浏览 23+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-14606 | tiny-rdm Tiny RDM Pickle Decoding pickle_convert.go pickle.loads deserialization | tiny-rdm | Tiny RDM | Medium | 5.0 | 2025-12-13 12:32:06 | Deep Dive |
| CVE-2025-67520 | WordPress Media Library Tools plugin <= 1.6.15 - SQL Injection vulnerability | Tiny Solutions | Media Library Tools | High | 7.6 | 2025-12-09 14:13:59 | Deep Dive |
| CVE-2025-9991 | Tiny Bootstrap Elements Light <= 4.3.34 - Unauthenticated Local File Inclusion | migli | Tiny Bootstrap Elements Light | High | 8.1 | 2025-09-30 03:35:31 | Deep Dive |
| CVE-2025-58759 | TinyEnv: Inline comments not stripped properly in .env values | datahihi1 | tiny-env | Medium | 5.1 | 2025-09-09 19:52:39 | Deep Dive |
| CVE-2025-58758 | TinyEnv: Missing .env file not required — may cause unexpected behavior | datahihi1 | tiny-env | Medium | 5.1 | 2025-09-09 19:50:19 | Deep Dive |
| CVE-2025-55149 | Path Traversal Vulnerability in PDF Review Function (CWE-22) | ulab-uiuc | tiny-scientist | 中危 | - | 2025-08-09 02:02:31 | Deep Dive |
| CVE-2024-49364 | tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment | bitcoinjs | tiny-secp256k1 | - | - | 2025-07-01 02:07:07 | Deep Dive |
| CVE-2024-49365 | tiny-secp256k1 allows for verify() bypass when running in bundled environment | bitcoinjs | tiny-secp256k1 | - | - | 2025-07-01 02:07:03 | Deep Dive |
| CVE-2025-3051 | Linux::Statm::Tiny for Perl allows untrusted code to be included from the current working directory | RRWO | Linux::Statm::Tiny | 中危 | - | 2025-04-01 02:20:41 | Deep Dive |
| CVE-2025-30091 | Tiny MoxieManager 安全漏洞 | Tiny | MoxieManager PHP | - | - | 2025-03-25 00:00:00 | Deep Dive |
| CVE-2023-44229 | WordPress Tiny Carousel Horizontal Slider Plugin <= 8.1 is vulnerable to Cross Site Scripting (XSS) | Gopi Ramasamy | Tiny Carousel Horizontal Slider | Medium | 5.9 | 2023-10-16 10:29:03 | Deep Dive |
| CVE-2023-24418 | WordPress Tiny carousel horizontal slider plus Plugin <= 3.2 is vulnerable to Cross Site Scripting (XSS) | Gopi Ramasamy | Tiny carousel horizontal slider plus | Medium | 5.9 | 2023-05-10 07:43:08 | Deep Dive |
| CVE-2022-45476 | Tiny File Manager 代码问题漏洞 | - | Tiny File Manager | 超危 | - | 2022-11-25 00:00:00 | Deep Dive |
| CVE-2022-45475 | Tiny File Manager 安全漏洞 | - | Tiny File Manager | 中危 | - | 2022-11-25 00:00:00 | Deep Dive |
| CVE-2022-23044 | Tiny File Manager 跨站请求伪造漏洞 | - | Tiny File Manager | 高危 | - | 2022-11-25 00:00:00 | Deep Dive |
| CVE-2022-39287 | Plaintext transmission of CSRF tokens in tiny-csrf | valexandersaulys | tiny-csrf | High | 8.1 | 2022-10-07 00:00:00 | Deep Dive |
| CVE-2022-1846 | Tiny Contact Form <= 0.7 - Arbitrary Settings Update via CSRF | Unknown | Tiny Contact Form | 中危 | - | 2022-06-27 08:58:03 | Deep Dive |
| CVE-2021-27439 | TencentOS-tiny Integer Overflow or Wraparound | TencentOS-tiny | TencentOS-tiny | High | 7.3 | 2022-05-03 20:26:05 | Deep Dive |
| CVE-2020-7724 | Prototype Pollution | - | tiny-conf | Critical | 9.8 | 2020-09-01 09:45:13 | Deep Dive |
| CVE-2011-4906 | Joomla! TinyMCE 代码问题漏洞 | Joomla! | Tiny browser included with TinyMCE 3.0 | 超危 | - | 2020-02-12 20:59:29 | Deep Dive |