| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-43844 | GHSL-2025-014_Retrieval-based-Voice-Conversion-WebUI | RVC-Project | Retrieval-based-Voice-Conversion-WebUI | - | - | 2025-05-05 17:11:06 | Deep Dive |
| CVE-2025-43843 | GHSL-2025-013_Retrieval-based-Voice-Conversion-WebUI | RVC-Project | Retrieval-based-Voice-Conversion-WebUI | - | - | 2025-05-05 17:09:35 | Deep Dive |
| CVE-2025-43842 | GHSL-2025-012_Retrieval-based-Voice-Conversion-WebUI | RVC-Project | Retrieval-based-Voice-Conversion-WebUI | - | - | 2025-05-05 17:08:48 | Deep Dive |
| CVE-2025-3952 | Projectopia – WordPress Project Management <= 5.1.16 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion | projectopia | Projectopia – Project Management Tool | High | 8.1 | 2025-05-01 04:22:58 | Deep Dive |
| CVE-2025-32444 | vLLM Vulnerable to Remote Code Execution via Mooncake Integration | vllm-project | vllm | Critical | 10.0 | 2025-04-30 00:25:01 | Deep Dive |
| CVE-2025-46560 | vLLM phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service | vllm-project | vllm | Medium | 6.5 | 2025-04-30 00:24:54 | Deep Dive |
| CVE-2025-30202 | Data exposure via ZeroMQ on multi-node vLLM deployment | vllm-project | vllm | High | 7.5 | 2025-04-30 00:24:46 | Deep Dive |
| CVE-2024-32499 | Newforma Project Center Server 安全漏洞 | Newforma | Project Center Server | Medium | 4.9 | 2025-04-28 00:00:00 | Deep Dive |
| CVE-2025-46687 | QuickJS 安全漏洞 | QuickJS Project | QuickJS | Medium | 5.6 | 2025-04-27 00:00:00 | Deep Dive |
| CVE-2025-46688 | QuickJS 安全漏洞 | QuickJS Project | QuickJS | Medium | 5.6 | 2025-04-27 00:00:00 | Deep Dive |
| CVE-2025-3855 | CodeCanyon RISE Ultimate Project Manager Profile Picture save_profile_image resource injection | CodeCanyon | RISE Ultimate Project Manager | Medium | 4.3 | 2025-04-22 00:31:09 | Deep Dive |
| CVE-2025-43929 | kitty 安全漏洞 | kitty project | kitty | Medium | 4.1 | 2025-04-20 00:00:00 | Deep Dive |
| CVE-2023-26819 | cJSON 安全漏洞 | cJSON Project | cJSON | Low | 2.9 | 2025-04-19 00:00:00 | Deep Dive |
| CVE-2023-30421 | mJson 安全漏洞 | mjson project | mjson | Low | 2.9 | 2025-04-19 00:00:00 | Deep Dive |
| CVE-2025-32526 | WordPress Zephyr Project Manager plugin <= 3.3.101 - Cross Site Scripting (XSS) vulnerability | Dylan James | Zephyr Project Manager | High | 7.1 | 2025-04-17 15:47:41 | Deep Dive |
| CVE-2025-39552 | WordPress Zephyr Project Manager plugin <= 3.3.200 - Broken Access Control Vulnerability | Dylan James | Zephyr Project Manager | Medium | 5.4 | 2025-04-16 12:44:36 | Deep Dive |
| CVE-2025-2541 | WP Project Manager <= 2.6.22 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | wedevs | Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker | Medium | 6.4 | 2025-04-11 11:11:56 | Deep Dive |
| CVE-2025-32755 | Jenkins 安全漏洞 | Jenkins Project | Jenkins jenkins/ssh-slave Docker images | - | - | 2025-04-10 11:21:31 | Deep Dive |
| CVE-2025-32754 | Jenkins 安全漏洞 | Jenkins Project | Jenkins jenkins/ssh-agent Docker images | - | - | 2025-04-10 11:20:30 | Deep Dive |
| CVE-2025-3100 | WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload | wedevs | Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker | Medium | 6.4 | 2025-04-09 04:21:20 | Deep Dive |