| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-4364 | Security Vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access | IBM | Verify Identity Access Container | Medium | 5.4 | 2026-04-01 20:34:30 | Deep Dive |
| CVE-2026-3470 | SonicWALL Email Security 输入验证错误漏洞 | SonicWall | Email Security | - | - | 2026-03-31 20:19:38 | Deep Dive |
| CVE-2026-3469 | SonicWALL Email Security 输入验证错误漏洞 | SonicWall | Email Security | - | - | 2026-03-31 20:18:33 | Deep Dive |
| CVE-2026-3468 | SonicWALL Email Security 跨站脚本漏洞 | SonicWall | Email Security | - | - | 2026-03-31 20:17:11 | Deep Dive |
| CVE-2026-33545 | MobSF has SQL Injection in its SQLite Database Viewer Utils | MobSF | Mobile-Security-Framework-MobSF | Medium | 5.3 | 2026-03-26 20:32:21 | Deep Dive |
| CVE-2026-20012 | Cisco多款产品 安全漏洞 | Cisco | IOS | High | 8.6 | 2026-03-25 16:03:12 | Deep Dive |
| CVE-2026-32947 | Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier) | step-security | harden-runner | 中危 | - | 2026-03-20 04:03:04 | Deep Dive |
| CVE-2026-32946 | Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier) | step-security | harden-runner | 中危 | - | 2026-03-20 03:58:41 | Deep Dive |
| CVE-2026-22733 | Authentication Bypass under Actuator CloudFoundry endpoints | Spring | Spring Security | High | 8.2 | 2026-03-19 23:29:10 | Deep Dive |
| CVE-2026-22732 | Under Some Conditions Spring Security HTTP Headers Are not Written | VMware | Spring Security | Critical | 9.1 | 2026-03-19 22:47:38 | Deep Dive |
| CVE-2026-27397 | WordPress Really Simple Security Pro plugin <= 9.5.4.0 - Insecure Direct Object References (IDOR) vulnerability | Really Simple Plugins B.V. | Really Simple Security Pro | Medium | 6.5 | 2026-03-19 05:30:19 | Deep Dive |
| CVE-2025-2274 | Stored Cross Site Scripting in Forcepoint Web Security | Forcepoint | Web Security (On-Prem) | - | - | 2026-03-16 14:46:50 | Deep Dive |
| CVE-2016-20032 | ZKTeco ZKAccess Security System 5.3.1 Stored XSS | ZKTeco Inc. | ZKTeco ZKAccess Security System | High | 7.2 | 2026-03-15 13:35:37 | Deep Dive |
| CVE-2026-32600 | xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption | simplesamlphp | xml-security | High | 8.2 | 2026-03-13 19:58:42 | Deep Dive |
| CVE-2026-32100 | swag/platform-security: `/api/_info/config` route exposes information about licenses and active security fixes | swag | platform-security | Medium | 5.3 | 2026-03-12 18:10:59 | Deep Dive |
| CVE-2026-27661 | Siemens SINEC Security Monitor 安全漏洞 | Siemens | SINEC Security Monitor | Medium | 4.3 | 2026-03-10 16:08:00 | Deep Dive |
| CVE-2026-28287 | FreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints | FreePBX | security-reporting | 高危 | - | 2026-03-05 18:25:55 | Deep Dive |
| CVE-2026-28284 | FreePBX: Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module | FreePBX | security-reporting | 高危 | - | 2026-03-05 18:24:51 | Deep Dive |
| CVE-2026-28210 | FreePBX: Authenticated SQL Injection in CDR (Call Data Record) Reports | FreePBX | security-reporting | 高危 | - | 2026-03-05 18:24:06 | Deep Dive |
| CVE-2026-28209 | FreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integration | FreePBX | security-reporting | 高危 | - | 2026-03-05 18:22:39 | Deep Dive |