| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-41337 | Missing Authorization vulnerability in CanalDenuncia.app | CanalDenuncia | CanalDenuncia.app | - | - | 2025-11-04 13:16:21 | Deep Dive |
| CVE-2025-41336 | Missing Authorization vulnerability in CanalDenuncia.app | CanalDenuncia | CanalDenuncia.app | - | - | 2025-11-04 13:16:03 | Deep Dive |
| CVE-2025-41335 | Missing Authorization vulnerability in CanalDenuncia.app | CanalDenuncia | CanalDenuncia.app | - | - | 2025-11-04 13:15:43 | Deep Dive |
| CVE-2025-41114 | Missing Authorization vulnerability in CanalDenuncia.app | CanalDenuncia | CanalDenuncia.app | - | - | 2025-11-04 13:10:32 | Deep Dive |
| CVE-2025-41113 | Missing Authorization vulnerability in CanalDenuncia.app | CanalDenuncia | CanalDenuncia.app | - | - | 2025-11-04 13:10:12 | Deep Dive |
| CVE-2025-41112 | Missing Authorization vulnerability in CanalDenuncia.app | CanalDenuncia | CanalDenuncia.app | - | - | 2025-11-04 13:09:54 | Deep Dive |
| CVE-2025-41111 | Missing Authorization vulnerability in CanalDenuncia.app | CanalDenuncia | CanalDenuncia.app | - | - | 2025-11-04 13:08:40 | Deep Dive |
| CVE-2025-11833 | Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure | saadiqbal | Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App | Critical | 9.8 | 2025-11-01 03:34:36 | Deep Dive |
| CVE-2025-30191 | Open-Xchange OX App Suite 安全漏洞 | Open-Xchange GmbH | OX App Suite | Medium | 5.4 | 2025-10-31 08:54:42 | Deep Dive |
| CVE-2025-30188 | Open-Xchange OX App Suite 安全漏洞 | Open-Xchange GmbH | OX App Suite | High | 7.5 | 2025-10-31 08:54:41 | Deep Dive |
| CVE-2025-11881 | AppPresser – Mobile App Framework <= 4.5.0 - Missing Authorization to Unauthenticated Limited Sensitive Information Exposure | scottopolis | AppPresser – Mobile App Framework | Medium | 5.3 | 2025-10-30 06:45:40 | Deep Dive |
| CVE-2025-36361 | IBM App Connect Enterprise runtime is vulnerable to a lack of authorization on windows environments using IWA | IBM | App Connect Enterprise | Medium | 6.3 | 2025-10-24 09:35:21 | Deep Dive |
| CVE-2025-61865 | I-O DATA I‑O DATA NarSuS App 代码问题漏洞 | I-O DATA DEVICE, INC. | NarSuS App | - | - | 2025-10-23 04:14:50 | Deep Dive |
| CVE-2025-62614 | BookLore Media API Authentication Bypass | booklore-app | booklore | - | - | 2025-10-22 20:58:46 | Deep Dive |
| CVE-2025-62607 | Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL | nautobot | nautobot-app-ssot | Medium | 5.3 | 2025-10-22 15:40:46 | Deep Dive |
| CVE-2025-11757 | Improper Neutralization of Wildcards or Matching Symbols in CloudEdge Online Cameras and App | CloudEdge | CloudEdge App | - | - | 2025-10-21 17:24:54 | Deep Dive |
| CVE-2025-62428 | Drawing-Captcha APP Host Header Injection in `/register` and `/confirm-email` Endpoints | Drawing-Captcha | Drawing-Captcha-APP | - | - | 2025-10-16 18:57:14 | Deep Dive |
| CVE-2025-58474 | BIG-IP Advanced WAF and ASM and NGINX App Protect DNS lookup vulnerability | F5 | BIG-IP | Medium | 5.3 | 2025-10-15 13:55:43 | Deep Dive |
| CVE-2025-58718 | Remote Desktop Client Remote Code Execution Vulnerability | Microsoft | Remote Desktop client for Windows Desktop | High | 8.8 | 2025-10-14 17:01:16 | Deep Dive |
| CVE-2025-9976 | OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x | Dassault Systèmes | Station Launcher App in 3DEXPERIENCE platform | Critical | 9.0 | 2025-10-13 07:33:16 | Deep Dive |