| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-53960 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x SQL Injection via Authentication Bypass | SOUND4 Ltd. | Impact/Pulse/First | Critical | 9.8 | 2025-12-22 21:37:16 | Deep Dive |
| CVE-2023-53961 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request Forgery | SOUND4 Ltd. | Impact/Pulse/First | Medium | 4.3 | 2025-12-22 21:37:16 | Deep Dive |
| CVE-2023-53955 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References | SOUND4 Ltd. | Impact/Pulse/First | Critical | 9.8 | 2025-12-22 21:37:15 | Deep Dive |
| CVE-2025-13866 | Flow-Flow Social Feed Stream 3.0.0 - 4.7.5 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via flow_flow_social_auth AJAX action | looks_awesome | Flow-Flow Social Feed Stream | Medium | 6.4 | 2025-12-12 03:20:37 | Deep Dive |
| CVE-2025-6441 | Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition <= 4.03.32 - Unauthenticated Login Token Generation to Authentication Bypass | tobias_conrad | WebinarIgnition – Live, Automated & Evergreen Webinars for WooCommerce | Critical | 9.8 | 2025-07-24 09:22:17 | Deep Dive |
| CVE-2025-7655 | Live Stream Badger <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | tkrivickas | Live Stream Badger | Medium | 6.4 | 2025-07-19 02:22:57 | Deep Dive |
| CVE-2025-32677 | WordPress WP Social Stream Designer plugin <= 1.3 - SQL Injection vulnerability | solwininfotech | WP Social Stream Designer | High | 7.6 | 2025-04-09 16:09:15 | Deep Dive |
| CVE-2025-32680 | WordPress Review Stream plugin <= 1.6.7 - Cross Site Scripting (XSS) vulnerability | Grade Us, Inc. | Review Stream | Medium | 5.9 | 2025-04-09 16:09:13 | Deep Dive |
| CVE-2024-13879 | Stream <= 4.0.2 - Authenticated (Admin+) Server-Side Request Forgery | xwp | Stream | Medium | 5.5 | 2025-02-17 15:21:20 | Deep Dive |
| CVE-2025-25074 | WordPress WP Social Stream plugin <= 1.1 - CSRF to Stored XSS vulnerability | Nirmal Kumar Ram | WP Social Stream | High | 7.1 | 2025-02-07 10:11:30 | Deep Dive |
| CVE-2024-47072 | XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream | x-stream | xstream | High | 7.5 | 2024-11-07 23:38:53 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-8267 | Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress <= 2.0.78 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute | princeahmed | Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player | Medium | 6.4 | 2024-09-24 06:40:55 | Deep Dive |
| CVE-2024-7423 | Stream <= 4.0.1 - Cross-Site Request Forgery to Arbitrary Options Update | xwp | Stream | High | 8.8 | 2024-09-13 15:10:41 | Deep Dive |
| CVE-2023-4025 | Radio Player <= 2.0.73 - Missing Authorization to Player Update | princeahmed | Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player | Medium | 5.3 | 2024-08-17 07:34:24 | Deep Dive |
| CVE-2023-4024 | Radio Player <= 2.0.73 - Missing Authorization to Player Deletion | princeahmed | Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player | Medium | 5.3 | 2024-08-17 07:34:21 | Deep Dive |
| CVE-2023-4027 | Radio Player <= 2.0.73 - Missing Authorization to Settings Update | princeahmed | Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player | Medium | 5.3 | 2024-08-17 07:34:20 | Deep Dive |
| CVE-2023-49141 | Intel Processors 安全漏洞 | - | Intel(R) Processors stream cache mechanism | High | 7.8 | 2024-08-14 13:45:38 | Deep Dive |
| CVE-2023-42667 | Intel Core Ultra Processors 安全漏洞 | - | Intel(R) Core(TM) Ultra Processor stream cache mechanism | High | 7.8 | 2024-08-14 13:45:38 | Deep Dive |
| CVE-2023-47513 | WordPress ARI Stream Quiz – WordPress Quizzes Builder plugin <= 1.3.2 - Content Injection vulnerability | ARI Soft | ARI Stream Quiz | Medium | 5.4 | 2024-06-04 09:46:24 | Deep Dive |