| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-7634 | WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Unauthenticated Local File Inclusion | wptravelengine | WP Travel Engine – Tour Booking Plugin – Tour Operator Software | Critical | 9.8 | 2025-10-09 05:23:53 | Deep Dive |
| CVE-2025-7526 | WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming | wptravelengine | WP Travel Engine – Tour Booking Plugin – Tour Operator Software | Critical | 9.8 | 2025-10-09 05:23:52 | Deep Dive |
| CVE-2025-11192 | Fabric Engine (VOSS) AutoSense Authentication Bypass | Extreme Networks | Fabric Engine (VOSS) | - | - | 2025-10-07 19:07:45 | Deep Dive |
| CVE-2025-59574 | WordPress WP Travel Engine Plugin <= 1.4.2 - Cross Site Scripting (XSS) Vulnerability | WP Travel Engine | WP Travel Engine | Medium | 6.5 | 2025-09-22 18:25:56 | Deep Dive |
| CVE-2025-58661 | WordPress eZee Online Hotel Booking Engine Plugin <= 1.0.0 - Cross Site Scripting (XSS) Vulnerability | eZee Technosys | eZee Online Hotel Booking Engine | Medium | 5.9 | 2025-09-22 18:23:02 | Deep Dive |
| CVE-2025-8268 | Ai Engine <= 2.9.5 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion | tigroumeow | AI Engine – The Chatbot, AI Framework & MCP for WordPress | Medium | 6.5 | 2025-09-03 20:24:16 | Deep Dive |
| CVE-2025-58640 | WordPress Document Engine Plugin <= 1.2 - Cross Site Scripting (XSS) Vulnerability | MatrixAddons | Document Engine | Medium | 6.5 | 2025-09-03 14:36:58 | Deep Dive |
| CVE-2025-20131 | Cisco Identity Services Engine Arbitrary File Upload Vulnerability | Cisco | Cisco Identity Services Engine Software | Medium | 4.9 | 2025-08-20 16:26:23 | Deep Dive |
| CVE-2025-48169 | WordPress Code Engine Plugin <= 0.3.3 - Remote Code Execution (RCE) Vulnerability | Jordy Meow | Code Engine | Critical | 9.9 | 2025-08-20 08:03:27 | Deep Dive |
| CVE-2025-54672 | WordPress Photo Engine Plugin plugin <= 6.4.3 - Cross Site Request Forgery (CSRF) Vulnerability | Jordy Meow | Photo Engine | Medium | 4.3 | 2025-08-14 10:34:40 | Deep Dive |
| CVE-2025-20037 | Intel Converged Security and Management Engine 安全漏洞 | - | Intel(R) Converged Security and Management Engine | High | 7.2 | 2025-08-12 16:57:59 | Deep Dive |
| CVE-2025-7195 | Operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd | operator-framework | operator-sdk | Medium | 6.4 | 2025-08-07 19:05:09 | Deep Dive |
| CVE-2025-20332 | Cisco Identity Services Engine Authorization Bypass Vulnerability | Cisco | Cisco Identity Services Engine Software | Medium | 4.3 | 2025-08-06 16:14:49 | Deep Dive |
| CVE-2025-20331 | Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabiliy | Cisco | Cisco Identity Services Engine Software | Medium | 5.4 | 2025-08-06 16:14:41 | Deep Dive |
| CVE-2025-7710 | Brave Conversion Engine (PRO) <= 0.7.7 - Authentication Bypass to Administrator | Brave | Brave Conversion Engine (PRO) | Critical | 9.8 | 2025-08-02 11:23:55 | Deep Dive |
| CVE-2025-7847 | AI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload | tigroumeow | AI Engine | High | 8.8 | 2025-07-31 04:26:20 | Deep Dive |
| CVE-2025-8179 | PHPGurukul Local Services Search Engine Management System changeimage.php sql injection | PHPGurukul | Local Services Search Engine Management System | High | 7.3 | 2025-07-26 05:02:07 | Deep Dive |
| CVE-2025-7780 | AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions | tigroumeow | AI Engine – The Chatbot, AI Framework & MCP for WordPress | Medium | 6.5 | 2025-07-24 09:22:16 | Deep Dive |
| CVE-2025-20337 | Cisco ISE API Unauthenticated Remote Code Execution Vulnerability | Cisco | Cisco Identity Services Engine Software | Critical | 10.0 | 2025-07-16 16:17:05 | Deep Dive |
| CVE-2025-20285 | Cisco Identity Services Engine IP Filter Access Restriction for Admin Access Configuration Bypass Vulnerability | Cisco | Cisco Identity Services Engine Software | Medium | 4.1 | 2025-07-16 16:16:56 | Deep Dive |