浏览 37+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-24911 | Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Reference | Hitachi Vantara | Pentaho Business Analytics Server | Medium | 4.9 | 2025-04-16 22:35:11 | Deep Dive |
| CVE-2025-24910 | Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Reference | Hitachi Vantara | Pentaho Business Analytics Server | Medium | 4.9 | 2025-04-16 22:32:46 | Deep Dive |
| CVE-2025-24909 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Hitachi Vantara | Pentaho Business Analytics Server | Medium | 4.4 | 2025-04-16 22:30:10 | Deep Dive |
| CVE-2025-0757 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Hitachi Vantara | Pentaho Business Analytics Server | Medium | 4.4 | 2025-04-16 22:18:19 | Deep Dive |
| CVE-2025-0758 | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource | Hitachi Vantara | Pentaho Business Analytics Server | Medium | 6.1 | 2025-04-16 22:12:30 | Deep Dive |
| CVE-2024-37363 | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization | Hitachi Vantara | Pentaho Data Integration & Analytics | Medium | 6.5 | 2025-02-19 23:40:10 | Deep Dive |
| CVE-2024-37362 | Hitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected Credentials | Hitachi Vantara | Pentaho Data Integration & Analytics | Medium | 6.3 | 2025-02-19 23:34:30 | Deep Dive |
| CVE-2024-6697 | Hitachi Vantara Pentaho Business Analytics Server - Improper Handling of Insufficient Permissions or Privileges | Hitachi Vantara | Pentaho Data Integration & Analytics | Medium | 6.5 | 2025-02-19 23:32:19 | Deep Dive |
| CVE-2024-6696 | Hitachi Vantara Pentaho Business Analytics Server - Insufficient Granularity of Access Control | Hitachi Vantara | Pentaho Data Integration & Analytics | Medium | 4.9 | 2025-02-19 23:29:43 | Deep Dive |
| CVE-2024-37361 | Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data | Hitachi Vantara | Pentaho Data Integration & Analytics | Critical | 9.9 | 2025-02-19 23:25:33 | Deep Dive |
| CVE-2024-37360 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Hitachi Vantara | Pentaho Data Integration & Analytics | Medium | 4.4 | 2025-02-19 23:01:42 | Deep Dive |
| CVE-2024-37359 | Hitachi Vantara Pentaho Business Analytics Server – Server Side Request Forgery | Hitachi Vantara | Pentaho Data Integration & Analytics | High | 8.6 | 2025-02-19 22:58:58 | Deep Dive |
| CVE-2024-5705 | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization | Hitachi Vantara | Pentaho Data Integration & Analytics | High | 8.8 | 2025-02-19 22:55:09 | Deep Dive |
| CVE-2024-5706 | Hitachi Vantara Pentaho Data Integration & Analytics - Improper Control of Resource Identifiers ('Resource Injection') | Hitachi Vantara | Pentaho Data Integration & Analytics | High | 8.8 | 2025-02-19 22:49:47 | Deep Dive |
| CVE-2024-28984 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Hitachi Vantara | Pentaho Business Analytics Server | High | 8.8 | 2024-06-26 22:41:57 | Deep Dive |
| CVE-2024-28983 | Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Hitachi Vantara | Pentaho Business Analytics Server | High | 8.8 | 2024-06-26 22:40:16 | Deep Dive |
| CVE-2024-28982 | Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Reference | Hitachi Vantara | Pentaho Business Analytics Server | High | 7.1 | 2024-06-26 22:37:01 | Deep Dive |
| CVE-2023-2358 | Hitachi Vantara Pentaho Business Analytics Server – Password Stored in a Recoverable Format | Hitachi Vantara | Pentaho Business Analytics Server | Medium | 4.3 | 2023-09-26 21:34:07 | Deep Dive |
| CVE-2022-4815 | Hitachi Vantara Pentaho Business Analytics Server - Deserialization of Untrusted Data | Hitachi Vantara | Pentaho Business Analytics Server | High | 8.0 | 2023-05-24 21:30:37 | Deep Dive |
| CVE-2023-1158 | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Authorization | Hitachi Vantara | Pentaho Business Analytics Server | Medium | 4.3 | 2023-05-24 21:26:53 | Deep Dive |