| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-56137 | MaxKB RCE vulnerability in function library | 1Panel-dev | MaxKB | Medium | 6.8 | 2025-01-02 14:26:20 | Deep Dive |
| CVE-2024-49363 | Uncontrolled Recursion and Asymmetric Resource Consumption (Amplification) in media/file proxy in Misskey | misskey-dev | misskey | High | 7.4 | 2024-12-18 19:24:34 | Deep Dive |
| CVE-2024-52579 | Server-Side Request Forgery vulnerability in various APIs in Misskey | misskey-dev | misskey | Medium | 6.4 | 2024-12-18 19:22:32 | Deep Dive |
| CVE-2024-52590 | Missing validation allows spoofed profiles in Misskey | misskey-dev | misskey | 高危 | - | 2024-12-18 19:21:33 | Deep Dive |
| CVE-2024-52591 | Missing validation allows spoofed profiles and notes in Misskey | misskey-dev | misskey | 高危 | - | 2024-12-18 19:20:31 | Deep Dive |
| CVE-2024-52592 | Missing validation allows spoofed poll updates in Misskey | misskey-dev | misskey | 中危 | - | 2024-12-18 19:19:18 | Deep Dive |
| CVE-2024-52593 | Missing validation allows spoofed "origin" links in Misskey | misskey-dev | misskey | 中危 | - | 2024-12-18 19:17:49 | Deep Dive |
| CVE-2024-37444 | WordPress Defender plugin <= 4.7.1 - Broken Access Control vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Defender Security | Medium | 5.3 | 2024-11-01 14:18:21 | Deep Dive |
| CVE-2024-43118 | WordPress Hummingbird plugin <= 3.9.1 - Broken Access Control vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Hummingbird | Medium | 4.3 | 2024-11-01 14:17:50 | Deep Dive |
| CVE-2024-49298 | WordPress PeproDev Ultimate Invoice plugin <= 2.0.6 - Cross Site Scripting (XSS) vulnerability | Pepro Dev. Group | PeproDev Ultimate Invoice | Medium | 6.5 | 2024-10-17 19:02:18 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-9355 | Golang-fips: golang fips zeroed buffer | - | - | Medium | 6.5 | 2024-10-01 18:17:29 | Deep Dive |
| CVE-2024-43793 | Halo's editor has a stored XSS vulnerability | halo-dev | halo | Medium | 6.3 | 2024-09-11 14:37:58 | Deep Dive |
| CVE-2024-45625 | WordPress plugin Forminator Forms 安全漏洞 | WPMU DEV | Forminator | - | - | 2024-09-09 04:44:55 | Deep Dive |
| CVE-2024-43792 | Halo's editor has a stored Cross-Site Scripting vulnerability | halo-dev | halo | Medium | 6.3 | 2024-09-02 16:15:40 | Deep Dive |
| CVE-2024-43117 | WordPress Hummingbird plugin <= 3.9.1 - Cross Site Request Forgery (CSRF) vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Hummingbird | Medium | 4.3 | 2024-08-26 20:50:26 | Deep Dive |
| CVE-2024-43367 | Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects | boa-dev | boa | High | 7.5 | 2024-08-15 20:38:24 | Deep Dive |
| CVE-2024-36111 | KubePi's JWT token validation has a defect | 1Panel-dev | KubePi | Medium | 6.3 | 2024-07-25 13:26:13 | Deep Dive |
| CVE-2024-37239 | WordPress Branda plugin <= 3.4.17 - Cross Site Scripting (XSS) vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Branda | Medium | 5.9 | 2024-07-22 09:14:17 | Deep Dive |
| CVE-2024-39911 | 1Panel SQL injection | 1Panel-dev | 1Panel | Critical | 10.0 | 2024-07-18 15:35:16 | Deep Dive |