| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-59528 🧪 💣 | Flowise has Remote Code Execution vulnerability EPSS 0.87 | FlowiseAI | Flowise | Critical | 10.0 | 2025-09-22 19:54:58 | Deep Dive |
| CVE-2025-48703 KEV 📌 💣 | Control Web Panel 操作系统命令注入漏洞 EPSS 1.00 | centos-webpanel | CentOS Web Panel | Critical | 9.0 | 2025-09-19 00:00:00 | Deep Dive |
| CVE-2025-10035 KEV 📌 💣 | Deserialization Vulnerability in GoAnywhere MFT's License Servlet EPSS 1.00 | Fortra | GoAnywhere MFT | Critical | 10.0 | 2025-09-18 22:01:51 | Deep Dive |
| CVE-2025-9242 KEV 📌 | WatchGuard Firebox iked Out of Bounds Write Vulnerability EPSS 0.91 | WatchGuard | Fireware OS | Critical | 9.3 | 2025-09-17 07:29:24 | Deep Dive |
| CVE-2025-54236 KEV 📌 💣 | Adobe Commerce | Improper Input Validation (CWE-20) EPSS 0.95 | Adobe | Adobe Commerce | Critical | 9.1 | 2025-09-09 13:20:18 | Deep Dive |
| CVE-2025-57819 KEV 📌 💣 | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE EPSS 0.88 | FreePBX | endpoint | - | - | 2025-08-28 16:45:19 | Deep Dive |
| CVE-2025-8943 📌 💣 | Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers EPSS 0.72 | - | - | Critical | 9.8 | 2025-08-14 09:54:23 | Deep Dive |
| CVE-2024-32640 🧪 💣 | MasaCMS SQL Injection vulnerability EPSS 0.70 | MasaCMS | MasaCMS | Critical | 9.8 | 2025-08-11 20:38:56 | Deep Dive |
| CVE-2025-8088 KEV 📌 | Path traversal vulnerability in WinRAR EPSS 0.95 | win.rar GmbH | WinRAR | High | 8.4 | 2025-08-08 11:11:42 | Deep Dive |
| CVE-2025-54253 KEV 📌 | Adobe Experience Manager | Incorrect Authorization (CWE-863) EPSS 0.88 | Adobe | Adobe Experience Manager | Critical | 10.0 | 2025-08-05 16:53:41 | Deep Dive |
| CVE-2025-54254 | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611) EPSS 0.77 | Adobe | Adobe Experience Manager | High | 8.6 | 2025-08-05 16:53:40 | Deep Dive |
| CVE-2025-6205 KEV 📌 💣 | Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 EPSS 0.71 | Dassault Systèmes | DELMIA Apriso | Critical | 9.1 | 2025-08-04 09:14:42 | Deep Dive |
| CVE-2025-6204 KEV 📌 💣 | Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 EPSS 0.76 | Dassault Systèmes | DELMIA Apriso | High | 8.0 | 2025-08-04 09:14:08 | Deep Dive |
| CVE-2025-32429 📌 💣 | XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter EPSS 0.85 | xwiki | xwiki-platform | 中危 | - | 2025-07-24 22:22:35 | Deep Dive |
| CVE-2025-53771 📌 💣 | Microsoft SharePoint Server Spoofing Vulnerability EPSS 1.00 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | Medium | 6.5 | 2025-07-20 22:16:52 | Deep Dive |
| CVE-2025-53770 KEV 📌 💣 | Microsoft SharePoint Server Remote Code Execution Vulnerability EPSS 1.00 | Microsoft | Microsoft SharePoint Enterprise Server 2016 | Critical | 9.8 | 2025-07-20 01:06:34 | Deep Dive |
| CVE-2025-54309 KEV 📌 | CrushFTP 安全漏洞 EPSS 0.94 | CrushFTP | CrushFTP | Critical | 9.0 | 2025-07-18 00:00:00 | Deep Dive |
| CVE-2025-54068 KEV 📌 💣 | Livewire vulnerable to remote command execution during property update hydration EPSS 0.96 | livewire | livewire | - | - | 2025-07-17 18:16:56 | Deep Dive |
| CVE-2025-25257 KEV 📌 💣 | Fortinet FortiWeb SQL注入漏洞 EPSS 1.00 | Fortinet | FortiWeb | Critical | 9.8 | 2025-07-17 15:10:05 | Deep Dive |
| CVE-2025-6965 📌 💣 | Integer Truncation on SQLite EPSS 0.76 | SQLite | SQLite | 高危 | - | 2025-07-15 13:44:01 | Deep Dive |