| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-12966 | All-in-One Video Gallery 4.5.4 - 4.5.7 – Authenticated (Author+) Arbitrary File Upload via Import ZIP | plugins360 | All-in-One Video Gallery | High | 8.8 | 2025-12-06 09:25:58 | Deep Dive |
| CVE-2025-27935 | Authentication Bypass in OTP (One-time Passcode) IdP Adapter Integration Kit | Ping Identity | One-Time Passcode Integration Kit for PingFederate | - | - | 2025-12-04 20:38:32 | Deep Dive |
| CVE-2025-12358 | ShopEngine <= 4.8.5 - Cross-Site Request Forgery to Wishlist Manipulation | roxnor | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution | Medium | 4.3 | 2025-12-03 12:29:56 | Deep Dive |
| CVE-2025-11265 | VK All in One Expansion Unit <= 9.112.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | kurudrive | VK All in One Expansion Unit | Medium | 6.4 | 2025-11-18 07:30:37 | Deep Dive |
| CVE-2025-11267 | VK All in One Expansion Unit <= 9.112.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | kurudrive | VK All in One Expansion Unit | Medium | 6.4 | 2025-11-18 07:30:37 | Deep Dive |
| CVE-2025-12847 | All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion | smub | All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic | Medium | 4.3 | 2025-11-15 05:45:33 | Deep Dive |
| CVE-2025-25236 | Omnissa Workspace ONE UEM 安全漏洞 | Omnissa | Omnissa Workspace ONE UEM | Medium | 5.3 | 2025-11-12 17:41:57 | Deep Dive |
| CVE-2025-30398 | Nuance PowerScribe 360 Information Disclosure Vulnerability | Microsoft | Nuance PowerScribe 360 version 4.0.1 | High | 8.1 | 2025-11-11 17:59:51 | Deep Dive |
| CVE-2025-27711 | Intel OFU 安全漏洞 | - | Intel(R) One Boot Flash Update (Intel(R) OFU) software | Medium | 6.7 | 2025-11-11 16:50:25 | Deep Dive |
| CVE-2025-25059 | Intel OFU 代码问题漏洞 | - | Intel(R) One Boot Flash Update (Intel(R) OFU) software | Medium | 6.7 | 2025-11-11 16:50:10 | Deep Dive |
| CVE-2025-13032 | Gen Digital Antivirus 安全漏洞 | Avast | (Free/Premiium/Ultimeat) Antivirus | Critical | 9.9 | 2025-11-11 16:16:34 | Deep Dive |
| CVE-2025-42897 | Information Disclosure vulnerability in SAP Business One (SLD) | SAP_SE | SAP Business One (SLD) | Medium | 5.3 | 2025-11-11 00:19:51 | Deep Dive |
| CVE-2025-58595 | WordPress All In One Login plugin <= 2.0.8 - Bypass Vulnerability vulnerability | Saad Iqbal | All In One Login | 中危 | - | 2025-11-06 15:54:22 | Deep Dive |
| CVE-2025-48090 | WordPress Blanka - One Page WordPress Theme Theme < 1.5 - Local File Inclusion Vulnerability | CocoBasic | Blanka - One Page WordPress Theme | High | 8.1 | 2025-11-06 15:53:44 | Deep Dive |
| CVE-2025-22288 | WordPress Smush Image Compression and Optimization plugin <= 3.17.0 - Directory Traversal vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Smush Image Compression and Optimization | 中危 | - | 2025-11-06 15:53:18 | Deep Dive |
| CVE-2025-12493 | ShopLentor <= 3.2.5 - Unauthenticated Local PHP File Inclusion via 'load_template' | devitemsllc | ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | Critical | 9.8 | 2025-11-04 11:19:27 | Deep Dive |
| CVE-2025-12156 | Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One 2.0.7 - 2.2.6 - Missing Authorization to Authenticated (Subscriber+) Post Creation | aitool | Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One | Medium | 4.3 | 2025-11-04 04:27:19 | Deep Dive |
| CVE-2025-11758 | All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0.3 - Missing Authorization to Page Creation and Information Exposure | codebangers | All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier | Medium | 6.5 | 2025-11-04 04:27:15 | Deep Dive |
| CVE-2025-11193 | Lenovo Tablets 安全漏洞 | Lenovo | Tab M11 TB330FU TB330XU | Medium | 5.5 | 2025-11-03 21:40:32 | Deep Dive |
| CVE-2025-11888 | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update | roxnor | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution | Low | 2.7 | 2025-10-25 05:31:22 | Deep Dive |