| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-23688 | Missing Authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services) | SAP_SE | SAP Fiori App (Manage Service Entry Sheets - Lean Services) | Medium | 4.3 | 2026-02-10 03:02:59 | Deep Dive |
| CVE-2019-25293 | Blue Stacks App Player 2.4.44.62.57 - "BstHdLogRotatorSvc" Unquote Service Path | bluestacks | Blue Stacks App Player | High | 7.8 | 2026-02-06 16:42:04 | Deep Dive |
| CVE-2025-13491 | IBM App Connect Enterprise Certified Container Information Disclosure | IBM | App Connect Enterprise Certified Container | Medium | 5.1 | 2026-02-05 13:55:22 | Deep Dive |
| CVE-2019-25263 | Zendesk App SweetHawk Survey 1.6 - Persistent Cross-Site Scripting | Sweethawk | Zendesk App SweetHawk Survey | Medium | 6.4 | 2026-02-03 16:52:41 | Deep Dive |
| CVE-2026-1745 | SourceCodester Medical Certificate Generator App cross-site request forgery | SourceCodester | Medical Certificate Generator App | Medium | 4.3 | 2026-02-02 05:02:07 | Deep Dive |
| CVE-2026-23896 | immich API Key Privilege Escalation vulnerability | immich-app | immich | High | 7.2 | 2026-01-29 17:12:44 | Deep Dive |
| CVE-2026-23683 | Missing Authorization check in SAP Fiori App (Intercompany Balance Reconciliation) | SAP_SE | SAP Fiori App (Intercompany Balance Reconciliation) | Medium | 4.3 | 2026-01-27 00:22:13 | Deep Dive |
| CVE-2026-22463 | WordPress Form to Chat App plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability | Micro.company | Form to Chat App | - | - | 2026-01-22 16:52:40 | Deep Dive |
| CVE-2026-0511 | Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation) | SAP_SE | SAP Fiori App (Intercompany Balance Reconciliation) | High | 8.1 | 2026-01-13 01:15:51 | Deep Dive |
| CVE-2026-0496 | Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation) | SAP_SE | SAP Fiori App (Intercompany Balance Reconciliation) | Medium | 6.6 | 2026-01-13 01:13:29 | Deep Dive |
| CVE-2026-0495 | Multiple vulnerabilities in SAP Fiori App (Intercompany Balance Reconciliation) | SAP_SE | SAP Fiori App (Intercompany Balance Reconciliation) | Medium | 5.1 | 2026-01-13 01:13:21 | Deep Dive |
| CVE-2026-0494 | Information Disclosure vulnerability in SAP Fiori App (Intercompany Balance Reconciliation) | SAP_SE | SAP Fiori App (Intercompany Balance Reconciliation) | Medium | 4.3 | 2026-01-13 01:13:14 | Deep Dive |
| CVE-2026-0493 | Cross-Site Request Forgery (CSRF) vulnerability in SAP Fiori App (Intercompany Balance Reconciliation) | SAP_SE | SAP Fiori App (Intercompany Balance Reconciliation) | Medium | 4.3 | 2026-01-13 01:13:07 | Deep Dive |
| CVE-2026-22685 | DevToys Path Traversal (“Zip Slip”) Vulnerability in DevToys Extension Installation | DevToys-app | DevToys | High | 8.8 | 2026-01-10 05:43:20 | Deep Dive |
| CVE-2025-62487 | Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings of their parent artifact. This lack of security markings could lead to unintended access to the uploaded files. | Palantir | com.palantir.acme:gotham-default-apps-bundle | Low | 3.5 | 2026-01-09 21:17:37 | Deep Dive |
| CVE-2025-68891 | WordPress WP App Bar plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability | Ryan Sutana | WP App Bar | 中危 | - | 2026-01-08 09:17:54 | Deep Dive |
| CVE-2025-13841 | Smart App Banners <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' and 'verticalalign' Shortcode Attributes | clevelandwebdeveloper | Smart App Banners | Medium | 6.4 | 2026-01-07 09:21:03 | Deep Dive |
| CVE-2026-0580 | SourceCodester API Key Manager App Import Key cross site scripting | SourceCodester | API Key Manager App | Low | 3.5 | 2026-01-05 07:32:06 | Deep Dive |
| CVE-2025-50053 | WordPress Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App Plugin <= 0.8.8.8 - Cross Site Scripting (XSS) Vulnerability | nebelhorn | Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App | High | 7.1 | 2025-12-31 20:09:03 | Deep Dive |
| CVE-2025-13029 | Knowband Mobile App Builder for wooCommerce < 3.0.0 – Unauthenticated Arbitrary User Deletion | Unknown | Knowband Mobile App Builder | 高危 | - | 2025-12-31 06:00:03 | Deep Dive |