| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-59553 | WordPress Custom iFrame for Elementor Plugin <= 1.0.13 - Cross Site Scripting (XSS) Vulnerability | Coderz Studio | Custom iFrame for Elementor | Medium | 6.5 | 2025-09-22 18:26:05 | Deep Dive |
| CVE-2025-57910 | WordPress AnyClip Luminous Studio Plugin <= 1.3.3 - Cross Site Scripting (XSS) Vulnerability | AnyClip Video Platform | AnyClip Luminous Studio | Medium | 6.5 | 2025-09-22 18:25:21 | Deep Dive |
| CVE-2025-58271 | WordPress AnyClip Luminous Studio Plugin <= 1.3.3 - Cross Site Scripting (XSS) Vulnerability | AnyClip Video Platform | AnyClip Luminous Studio | Medium | 5.9 | 2025-09-22 18:23:14 | Deep Dive |
| CVE-2025-10492 | Jaspersoft Library Deserialisation Vulnerability | Jaspersoft | JasperReports Library Community Edition | - | - | 2025-09-16 16:41:45 | Deep Dive |
| CVE-2025-55319 | Agentic AI and Visual Studio Code Remote Code Execution Vulnerability | Microsoft | Visual Studio Code | High | 8.8 | 2025-09-12 00:49:28 | Deep Dive |
| CVE-2025-26499 | Wind River Studio Developer 安全漏洞 | Wind River Studio Developer | Wind River Studio Developer | Medium | 6.0 | 2025-09-11 16:46:29 | Deep Dive |
| CVE-2025-8360 | LA-Studio Element Kit for Elementor <= 1.5.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets | choijun | LA-Studio Element Kit for Elementor | Medium | 6.4 | 2025-09-06 02:24:17 | Deep Dive |
| CVE-2025-35452 | Pan-Tilt-Zoom cameras default administrative credentials for web interface | PTZOptics | PT12X-SE-xx-G3 | Critical | 9.8 | 2025-09-05 17:49:03 | Deep Dive |
| CVE-2025-35451 | Pan-Tilt-Zoom cameras hard-coded default passwords with SSH and telnet enabled | PTZOptics | PT12X-SE-xx-G3 | Critical | 9.8 | 2025-09-05 17:43:53 | Deep Dive |
| CVE-2025-58361 | Promptcraft Forge Studio's incomplete URL check is vulnerable to XSS via SVG | MarceloTessaro | promptcraft-forge-studio | Critical | 9.3 | 2025-09-04 19:43:44 | Deep Dive |
| CVE-2025-58353 | Promptcraft Forge Studio: Complete Sanitizer Bypass Enables XSS via Overlapping Patterns | MarceloTessaro | promptcraft-forge-studio | High | 8.2 | 2025-09-04 19:39:24 | Deep Dive |
| CVE-2025-9604 | coze-studio aes.go hard-coded key | - | coze-studio | Low | 3.7 | 2025-08-29 01:32:09 | Deep Dive |
| CVE-2024-49790 | IBM Watson Studio on Cloud Pak for Data cross-site scripting | IBM | Watson Studio on Cloud Pak for Data | Medium | 5.4 | 2025-08-28 14:09:59 | Deep Dive |
| CVE-2009-20002 | Millenium MP3 Studio <= 2.0 .pls File Stack-Based Buffer Overflow | Millenium | MP3 Studio | - | - | 2025-08-21 20:13:18 | Deep Dive |
| CVE-2025-7971 | Studio 5000 Logix Designer® – Arbitrary Code Execution Vulnerability | Rockwell Automation | Studio 5000 Logix Designer® | - | - | 2025-08-14 15:02:05 | Deep Dive |
| CVE-2011-10015 | Cytel Studio <= 9.0 .CY3 File Stack Buffer Overflow | Cytel Inc. | Studio | - | - | 2025-08-13 20:33:28 | Deep Dive |
| CVE-2025-54382 | Cherry Studio RCE Vulnerability Disclosure | CherryHQ | cherry-studio | Critical | 9.6 | 2025-08-13 13:31:14 | Deep Dive |
| CVE-2025-54074 | Cherry Studio is Vulnerable to OS Command Injection during Connection with a Malicious MCP Server | CherryHQ | cherry-studio | - | - | 2025-08-13 13:27:28 | Deep Dive |
| CVE-2025-53773 | GitHub Copilot and Visual Studio Remote Code Execution Vulnerability | Microsoft | Microsoft Visual Studio 2022 version 17.14 | High | 7.8 | 2025-08-12 17:09:51 | Deep Dive |
| CVE-2025-54063 | Cherry Studio One-click Remote Code Execution Vulnerability through Custom URL Handling | CherryHQ | cherry-studio | High | 8.0 | 2025-08-11 17:59:41 | Deep Dive |