2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-11788CRITICAL9.8Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' f...
CVE-2025-11786CRITICAL9.8Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function,...
CVE-2025-11785CRITICAL9.8Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' functi...
CVE-2025-11784CRITICAL9.8Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' functio...
CVE-2025-11783CRITICAL9.8Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'A...
CVE-2025-11782CRITICAL9.8Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “...
CVE-2025-11780CRITICAL9.8Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function,...
CVE-2025-11779CRITICAL9.8Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when...
CVE-2025-11778CRITICAL9.8Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely ...
CVE-2025-41744CRITICAL9.1Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to acce...
CVE-2025-41742CRITICAL9.8Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker ...
CVE-2025-13872CRITICAL9.1Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-b...
CVE-2025-66410CRITICAL9.1Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file...
CVE-2025-66405CRITICAL9.8Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the ...
CVE-2025-66401CRITICAL9.8MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPSca...
CVE-2025-66301CRITICAL9.6Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical ...
CVE-2025-66205CRITICAL9.8Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to err...
CVE-2025-65836CRITICAL9.1PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.
CVE-2025-51683CRITICAL9.8A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL...
CVE-2025-51682CRITICAL9.8mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and ga...
CVE-2025-3500CRITICAL9.8Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This...
CVE-2025-63531CRITICAL9.8A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The...
CVE-2025-12106CRITICAL9.1Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-...
CVE-2025-13815CRITICAL9.8A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the ...
CVE-2025-13814CRITICAL9.8A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now