| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-5544 | Media Library Assistant <= 3.17 - Reflected Cross-Site Scripting | dglingren | Media Library Assistant | Medium | 6.1 | 2024-07-02 07:37:05 | Deep Dive |
| CVE-2024-5605 | Media Library Assistant <= 3.16 - Authenticated (Contributor+) SQL Injection via order Parameter | dglingren | Media Library Assistant | High | 8.8 | 2024-06-20 03:37:22 | Deep Dive |
| CVE-2024-5292 | D-Link Network Assistant Uncontrolled Search Path Element Local Privilege Escalation Vulnerability | D-Link | Network Assistant | - | - | 2024-05-23 21:29:37 | Deep Dive |
| CVE-2024-3518 | Media Library Assistant <= 3.15 - Authenticated (Contributor+) SQL Injection via Shortcode | dglingren | Media Library Assistant | High | 8.8 | 2024-05-21 23:30:41 | Deep Dive |
| CVE-2024-3519 | Media Library Assistant <= 3.15 - Reflected Cross-Site Scripting via lang | dglingren | Media Library Assistant | Medium | 6.1 | 2024-05-21 23:30:40 | Deep Dive |
| CVE-2023-50197 | Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability | Intel | Driver & Support Assistant | 高危 | - | 2024-05-03 02:14:22 | Deep Dive |
| CVE-2023-42099 | Intel Driver & Support Assistant Link Following Local Privilege Escalation Vulnerability | Intel | Driver & Support Assistant | 高危 | - | 2024-05-03 02:13:11 | Deep Dive |
| CVE-2024-33538 | WordPress Assistant – Every Day Productivity Apps plugin <= 1.4.9.1 - Sensitive Data Exposure vulnerability | Fastline Media LLC | Assistant – Every Day Productivity Apps | Medium | 5.3 | 2024-04-29 07:50:06 | Deep Dive |
| CVE-2024-2871 | Media Library Assistant <= 3.13 - Authenticated (Contributor+) SQL Injection via Shortcode | dglingren | Media Library Assistant | Medium | 6.4 | 2024-04-09 18:59:09 | Deep Dive |
| CVE-2024-2475 | Media Library Assistant <= 3.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via mla_gallery Shortcode | dglingren | Media Library Assistant | Medium | 6.4 | 2024-03-29 04:31:34 | Deep Dive |
| CVE-2024-2863 | Path traversal via file upload on LG LED Assistant | LG Electronics | LG LED Assistant | Medium | 5.3 | 2024-03-25 06:39:47 | Deep Dive |
| CVE-2024-2862 | Password reset vulnerability without authorization on LG LED Assistant | LG Electronics | LG LED Assistant | Critical | 9.1 | 2024-03-25 06:31:35 | Deep Dive |
| CVE-2023-6985 | 10Web AI Assistant – AI content writing assistant <= 1.0.18 - Missing Authorization to Arbitrary Plugin Installation | 10web | 10Web AI Assistant – AI content writing assistant | Medium | 6.5 | 2024-02-05 21:21:37 | Deep Dive |
| CVE-2023-35867 | 部分Bosch产品 安全漏洞 | Bosch | BVMS | Medium | 5.9 | 2023-12-18 12:59:49 | Deep Dive |
| CVE-2023-50715 | User accounts disclosed to unauthenticated actors on the LAN | home-assistant | core | Medium | 4.3 | 2023-12-15 02:05:58 | Deep Dive |
| CVE-2023-26516 | WordPress Debug Assistant Plugin <= 1.4 is vulnerable to Cross Site Request Forgery (CSRF) | WPIndeed | Debug Assistant | High | 8.8 | 2023-11-12 23:48:59 | Deep Dive |
| CVE-2023-5798 | Assistant < 1.4.4 - Editor+ SSRF | Unknown | Assistant | 高危 | - | 2023-10-26 09:08:54 | Deep Dive |
| CVE-2023-41893 | Account takeover via auth_callback login in Home Assistant Core | home-assistant | core | Medium | 4.3 | 2023-10-19 23:27:09 | Deep Dive |
| CVE-2023-41894 | Local-only webhooks externally accessible via SniTun in Home Assistant Core | home-assistant | core | Medium | 5.3 | 2023-10-19 23:23:18 | Deep Dive |
| CVE-2023-41895 | Cross-site Scripting via auth_callback login in Home Assistant Core | home-assistant | core | High | 8.8 | 2023-10-19 22:37:24 | Deep Dive |