| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-12741 | Arbitrary File Write in Denodo dialect of Looker allows Remote Code Execution | Google Cloud | Looker | - | - | 2025-11-24 11:35:34 | Deep Dive |
| CVE-2025-12740 | Remote Command Execution in Looker via IBM DB2 JDBC drive | Google Cloud | Looker | - | - | 2025-11-24 11:30:32 | Deep Dive |
| CVE-2025-12739 | Cross-Site Scripting (XSS) in Looker's Extension Loader leading to Admin Account Compromise | Google Cloud | Looker | - | - | 2025-11-24 09:11:38 | Deep Dive |
| CVE-2025-12414 | Looker account compromise via punycode homograph attack | Google Cloud | Looker | 超危 | - | 2025-11-20 10:32:52 | Deep Dive |
| CVE-2025-62346 | HCL Glovius Cloud is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability | HCL Software | Glovius Cloud | Medium | 6.8 | 2025-11-20 08:08:07 | Deep Dive |
| CVE-2025-12743 | SQL Injection in Looker Project Generation Endpoint Allows Access to Internal MySQL Database | Google Cloud | Looker | - | - | 2025-11-19 16:41:31 | Deep Dive |
| CVE-2025-10703 | Progress多款产品 代码注入漏洞 | Progress | DataDirect Connect for JDBC for Amazon Redshift | - | - | 2025-11-19 15:47:08 | Deep Dive |
| CVE-2025-10702 | Progress多款产品 代码注入漏洞 | Progress | DataDirect Connect for JDBC for Amazon Redshift | - | - | 2025-11-19 15:46:27 | Deep Dive |
| CVE-2025-12472 | Remote Code Execution in Looker due to Improperly Validated Directory Deletion | Google Cloud | Looker | - | - | 2025-11-19 10:27:57 | Deep Dive |
| CVE-2025-4619 | PAN-OS: Firewall Denial of Service (DoS) Using Specially Crafted Packets | Palo Alto Networks | Cloud NGFW | 中危 | - | 2025-11-13 20:24:19 | Deep Dive |
| CVE-2025-20379 | Risky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk Enterprise | Splunk | Splunk Enterprise | Low | 3.5 | 2025-11-12 17:23:01 | Deep Dive |
| CVE-2025-20378 | Open Redirect on Web Login endpoint in Splunk Enterprise | Splunk | Splunk Enterprise | Low | 3.1 | 2025-11-12 17:22:57 | Deep Dive |
| CVE-2025-11085 | FactoryTalk® DataMosaix™ Private Cloud – Persistent XSS | Rockwell Automation | FactoryTalk® DataMosaix™ Private Cloud | 高危 | - | 2025-11-11 13:35:19 | Deep Dive |
| CVE-2025-11084 | FactoryTalk® DataMosaix™ Private Cloud – Authentication Bypass | Rockwell Automation | FactoryTalk® DataMosaix™ Private Cloud | 高危 | - | 2025-11-11 13:26:06 | Deep Dive |
| CVE-2025-12405 | Unauthorized access through stored credentials in Looker Studio | Google Cloud | Looker Studio | 高危 | - | 2025-11-10 09:27:45 | Deep Dive |
| CVE-2025-12409 | SQL Injection in Looker Studio | Google Cloud | Looker Studio | 中危 | - | 2025-11-10 08:59:16 | Deep Dive |
| CVE-2025-12397 | SQL Injection in Looker Studio | Google Cloud | Looker Studio | 高危 | - | 2025-11-10 08:55:05 | Deep Dive |
| CVE-2025-12155 | Command Injection in Looker | Google Cloud | Looker | 中危 | - | 2025-11-10 08:49:46 | Deep Dive |
| CVE-2025-37736 | Elastic Cloud Enterprise Improper Authorization | Elastic | Elastic Cloud Enterprise (ECE) | High | 8.8 | 2025-11-07 22:08:12 | Deep Dive |
| CVE-2025-62032 | WordPress tagDiv Cloud Library plugin < 3.9.2 - Cross Site Scripting (XSS) vulnerability | tagDiv | tagDiv Cloud Library | 中危 | - | 2025-11-06 15:55:29 | Deep Dive |