| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-3936 | Incorrect Permission Assignment for Critical Resource | Tridium | Niagara Framework | Medium | 6.5 | 2025-05-22 12:20:42 | Deep Dive |
| CVE-2025-22233 | Spring Framework DataBinder Case Sensitive Match Exception | Spring | Spring Framework | Low | 3.1 | 2025-05-16 19:14:08 | Deep Dive |
| CVE-2024-13621 | The GDPR Framework By Data443 < 2.2.0 - Admin+ Stored XSS | Unknown | The GDPR Framework By Data443 | - | - | 2025-05-15 20:07:04 | Deep Dive |
| CVE-2025-46730 | Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack | MobSF | Mobile-Security-Framework-MobSF | Medium | 6.8 | 2025-05-05 19:32:24 | Deep Dive |
| CVE-2025-46335 | Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload | MobSF | Mobile-Security-Framework-MobSF | - | - | 2025-05-05 18:24:00 | Deep Dive |
| CVE-2024-13418 | Smart Framework <= Multiple Plugins - Authenticated (Subscriber+) Arbitrary File Upload | G5Theme | Benaa Framework | High | 8.8 | 2025-05-02 03:21:20 | Deep Dive |
| CVE-2024-13420 | Smart Framework <= Multiple Plugins - Missing Authorization to Authenticated (Subscriber+) Settings Updates | G5Theme | Benaa Framework | Medium | 4.3 | 2025-05-02 03:21:20 | Deep Dive |
| CVE-2024-13419 | Smart Framework <= Multiple Plugins - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | G5Theme | Benaa Framework | Medium | 6.4 | 2025-05-02 03:21:17 | Deep Dive |
| CVE-2025-32951 | io.jmix.rest:jmix-rest allows XSS in the /files Endpoint of the Generic REST API | jmix-framework | jmix | Medium | 6.4 | 2025-04-22 17:32:23 | Deep Dive |
| CVE-2025-32952 | io.jmix.localfs:jmix-localfs affected by DoS in the Local File Storage | jmix-framework | jmix | Medium | 6.5 | 2025-04-22 17:32:12 | Deep Dive |
| CVE-2025-32950 | io.jmix.localfs:jmix-localfs has a Path Traversal in Local File Storage | jmix-framework | jmix | Medium | 6.5 | 2025-04-22 17:14:43 | Deep Dive |
| CVE-2025-23251 | NVIDIA Nemo Framework 代码注入漏洞 | NVIDIA | NeMo Framework | High | 7.6 | 2025-04-22 15:42:04 | Deep Dive |
| CVE-2025-23250 | NVIDIA Nemo Framework 路径遍历漏洞 | NVIDIA | NeMo Framework | High | 7.6 | 2025-04-22 15:35:29 | Deep Dive |
| CVE-2025-23249 | NVIDIA Nemo Framework 代码问题漏洞 | NVIDIA | NeMo Framework | High | 7.6 | 2025-04-22 15:30:17 | Deep Dive |
| CVE-2025-30718 | Oracle E-Business Suite 安全漏洞 | Oracle Corporation | Oracle Applications Framework | Medium | 5.4 | 2025-04-15 20:31:13 | Deep Dive |
| CVE-2025-30711 | Oracle E-Business Suite 安全漏洞 | Oracle Corporation | Oracle Applications Framework | Medium | 5.4 | 2025-04-15 20:31:10 | Deep Dive |
| CVE-2025-3590 | Adianti Framework deserialization | Adianti | Framework | Medium | 6.3 | 2025-04-14 21:31:05 | Deep Dive |
| CVE-2025-30148 | Silverstripe Framework has a XSS vulnerability in HTML editor | silverstripe | silverstripe-framework | Medium | 5.4 | 2025-04-10 13:02:22 | Deep Dive |
| CVE-2025-25226 | [20250401] - Joomla Framework - SQL injection vulnerability in quoteNameStr method of Database package | Joomla! Project | Joomla! Framework | - | - | 2025-04-08 16:24:35 | Deep Dive |
| CVE-2025-31116 | Mobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding | MobSF | Mobile-Security-Framework-MobSF | Medium | 4.4 | 2025-03-31 16:42:43 | Deep Dive |