| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-50891 | Owlfiles File Manager 12.0.1 Cross-Site Scripting via HTTP Server | Skyjos | Owlfiles File Manager | Medium | 5.0 | 2026-01-13 22:51:42 | Deep Dive |
| CVE-2025-11669 | Broken Access Control | Zohocorp | ManageEngine PAM360 | High | 8.1 | 2026-01-13 14:10:56 | Deep Dive |
| CVE-2026-0500 | Remote code execution in SAP Wily Introscope Enterprise Manager (WorkStation) | SAP_SE | SAP Wily Introscope Enterprise Manager (WorkStation) | Critical | 9.6 | 2026-01-13 01:13:58 | Deep Dive |
| CVE-2026-22777 | ComfyUI-Manager is Vulnerable to CRLF Injection in Configuration Handler | Comfy-Org | ComfyUI-Manager | High | 7.5 | 2026-01-10 06:43:22 | Deep Dive |
| CVE-2025-14657 | Eventin – Event Manager, Event Booking, Calendar, Tickets and Registration Plugin (AI Powered) <= 4.0.51 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via 'post_settings' | arraytics | Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) | High | 7.2 | 2026-01-09 07:22:13 | Deep Dive |
| CVE-2026-0747 | Devolutions Remote Desktop Manager 安全漏洞 | Devolutions | Remote Desktop Manager | 中危 | - | 2026-01-08 19:55:59 | Deep Dive |
| CVE-2025-12640 | Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 - Missing Authorization to Authenticated (Author+) Media Replacement | premio | Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager | Medium | 4.3 | 2026-01-08 02:21:17 | Deep Dive |
| CVE-2026-21856 | Tarkov Data Manager has Authenticated SQL Injection | the-hideout | tarkov-data-manager | High | 7.2 | 2026-01-07 18:18:23 | Deep Dive |
| CVE-2026-21855 | Tarkov Data Manager has Unauthenticated Reflected XSS | the-hideout | tarkov-data-manager | Critical | 9.3 | 2026-01-07 18:16:03 | Deep Dive |
| CVE-2026-21854 | Tarkov Data Manager Authentication Bypass vulnerability | the-hideout | tarkov-data-manager | Critical | 9.8 | 2026-01-07 18:14:59 | Deep Dive |
| CVE-2025-13667 | WP Recipe Manager <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Skill Level' Input Field | tomiup | WP Recipe Manager | Medium | 6.4 | 2026-01-07 09:20:52 | Deep Dive |
| CVE-2025-13369 | Premmerce WooCommerce Customers Manager <= 1.1.14 - Reflected Cross-Site Scripting | premmerce | Premmerce WooCommerce Customers Manager | Medium | 6.1 | 2026-01-07 07:17:34 | Deep Dive |
| CVE-2025-14804 | Frontend File Manager < 23.5 - Subscriber+ Arbitrary File Deletion | Unknown | Frontend File Manager Plugin | 中危 | - | 2026-01-07 06:00:10 | Deep Dive |
| CVE-2024-31088 | WordPress AdsPlace'r – Ad Manager, Inserter, AdSense Ads plugin <= 1.1.5 - Cross Site Scripting (XSS) vulnerability | WPShop.ru | AdsPlace'r – Ad Manager, Inserter, AdSense Ads | Medium | 6.5 | 2026-01-06 16:52:54 | Deep Dive |
| CVE-2025-69327 | WordPress Car Rental Manager plugin <= 1.0.9 - Broken Access Control vulnerability | magepeopleteam | Car Rental Manager | Medium | 4.3 | 2026-01-06 16:36:38 | Deep Dive |
| CVE-2025-14371 | TaxoPress <= 3.41.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Tag Modification | stevejburge | Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI | Medium | 4.3 | 2026-01-06 07:22:12 | Deep Dive |
| CVE-2025-13409 | Form Vibes – Database Manager for Forms <= 1.4.13 - Authenticated (Admin+) SQL Injection | wpvibes | Form Vibes – Database Manager for Forms | Medium | 4.9 | 2026-01-06 03:21:38 | Deep Dive |
| CVE-2025-15364 | Download Manager <= 3.3.40 - Unauthenticated Limited Privilege Escalation via updatePassword | codename065 | Download Manager | High | 7.3 | 2026-01-06 01:50:13 | Deep Dive |
| CVE-2024-53735 | WordPress iPhone Webclip Manager plugin <= 0.5 - CSRF to Stored XSS vulnerability | corourke | iPhone Webclip Manager | High | 7.1 | 2026-01-05 16:41:09 | Deep Dive |
| CVE-2023-52212 | WordPress WP Job Manager plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) vulnerability | Automattic | WP Job Manager | Medium | 5.4 | 2026-01-05 13:32:31 | Deep Dive |