| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-20013 | Intel Tiber Edge Platform Edge Orchestrator 信息泄露漏洞 | - | Edge Orchestrator software for Intel(R) Tiber™ Edge Platform | Medium | 5.5 | 2025-05-13 21:01:35 | Deep Dive |
| CVE-2025-22249 | VMSA-2025-0008: VMware Aria automation updates address a DOM based Cross-site scripting vulnerability (CVE-2025-22249) | VMware | Vmware Aria Automation | High | 8.2 | 2025-05-13 05:08:03 | Deep Dive |
| CVE-2025-43000 | Information Disclosure Vulnerability in SAP Business Objects Business Intelligence Platform (PMW) | SAP_SE | SAP Business Objects Business Intelligence Platform (PMW) | High | 7.9 | 2025-05-13 00:18:00 | Deep Dive |
| CVE-2025-31329 | Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform | SAP_SE | SAP NetWeaver Application Server ABAP and ABAP Platform | Medium | 6.2 | 2025-05-13 00:16:51 | Deep Dive |
| CVE-2025-4556 | ZONG YU Okcat Parking Management Platform - Arbitrary File Upload | ZONG YU | Okcat Parking Management Platform | Critical | 9.8 | 2025-05-12 02:11:57 | Deep Dive |
| CVE-2025-4555 | ZONG YU Okcat Parking Management Platform - Missing Authentication | ZONG YU | Okcat Parking Management Platform | Critical | 9.8 | 2025-05-12 02:02:16 | Deep Dive |
| CVE-2025-4536 | Gosuncn Technology Group Audio-Visual Integrated Management Platform listByPage information disclosure | Gosuncn Technology Group | Audio-Visual Integrated Management Platform | Medium | 5.3 | 2025-05-11 08:31:07 | Deep Dive |
| CVE-2025-4535 | Gosuncn Technology Group Audio-Visual Integrated Management Platform Configuration File config.properties information disclosure | Gosuncn Technology Group | Audio-Visual Integrated Management Platform | Medium | 5.3 | 2025-05-11 08:00:12 | Deep Dive |
| CVE-2025-4432 | Ring: some aes functions may panic when overflow checking is enabled in ring | - | - | Medium | 5.3 | 2025-05-09 16:06:34 | Deep Dive |
| CVE-2025-4382 | Grub2: grub allow access to encrypted device through cli once root device is unlocked via tpm | - | - | Medium | 5.9 | 2025-05-09 11:59:33 | Deep Dive |
| CVE-2025-1909 | BuddyBoss Platform Pro <= 2.7.01 - Authentication Bypass via Apple OAuth provider | BuddyBoss | BuddyBoss Platform Pro | Critical | 9.8 | 2025-05-05 19:42:26 | Deep Dive |
| CVE-2025-24977 | OpenCTI has remote code execution and sensitive secrets exposed through web hook | OpenCTI-Platform | opencti | Critical | 9.1 | 2025-05-05 17:07:36 | Deep Dive |
| CVE-2024-13860 | BuddyBoss Platform <= 2.8.50 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bbp_topic_title' | Boss Media | BuddyBoss Platform | Medium | 6.4 | 2025-05-02 06:41:51 | Deep Dive |
| CVE-2024-13859 | BuddyBoss Platform <= 2.8.50 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'bp_nouveau_ajax_media_save' function | Boss Media | BuddyBoss Platform | Medium | 6.4 | 2025-05-02 06:41:51 | Deep Dive |
| CVE-2024-13858 | BuddyBoss Platform and BuddyBoss Theme <= Multiple Versions - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'invitee_name' | Boss Media | BuddyBoss Theme | Medium | 6.4 | 2025-05-02 06:41:50 | Deep Dive |
| CVE-2025-46554 | XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API | xwiki | xwiki-platform | Medium | 5.3 | 2025-04-30 18:27:54 | Deep Dive |
| CVE-2025-46557 | Any user with view access to the XWiki space can change the authenticator | xwiki | xwiki-platform | - | - | 2025-04-30 18:27:40 | Deep Dive |
| CVE-2025-24887 | OpenCTI bypass of protected attribute update | OpenCTI-Platform | opencti | Medium | 6.3 | 2025-04-30 18:27:25 | Deep Dive |
| CVE-2025-32973 | org.xwiki.platform:xwiki-platform-component-wiki provides no warning when granting XWiki.ComponentClass programming right | xwiki | xwiki-platform | Critical | 9.0 | 2025-04-30 14:55:04 | Deep Dive |
| CVE-2025-32974 | org.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't consider TextAreas with default content type | xwiki | xwiki-platform | Critical | 9.0 | 2025-04-30 14:55:01 | Deep Dive |