| CVE-2025-11696 | Studio 5000 ® Simulation Interface SSRF | Rockwell Automation | Studio 5000® Simulation Interface™ | 高危 | - | 2025-11-11 13:47:11 | Deep Dive |
| CVE-2025-11862 | Verve Asset Manager Access Control Vulnerability | Rockwell Automation | Verve Asset Manager | 超危 | - | 2025-11-11 13:43:11 | Deep Dive |
| CVE-2025-11085 | FactoryTalk® DataMosaix™ Private Cloud – Persistent XSS | Rockwell Automation | FactoryTalk® DataMosaix™ Private Cloud | 高危 | - | 2025-11-11 13:35:19 | Deep Dive |
| CVE-2025-11084 | FactoryTalk® DataMosaix™ Private Cloud – Authentication Bypass | Rockwell Automation | FactoryTalk® DataMosaix™ Private Cloud | 高危 | - | 2025-11-11 13:26:06 | Deep Dive |
| CVE-2025-11967 | Mail Mint <= 1.18.10 - Authenticated (Admin+) Arbitrary File Upload | getwpfunnels | Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails | High | 7.2 | 2025-11-08 09:28:12 | Deep Dive |
| CVE-2025-36054 | Cross-site scripting vulnerability affect IBM Business Automation Workflow Process Federation Server - | IBM | Business Automation Workflow containers | Medium | 6.1 | 2025-11-06 14:11:49 | Deep Dive |
| CVE-2025-12469 | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending | amans2k | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Medium | 4.3 | 2025-11-05 09:27:40 | Deep Dive |
| CVE-2025-12468 | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure | amans2k | FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce | Medium | 5.3 | 2025-11-05 09:27:39 | Deep Dive |
| CVE-2025-36172 | Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes for 24.0.0-IF007, 24.0.1-IF005 and 25.0.0-IF002 | IBM | Cloud Pak for Business Automation | Medium | 6.4 | 2025-11-03 21:18:09 | Deep Dive |
| CVE-2025-36093 | security vulnerabilities are addressed with IBM Business Automation Insights iFixes for October 2025. | IBM | Cloud Pak For Business Automation | Medium | 4.8 | 2025-11-03 15:54:31 | Deep Dive |
| CVE-2025-36092 | IBM Business Automation Insights improper input validation | IBM | Cloud Pak For Business Automation | Medium | 6.5 | 2025-11-03 15:15:44 | Deep Dive |
| CVE-2025-36091 | IBM Business Automation Insights unverified ownership | IBM | Cloud Pak For Business Automation | Medium | 4.3 | 2025-11-03 15:14:03 | Deep Dive |
| CVE-2025-11975 | FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Missing Authorization to Authenticated (Subscriber+) Sync Rule Creation | fusewp | FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) | Medium | 4.3 | 2025-10-31 02:26:04 | Deep Dive |
| CVE-2025-10151 | Malicious TCP/IP thread locking leads into diverse malfunctions | Softing Industrial Automation GmbH | smartLink HW-PN | - | - | 2025-10-28 07:25:40 | Deep Dive |
| CVE-2025-10150 | Webserver crash caused by scanning on TCP port 80 | Softing Industrial Automation GmbH | smartLink HW-PN | - | - | 2025-10-28 07:24:38 | Deep Dive |
| CVE-2025-11976 | FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation | fusewp | FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) | Medium | 4.3 | 2025-10-25 06:49:25 | Deep Dive |
| CVE-2025-9178 | Rockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service Vulnerability | Rockwell Automation | 1715-AENTR EtherNet/IP Adapter | - | - | 2025-10-14 12:51:37 | Deep Dive |
| CVE-2025-9177 | Rockwell Automation 1715 EtherNet/IP Comms Module Denial-Of-Service Vulnerability | Rockwell Automation | 1715-AENTR EtherNet/IP Adapter | - | - | 2025-10-14 12:48:52 | Deep Dive |
| CVE-2025-7330 | Rockwell Automation 1783-NATR Cross-Site Request Forgery Vulnerability | Rockwell Automation | Comms - 1783-NATR | - | - | 2025-10-14 12:43:40 | Deep Dive |
| CVE-2025-11498 | CSV Formula Injection Vulnerability | B&R Industrial Automation GmbH | Automation Runtime | Medium | 6.1 | 2025-10-14 12:42:59 | Deep Dive |