2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11788 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' f... |
| CVE-2025-11786 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function,... |
| CVE-2025-11785 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' functi... |
| CVE-2025-11784 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' functio... |
| CVE-2025-11783 | CRITICAL | 9.8 | 0.6% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'A... |
| CVE-2025-11782 | CRITICAL | 9.8 | 0.4% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “... |
| CVE-2025-11780 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function,... |
| CVE-2025-11779 | CRITICAL | 9.8 | 1.3% | Dec 2, 2025 | Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when... |
| CVE-2025-11778 | CRITICAL | 9.8 | 0.3% | Dec 2, 2025 | Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely ... |
| CVE-2025-41744 | CRITICAL | 9.1 | 0.4% | Dec 2, 2025 | Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to acce... |
| CVE-2025-41742 | CRITICAL | 9.8 | 0.5% | Dec 2, 2025 | Sprecher Automations SPRECON-E-C, SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker ... |
| CVE-2025-13872 | CRITICAL | 9.1 | 0.3% | Dec 2, 2025 | Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-b... |
| CVE-2025-66410 | CRITICAL | 9.1 | 0.5% | Dec 1, 2025 | Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file... |
| CVE-2025-66405 | CRITICAL | 9.8 | 0.3% | Dec 1, 2025 | Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the ... |
| CVE-2025-66401 | CRITICAL | 9.8 | 2.0% | Dec 1, 2025 | MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPSca... |
| CVE-2025-66301 | CRITICAL | 9.6 | 1.3% | Dec 1, 2025 | Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical ... |
| CVE-2025-66205 | CRITICAL | 9.8 | 0.3% | Dec 1, 2025 | Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to err... |
| CVE-2025-65836 | CRITICAL | 9.1 | 0.3% | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController. |
| CVE-2025-51683 | CRITICAL | 9.8 | 0.4% | Dec 1, 2025 | A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL... |
| CVE-2025-51682 | CRITICAL | 9.8 | 0.4% | Dec 1, 2025 | mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and ga... |
| CVE-2025-3500 | CRITICAL | 9.8 | 0.5% | Dec 1, 2025 | Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This... |
| CVE-2025-63531 | CRITICAL | 9.8 | 0.6% | Dec 1, 2025 | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The... |
| CVE-2025-12106 | CRITICAL | 9.1 | 0.6% | Dec 1, 2025 | Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-... |
| CVE-2025-13815 | CRITICAL | 9.8 | 0.4% | Dec 1, 2025 | A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the ... |
| CVE-2025-13814 | CRITICAL | 9.8 | 0.5% | Dec 1, 2025 | A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now