2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13505 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of ... |
| CVE-2025-65858 | LOW | 3.5 | 0.2% | Dec 2, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript... |
| CVE-2025-41086 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be gener... |
| CVE-2025-41066 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the ex... |
| CVE-2025-41015 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker ... |
| CVE-2025-41014 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker ... |
| CVE-2025-41013 | CRITICAL | 9.8 | 0.2% | Dec 2, 2025 | SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-13731 | MEDIUM | 6.4 | 0.2% | Dec 2, 2025 | The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-13295 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message ... |
| CVE-2025-41012 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attack... |
| CVE-2025-40700 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScri... |
| CVE-2025-13879 | LOW | 2.7 | 0.5% | Dec 2, 2025 | Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with admin... |
| CVE-2025-12465 | HIGH | 8.6 | 0.2% | Dec 2, 2025 | A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high... |
| CVE-2025-11789 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parame... |
| CVE-2025-11788 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' f... |
| CVE-2025-11787 | HIGH | 8.8 | 0.9% | Dec 2, 2025 | Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()',... |
| CVE-2025-11786 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function,... |
| CVE-2025-11785 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' functi... |
| CVE-2025-11784 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' functio... |
| CVE-2025-11783 | CRITICAL | 9.8 | 0.5% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'A... |
| CVE-2025-11782 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “... |
| CVE-2025-11781 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded... |
| CVE-2025-11780 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function,... |
| CVE-2025-11779 | CRITICAL | 9.8 | 1.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when... |
| CVE-2025-11778 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now