2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60854 | CRITICAL | 9.8 | 1.0% | Dec 2, 2025 | A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during... |
| CVE-2025-58386 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper serv... |
| CVE-2025-65656 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php. |
| CVE-2025-65358 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at... |
| CVE-2025-13828 | CRITICAL | 9 | 0.2% | Dec 2, 2025 | SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even... |
| CVE-2025-59703 | CRITICAL | 9.1 | 0.4% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker... |
| CVE-2025-59695 | CRITICAL | 9.8 | 0.5% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a user with OS root access to a... |
| CVE-2025-59693 | CRITICAL | 9.8 | 0.7% | Dec 2, 2025 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow... |
| CVE-2025-41013 | CRITICAL | 9.8 | 0.2% | Dec 2, 2025 | SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-11788 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' f... |
| CVE-2025-11786 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function,... |
| CVE-2025-11785 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' functi... |
| CVE-2025-11784 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' functio... |
| CVE-2025-11783 | CRITICAL | 9.8 | 0.5% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'A... |
| CVE-2025-11782 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “... |
| CVE-2025-11780 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function,... |
| CVE-2025-11779 | CRITICAL | 9.8 | 1.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when... |
| CVE-2025-11778 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely ... |
| CVE-2025-41744 | CRITICAL | 9.1 | 0.4% | Dec 2, 2025 | Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to acce... |
| CVE-2025-41742 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker ... |
| CVE-2025-13872 | CRITICAL | 9.1 | 0.3% | Dec 2, 2025 | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-b... |
| CVE-2025-66410 | CRITICAL | 9.1 | 0.5% | Dec 1, 2025 | Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file... |
| CVE-2025-66405 | CRITICAL | 9.8 | 0.3% | Dec 1, 2025 | Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the ... |
| CVE-2025-66401 | CRITICAL | 9.8 | 2.0% | Dec 1, 2025 | MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPSca... |
| CVE-2025-66301 | CRITICAL | 9.6 | 1.2% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now