| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-8110 KEV 📌 💣 | File overwrite in file update API in Gogs EPSS 0.83 | Gogs | Gogs | - | - | 2025-12-10 13:23:47 | Deep Dive |
| CVE-2025-34291 KEV 📌 💣 | Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE EPSS 0.84 | Langflow | Langflow | 中危 | - | 2025-12-05 22:27:26 | Deep Dive |
| CVE-2025-66516 📌 💣 | Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected EPSS 0.79 | Apache Software Foundation | Apache Tika core | High | 8.4 | 2025-12-04 16:17:25 | Deep Dive |
| CVE-2025-55182 KEV 📌 💣 | Meta React Server Components 安全漏洞 EPSS 1.00 | Meta | react-server-dom-webpack | Critical | 10.0 | 2025-12-03 15:40:57 | Deep Dive |
| CVE-2025-13486 📌 💣 | Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form EPSS 0.74 | hwk-fr | Advanced Custom Fields: Extended | Critical | 9.8 | 2025-12-03 06:47:47 | Deep Dive |
| CVE-2025-6389 📌 💣 | Sneeit Framework <= 8.3 - Unauthenticated Remote Code Execution in sneeit_articles_pagination_callback EPSS 0.73 | Sneeit | Sneeit Framework | Critical | 9.8 | 2025-11-25 02:26:50 | Deep Dive |
| CVE-2025-64446 KEV 📌 💣 | Fortinet FortiWeb 安全漏洞 EPSS 0.92 | Fortinet | FortiWeb | Critical | 9.8 | 2025-11-14 15:50:53 | Deep Dive |
| CVE-2025-12480 KEV 🧪 💣 | TrioFox 安全漏洞 EPSS 0.91 | TrioFox | TrioFox | Critical | 9.1 | 2025-11-10 14:20:41 | Deep Dive |
| CVE-2025-34299 📌 💣 | Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload EPSS 0.73 | Monsta Limited of New Zealand | Monsta FTP | 超危 | - | 2025-11-07 13:51:34 | Deep Dive |
| CVE-2025-64328 KEV 📌 💣 | FreePBX Administration GUI is Vulnerable to Authenticated Command Injection EPSS 0.85 | FreePBX | filestore | 中危 | - | 2025-11-07 03:32:21 | Deep Dive |
| CVE-2025-11749 📌 💣 | AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation EPSS 0.75 | tigroumeow | AI Engine – The Chatbot, AI Framework & MCP for WordPress | Critical | 9.8 | 2025-11-05 05:31:25 | Deep Dive |
| CVE-2025-11953 KEV 🧪 💣 | Command injection in React Native Community CLI allows remote attackers to perform remote code execution by sending HTTP requests EPSS 0.94 | - | - | Critical | 9.8 | 2025-11-03 16:35:07 | Deep Dive |
| CVE-2025-61757 KEV 📌 💣 | Oracle Fusion Middleware 安全漏洞 EPSS 0.88 | Oracle Corporation | Identity Manager | Critical | 9.8 | 2025-10-21 20:03:11 | Deep Dive |
| CVE-2025-59287 KEV 📌 💣 | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability EPSS 1.00 | Microsoft | Windows Server 2012 | Critical | 9.8 | 2025-10-14 17:01:48 | Deep Dive |
| CVE-2025-61884 KEV 📌 💣 | Oracle E-Business Suite 安全漏洞 EPSS 0.98 | Oracle Corporation | Oracle Configurator | High | 7.5 | 2025-10-12 02:34:52 | Deep Dive |
| CVE-2025-11371 KEV 📌 💣 | Gladinet CentreStack and TrioFox Local File Inclusion Flaw EPSS 0.92 | Gladinet | CentreStack and TrioFox | - | - | 2025-10-09 16:50:49 | Deep Dive |
| CVE-2025-61882 KEV 📌 💣 | Oracle E-Business Suite 安全漏洞 EPSS 1.00 | Oracle Corporation | Oracle Concurrent Processing | Critical | 9.8 | 2025-10-05 03:17:02 | Deep Dive |
| CVE-2025-49844 🧪 | Redis Lua Use-After-Free may lead to remote code execution EPSS 0.87 | redis | redis | Critical | 9.9 | 2025-10-03 19:27:24 | Deep Dive |
| CVE-2025-20362 KEV 📌 💣 | Cisco Secure Firewall Adaptive Security Appliance和Cisco Secure Firewall Threat Defense 安全漏洞 EPSS 0.87 | Cisco | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Medium | 6.5 | 2025-09-25 16:12:36 | Deep Dive |
| CVE-2025-26399 KEV 📌 💣 | SolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability EPSS 0.88 | SolarWinds | Web Help Desk | Critical | 9.8 | 2025-09-23 05:07:15 | Deep Dive |