| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-59547 | DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation | dnnsoftware | Dnn.Platform | Medium | 5.3 | 2025-09-23 17:56:47 | Deep Dive |
| CVE-2025-59821 | DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile | dnnsoftware | Dnn.Platform | Medium | 6.5 | 2025-09-23 17:42:17 | Deep Dive |
| CVE-2025-59546 | DNN Vulnerable to Stored XSS Using Backend Admin Credentials | dnnsoftware | Dnn.Platform | Low | 2.4 | 2025-09-23 17:41:48 | Deep Dive |
| CVE-2025-59545 | DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module | dnnsoftware | Dnn.Platform | Critical | 9.0 | 2025-09-23 17:41:30 | Deep Dive |
| CVE-2025-59539 | DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field | dnnsoftware | Dnn.Platform | Medium | 6.3 | 2025-09-23 17:41:01 | Deep Dive |
| CVE-2025-42907 | Server-Side Request Forgery in SAP BI Platform | SAP_SE | SAP BI Platform | Medium | 4.3 | 2025-09-23 01:58:28 | Deep Dive |
| CVE-2025-10822 | fuyang_lipengjun platform queryAll SysSmsLogController improper authorization | fuyang_lipengjun | platform | Medium | 4.3 | 2025-09-22 23:32:08 | Deep Dive |
| CVE-2025-10821 | fuyang_lipengjun platform queryAll TopicCategoryController improper authorization | fuyang_lipengjun | platform | Medium | 4.3 | 2025-09-22 23:02:10 | Deep Dive |
| CVE-2025-10820 | fuyang_lipengjun platform queryAll TopicController improper authorization | fuyang_lipengjun | platform | Medium | 4.3 | 2025-09-22 22:32:12 | Deep Dive |
| CVE-2025-10819 | fuyang_lipengjun platform queryAll UserCouponController improper authorization | fuyang_lipengjun | platform | Medium | 4.3 | 2025-09-22 22:32:08 | Deep Dive |
| CVE-2025-59535 | DotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters | dnnsoftware | Dnn.Platform | Medium | 6.5 | 2025-09-22 20:59:04 | Deep Dive |
| CVE-2025-57910 | WordPress AnyClip Luminous Studio Plugin <= 1.3.3 - Cross Site Scripting (XSS) Vulnerability | AnyClip Video Platform | AnyClip Luminous Studio | Medium | 6.5 | 2025-09-22 18:25:21 | Deep Dive |
| CVE-2025-58271 | WordPress AnyClip Luminous Studio Plugin <= 1.3.3 - Cross Site Scripting (XSS) Vulnerability | AnyClip Video Platform | AnyClip Luminous Studio | Medium | 5.9 | 2025-09-22 18:23:14 | Deep Dive |
| CVE-2025-9035 | Reflected XSS in Horato Internet Technologies' Virtual Library Platform | Horato Internet Technologies Ind. and Trade Inc. | Virtual Library Platform | Medium | 5.4 | 2025-09-22 09:15:16 | Deep Dive |
| CVE-2025-53692 | Sitecore Experience Platform Cross-Site Scripting Vulnerability | Sitecore | Sitecore Experience Manager (XM) | High | 7.1 | 2025-09-21 19:42:47 | Deep Dive |
| CVE-2025-10709 | Four-Faith Water Conservancy Informatization Platform historyDownload.do;otheruserLogin.do;getfile path traversal | Four-Faith | Water Conservancy Informatization Platform | Medium | 5.3 | 2025-09-19 12:02:07 | Deep Dive |
| CVE-2025-10708 | Four-Faith Water Conservancy Informatization Platform historyDownload.do;usrlogout.do path traversal | Four-Faith | Water Conservancy Informatization Platform | Medium | 5.3 | 2025-09-19 11:32:13 | Deep Dive |
| CVE-2025-10676 | fuyang_lipengjun platform queryAll BrandController improper authorization | fuyang_lipengjun | platform | Medium | 4.3 | 2025-09-18 16:02:13 | Deep Dive |
| CVE-2025-10675 | fuyang_lipengjun platform queryAll AttributeController improper authorization | fuyang_lipengjun | platform | Medium | 4.3 | 2025-09-18 16:02:09 | Deep Dive |
| CVE-2025-10674 | fuyang_lipengjun platform queryAll AttributeCategoryController improper authorization | fuyang_lipengjun | platform | Medium | 4.3 | 2025-09-18 15:32:09 | Deep Dive |