| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-13498 | Download Manager <= 3.3.32 - Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure | codename065 | Download Manager | Medium | 4.3 | 2025-12-18 07:20:46 | Deep Dive |
| CVE-2025-12976 | Events Manager <= 7.2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode | netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | Medium | 6.4 | 2025-12-18 07:20:46 | Deep Dive |
| CVE-2025-20393 | Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability | Cisco | Cisco Secure Email | Critical | 10.0 | 2025-12-17 16:47:13 | Deep Dive |
| CVE-2025-12496 | Zephyr Project Manager <= 3.3.203 - Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery | dylanjkotze | Zephyr Project Manager | Medium | 4.9 | 2025-12-17 07:21:01 | Deep Dive |
| CVE-2025-13532 | Weak Password Hash in Core Privileged Access Manager (BoKS) | Fortra | Core Privileged Access Manager (BoKS) | Medium | 6.2 | 2025-12-16 20:01:03 | Deep Dive |
| CVE-2025-68070 | WordPress VK Google Job Posting Manager plugin <= 1.2.22 - Cross Site Scripting (XSS) vulnerability | Vektor,Inc. | VK Google Job Posting Manager | Medium | 6.5 | 2025-12-16 08:13:04 | Deep Dive |
| CVE-2025-54004 | WordPress WCFM – Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control vulnerability | WC Lovers | WCFM – Frontend Manager for WooCommerce | Low | 2.7 | 2025-12-16 08:12:46 | Deep Dive |
| CVE-2025-14038 | EnterpriseDB Hybrid Manager - LTS 安全漏洞 | EnterpriseDB | Hybrid Manager - LTS | High | 7.0 | 2025-12-15 18:02:01 | Deep Dive |
| CVE-2025-34181 | NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE | NetSupport Software | Manager | - | - | 2025-12-15 14:42:18 | Deep Dive |
| CVE-2025-34180 | NetSupport Manager < 14.12.0001 Gateway Key Reversible Encoding Credential Recovery | NetSupport Software | Manager | - | - | 2025-12-15 14:41:52 | Deep Dive |
| CVE-2025-34179 | NetSupport Manager < 14.12.0001 Unauthenticated SQLi Local File Disclosure | NetSupport Software | Manager | - | - | 2025-12-15 14:41:27 | Deep Dive |
| CVE-2025-12900 | FileBird – WordPress Media Library Folders & File Manager <= 6.5.1 - Missing Authorization to Authenticated (Author+) Global Folders Tampering | ninjateam | FileBird – WordPress Media Library Folders & File Manager | Medium | 4.3 | 2025-12-15 14:25:11 | Deep Dive |
| CVE-2025-14451 | Solutions Ad Manager <= 1.0.0 - Unauthenticated Open Redirect via 'sam-redirect-to' Parameter | solutionsbysteve | Solutions Ad Manager | Medium | 4.7 | 2025-12-13 04:31:27 | Deep Dive |
| CVE-2025-12408 | Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure | netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | Medium | 5.3 | 2025-12-12 11:15:51 | Deep Dive |
| CVE-2025-12407 | Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion | netweblogic | Events Manager – Calendar, Bookings, Tickets, and more! | Medium | 4.3 | 2025-12-12 11:15:51 | Deep Dive |
| CVE-2025-4970 | BSK PDF Manager <= 3.7.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload | bannersky | BSK PDF Manager | Medium | 5.5 | 2025-12-12 07:20:34 | Deep Dive |
| CVE-2025-13987 | Purchase and Expense Manager <= 1.1.2 - Cross-Site Request Forgery to Arbitrary Purchase Record Deletion | codnloc | Purchase and Expense Manager | Medium | 4.3 | 2025-12-12 03:20:57 | Deep Dive |
| CVE-2025-13320 | WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter | wpusermanager | WP User Manager – User Profile Builder & Membership | Medium | 6.8 | 2025-12-12 03:20:51 | Deep Dive |
| CVE-2025-64622 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) | Adobe | Adobe Experience Manager | Medium | 5.4 | 2025-12-10 18:24:28 | Deep Dive |
| CVE-2025-64582 | Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) | Adobe | Adobe Experience Manager | Medium | 5.4 | 2025-12-10 18:24:27 | Deep Dive |