| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-4428 KEV 📌 💣 | Remote Code Execution EPSS 0.86 | Ivanti | Endpoint Manager Mobile | High | 7.2 | 2025-05-13 15:46:55 | Deep Dive |
| CVE-2025-4427 KEV 📌 💣 | Authentication Bypass EPSS 1.00 | Ivanti | Endpoint Manager Mobile | Medium | 5.3 | 2025-05-13 15:45:35 | Deep Dive |
| CVE-2025-2777 📌 💣 | SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection EPSS 0.72 | SysAid | SysAid On-Prem | Critical | 9.3 | 2025-05-07 14:53:01 | Deep Dive |
| CVE-2025-32432 KEV 🧪 💣 | Craft CMS Allows Remote Code Execution EPSS 1.00 | craftcms | cms | Critical | 10.0 | 2025-04-25 15:04:06 | Deep Dive |
| CVE-2025-31324 KEV 📌 💣 | Missing Authorization check in SAP NetWeaver (Visual Composer development server) EPSS 1.00 | SAP_SE | SAP NetWeaver (Visual Composer development server) | Critical | 10.0 | 2025-04-24 16:50:28 | Deep Dive |
| CVE-2025-32969 📌 💣 | org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API EPSS 0.78 | xwiki | xwiki-platform | 超危 | - | 2025-04-23 15:33:04 | Deep Dive |
| CVE-2025-34028 KEV 📌 💣 | Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal EPSS 0.98 | Commvault | Command Center Innovation Release | 超危 | - | 2025-04-22 16:32:23 | Deep Dive |
| CVE-2025-32433 KEV 📌 💣 | Erlang/OTP SSH Vulnerable to Pre-Authentication RCE EPSS 0.99 | erlang | otp | Critical | 10.0 | 2025-04-16 21:34:37 | Deep Dive |
| CVE-2025-3102 📌 💣 | SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation EPSS 0.76 | brainstormforce | OttoKit: All-in-One Automation Platform | High | 8.1 | 2025-04-10 04:22:06 | Deep Dive |
| CVE-2024-58136 KEV 🧪 💣 | Yii 安全漏洞 EPSS 0.85 | yiiframework | Yii | Critical | 9.0 | 2025-04-10 00:00:00 | Deep Dive |
| CVE-2025-3248 KEV 🧪 💣 | Langflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code EPSS 1.00 | langflow-ai | langflow | Critical | 9.8 | 2025-04-07 14:22:39 | Deep Dive |
| CVE-2025-22457 KEV 📌 💣 | Ivanti Connect Secure 安全漏洞 EPSS 1.00 | Ivanti | Connect Secure | Critical | 9.0 | 2025-04-03 15:20:24 | Deep Dive |
| CVE-2025-30406 KEV 📌 💣 | Gladinet CentreStack 安全漏洞 EPSS 0.94 | Gladinet | CentreStack | Critical | 9.0 | 2025-04-03 00:00:00 | Deep Dive |
| CVE-2025-31161 KEV 📌 💣 | CrushFTP 安全漏洞 EPSS 1.00 | CrushFTP | CrushFTP | Critical | 9.8 | 2025-04-03 00:00:00 | Deep Dive |
| CVE-2024-56325 📌 💣 | Apache Pinot: Authentication bypass issue. If the path does not contain / and contain . authentication is not required EPSS 0.79 | Apache Software Foundation | Apache Pinot | - | - | 2025-04-01 09:07:14 | Deep Dive |
| CVE-2025-2294 📌 💣 | Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion EPSS 0.78 | extendthemes | Kubio AI Page Builder | Critical | 9.8 | 2025-03-28 04:22:42 | Deep Dive |
| CVE-2025-29635 KEV 📌 💣 | D-Link DIR-823X 命令注入漏洞 EPSS 0.88 | - | - | 高危 | - | 2025-03-25 00:00:00 | Deep Dive |
| CVE-2025-1098 📌 💣 | ingress-nginx controller - configuration injection via unsanitized mirror annotations EPSS 0.83 | kubernetes | ingress-nginx | High | 8.8 | 2025-03-24 23:29:16 | Deep Dive |
| CVE-2025-1974 📌 💣 | ingress-nginx admission controller RCE escalation EPSS 1.00 | kubernetes | ingress-nginx | Critical | 9.8 | 2025-03-24 23:28:49 | Deep Dive |
| CVE-2025-2747 KEV 🧪 💣 | Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass EPSS 0.92 | Kentico | Xperience | Critical | 9.8 | 2025-03-24 18:17:06 | Deep Dive |