浏览 25+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-25414 | WordPress WPBookit Pro plugin <= 1.6.18 - Privilege Escalation vulnerability | iqonicdesign | WPBookit Pro | High | 8.8 | 2026-03-25 16:14:49 | Deep Dive |
| CVE-2026-25413 | WordPress WPBookit Pro plugin <= 1.6.18 - Arbitrary File Upload vulnerability | iqonicdesign | WPBookit Pro | Critical | 9.9 | 2026-03-25 16:14:49 | Deep Dive |
| CVE-2026-2992 | KiviCare <= 4.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | High | 8.2 | 2026-03-18 15:28:30 | Deep Dive |
| CVE-2026-2991 | KiviCare – Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | High | 7.3 | 2026-03-18 15:28:30 | Deep Dive |
| CVE-2026-1980 | WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure | iqonicdesign | WPBookit | Medium | 5.3 | 2026-03-04 01:21:59 | Deep Dive |
| CVE-2026-1945 | WPBookit <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting via 'wpb_user_name' and 'wpb_user_email' Parameters | iqonicdesign | WPBookit | High | 7.2 | 2026-03-04 01:21:58 | Deep Dive |
| CVE-2026-25415 | WordPress WPBookit Pro plugin <= 1.6.18 - Broken Access Control vulnerability | iqonicdesign | WPBookit Pro | - | - | 2026-02-19 08:27:06 | Deep Dive |
| CVE-2026-0927 | KiviCare – Clinic & Patient Management System (EHR) <= 3.6.15 - Missing Authorization to Unauthenticated Limited Arbitrary File Upload | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | Medium | 5.3 | 2026-01-23 05:29:50 | Deep Dive |
| CVE-2025-12135 | WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting | iqonicdesign | WPBookit | High | 7.2 | 2025-11-21 07:31:52 | Deep Dive |
| CVE-2025-11820 | Graphina – Elementor Charts and Graphs <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Chart Widgets | iqonicdesign | Graphina – Charts and Graphs For Elementor | Medium | 6.4 | 2025-11-05 09:27:39 | Deep Dive |
| CVE-2025-8867 | Graphina - Elementor Charts and Graphs <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | iqonicdesign | Graphina – Charts and Graphs For Elementor | Medium | 6.4 | 2025-08-15 02:24:24 | Deep Dive |
| CVE-2025-7852 | WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function | iqonicdesign | WPBookit | Critical | 9.8 | 2025-07-24 04:24:13 | Deep Dive |
| CVE-2025-6057 | WPBookit <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Upload | iqonicdesign | WPBookit | High | 8.8 | 2025-07-12 04:22:22 | Deep Dive |
| CVE-2025-6058 | WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload | iqonicdesign | WPBookit | Critical | 9.8 | 2025-07-12 04:22:21 | Deep Dive |
| CVE-2025-3811 | WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update | iqonicdesign | WPBookit | Critical | 9.8 | 2025-05-09 01:42:35 | Deep Dive |
| CVE-2025-3810 | WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover | iqonicdesign | WPBookit | Critical | 9.8 | 2025-05-09 01:42:35 | Deep Dive |
| CVE-2025-2525 | Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Upload | iqonicdesign | Streamit | High | 8.8 | 2025-04-08 01:44:22 | Deep Dive |
| CVE-2025-2519 | Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Download | iqonicdesign | Streamit | Medium | 6.5 | 2025-04-08 01:44:22 | Deep Dive |
| CVE-2025-2526 | Streamit <= 4.0.2 - Authenticated (Subscriber+) Privilege Escalation via User Email Change/Account Takeover | iqonicdesign | Streamit | High | 8.8 | 2025-04-08 01:44:21 | Deep Dive |
| CVE-2025-1572 | KiviCare – Clinic & Patient Management System (EHR) <= 3.6.7 - Authenticated (Doctor+) SQL Injection via 'u_id' Parameter | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | Medium | 6.5 | 2025-02-28 07:34:39 | Deep Dive |