06 | Deep Dive |
| CVE-2025-3369 | xxyopen Novel-Plus list sql injection | xxyopen | Novel-Plus | Medium | 6.3 | 2025-04-07 13:31:05 | Deep Dive |
| CVE-2024-0941 | Novel-Plus list sql injection | - | Novel-Plus | Medium | 5.5 | 2024-01-26 18:31:05 | Deep Dive |
| CVE-2024-0655 | Novel-Plus list sql injection | - | Novel-Plus | Medium | 5.5 | 2024-01-18 01:31:04 | Deep Dive |
| CVE-2023-7171 | Novel-Plus Friendly Link FriendLinkController.java cross site scripting | - | Novel-Plus | Low | 2.4 | 2023-12-29 17:31:03 | Deep Dive |
| CVE-2023-7166 | Novel-Plus HTTP POST Request updateUserInfo cross site scripting | - | Novel-Plus | Low | 3.5 | 2023-12-29 08:31:05 | Deep Dive |
| CVE-2023-2041 | novel-plus sql injection | - | novel-plus | Medium | 6.3 | 2023-04-14 09:00:07 | Deep Dive |
| CVE-2023-2040 | novel-plus sql injection | - | novel-plus | Medium | 6.3 | 2023-04-14 08:31:03 | Deep Dive |
| CVE-2023-2039 | novel-plus sql injection | - | novel-plus | Medium | 6.3 | 2023-04-14 08:00:05 | Deep Dive |
| CVE-2023-1607 | novel-plus list sql injection | - | novel-plus | Medium | 4.7 | 2023-03-23 19:31:03 | Deep Dive |
| CVE-2023-1606 | novel-plus DictController.java sql injection | - | novel-plus | Medium | 6.3 | 2023-03-23 19:00:06 | Deep Dive |