| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-61776 | Dependency-Track possibly discloses private NuGet repository credentials to api.nuget.org | DependencyTrack | dependency-track | Medium | 4.7 | 2025-10-07 18:57:06 | Deep Dive |
| CVE-2025-27137 | Dependency-Track vulnerable to local file inclusion via custom notification templates | DependencyTrack | dependency-track | Medium | 4.4 | 2025-02-24 20:59:51 | Deep Dive |
| CVE-2024-54002 | Dependency-Track allows enumeration of managed users via /api/v1/user/login endpoint | DependencyTrack | dependency-track | Medium | 5.3 | 2024-12-04 15:33:05 | Deep Dive |
| CVE-2022-39351 | Dependency-Track vulnerable to logging of API keys in clear text when handling API requests using keys with insufficient permissions | DependencyTrack | dependency-track | Medium | 4.4 | 2022-10-25 00:00:00 | Deep Dive |
| CVE-2021-21633 | Jenkins OWASP Dependency-Track 跨站请求伪造漏洞 | Jenkins project | Jenkins OWASP Dependency-Track Plugin | 高危 | - | 2021-03-30 11:10:36 | Deep Dive |
| CVE-2021-21632 | Dependency-Track 安全漏洞 | Jenkins project | Jenkins OWASP Dependency-Track Plugin | 中危 | - | 2021-03-30 11:10:35 | Deep Dive |
| CVE-2019-1020007 | Dependency-Track 跨站脚本漏洞 | Dependency-Track | Dependency-Track | 中危 | - | 2019-07-29 14:18:52 | Deep Dive |