| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-4206 | WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File Deletion | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | High | 7.2 | 2025-05-09 11:11:19 | Deep Dive |
| CVE-2025-29827 | Azure Automation Elevation of Privilege Vulnerability | Microsoft | Azure Automation | Critical | 9.9 | 2025-05-08 22:17:25 | Deep Dive |
| CVE-2025-4098 | Out-of-bounds Read in Horner Automation Cscape | Horner Automation | Cscape | - | - | 2025-05-08 17:45:03 | Deep Dive |
| CVE-2025-1838 | IBM Cloud Pak for Business Automation denial of service | IBM | Cloud Pak for Business Automation | Medium | 6.5 | 2025-05-03 18:23:26 | Deep Dive |
| CVE-2025-1495 | IBM Business Automation Workflow missing authentication | IBM | IBM Business Automation Workflow | Medium | 4.3 | 2025-05-03 16:53:01 | Deep Dive |
| CVE-2024-41753 | IBM Cloud Pak for Business Automation cross-site scripting | IBM | Cloud Pak for Business Automation | Medium | 6.1 | 2025-05-03 16:06:19 | Deep Dive |
| CVE-2025-1301 | Reflected XSS in Yordam Informatics' Library Automation System | Yordam Informatics | Library Automation System | Medium | 6.1 | 2025-05-02 10:59:41 | Deep Dive |
| CVE-2025-2812 | SQLi in Mydata Informatics' Ticket Sales Automation | Mydata Informatics | Ticket Sales Automation | Critical | 9.8 | 2025-05-02 08:24:40 | Deep Dive |
| CVE-2025-3395 | ABB Automation Builder 安全漏洞 | ABB | Automation Builder | High | 7.1 | 2025-04-30 12:40:38 | Deep Dive |
| CVE-2025-3394 | Vulnerability in user management of Automation Builder | ABB | Automation Builder | High | 7.8 | 2025-04-30 12:34:51 | Deep Dive |
| CVE-2025-46552 | KHC-INVITATION-AUTOMATION Sensitive User Information Leakage in Invitation Automation | Krypto-Hashers-Community | KHC-INVITATION-AUTOMATION | - | - | 2025-04-29 22:13:38 | Deep Dive |
| CVE-2025-46531 | WordPress WP AVCL Automation Helper (formerly WPFlyLeads) plugin <= 3.4 - Server Side Request Forgery (SSRF) Vulnerability | Ankur Vishwakarma | WP AVCL Automation Helper (formerly WPFlyLeads) | Medium | 4.9 | 2025-04-24 16:09:24 | Deep Dive |
| CVE-2025-32608 | WordPress Movylo Marketing Automation Plugin <= 2.0.7 - Cross Site Scripting (XSS) vulnerability | Movylo | Movylo Marketing Automation | High | 7.1 | 2025-04-17 15:47:18 | Deep Dive |
| CVE-2025-39513 | WordPress ActiveDEMAND plugin <= 0.2.46 - Broken Access Control vulnerability | ActiveDEMAND Online Agency Marketing Automation | ActiveDEMAND | Medium | 5.3 | 2025-04-16 12:45:54 | Deep Dive |
| CVE-2025-3618 | Local Privilege Escalation Vulnerability | Rockwell Automation | ThinManager | - | - | 2025-04-15 17:19:53 | Deep Dive |
| CVE-2025-3617 | Local Privilege Escalation in ThinManager® | Rockwell Automation | ThinManager® | - | - | 2025-04-15 17:17:25 | Deep Dive |
| CVE-2024-49825 | IBM Robotic Process Automation session fixation | IBM | Robotic Process Automation | Medium | 6.3 | 2025-04-14 14:53:41 | Deep Dive |
| CVE-2025-3102 | SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation | brainstormforce | OttoKit: All-in-One Automation Platform | High | 8.1 | 2025-04-10 04:22:06 | Deep Dive |
| CVE-2025-3289 | Local Code Execution Vulnerability in Arena® | Rockwell Automation | Arena® | - | - | 2025-04-08 15:34:21 | Deep Dive |
| CVE-2025-3288 | Local Code Execution Vulnerability in Arena® | Rockwell Automation | Arena® | - | - | 2025-04-08 15:30:32 | Deep Dive |