8.5

CVSS4.0

CVE-2025-11782 - Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buffer 'acStack_4c' (64 bytes) without checking the length. An att…

📅 Published: Dec. 2, 2025, 1 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:11 p.m.

8.6

CVSS4.0

CVE-2025-11781 - Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50

Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded static authentication key. An attacker with local access to the device can extract this key (e.g., by analysing the firmware image or memory dump) and create valid firmware updat…

📅 Published: Dec. 2, 2025, 12:59 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:10 p.m.

8.7

CVSS4.0

CVE-2025-11780 - Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is directly incorporate…

📅 Published: Dec. 2, 2025, 12:58 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:08 p.m.

9.4

CVSS4.0

CVE-2025-11779 - Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes to the 'index.cgi' we…

📅 Published: Dec. 2, 2025, 12:57 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:07 p.m.

10

CVSS4.0

CVE-2025-11778 - Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50

Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' function of the TACACSPLUS implementation.

📅 Published: Dec. 2, 2025, 12:56 p.m. 🔄 Last Modified: Dec. 3, 2025, 7:07 p.m.

5.1

CVSS4.0

CVE-2025-13879 - Directory traversal vulnerability in EfficientIP's SOLIDserver IPAM

Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with administrator privileges to list directories other than those to which the have authorized access using the 'directory' parameter in '/mod/ajax.php?action=sections/list/list'.For examp…

📅 Published: Dec. 2, 2025, 12:23 p.m. 🔄 Last Modified: Jan. 30, 2026, 8:32 p.m.

8.6

CVSS4.0

CVE-2025-12465 - Blind SQL Injection in QuickCMS

A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high-privileged user into aFilesDelete allows for Blind SQL Injection attacks. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerab…

📅 Published: Dec. 2, 2025, 12:15 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.9

CVSS3.1

CVE-2025-13090 - WP Directory Kit <= 1.4.6 - Authenticated (Admin+) SQL Injection

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authe…

📅 Published: Dec. 2, 2025, 11:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS4.0

CVE-2025-13353 - gokey allows secret recovery from a seed file without the master password

In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely from the initial vector and the AES-GCM authentication tag of the key seed. This issue has been fixed in gokey version 0.2.0. This is a breaking change. The fix has invalidated …

📅 Published: Dec. 2, 2025, 11:03 a.m. 🔄 Last Modified: Dec. 15, 2025, 3:31 p.m.

9.8

CVSS3.1

CVE-2025-41742 - Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptog…

Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote maintenance.

📅 Published: Dec. 2, 2025, 10:39 a.m. 🔄 Last Modified: Feb. 23, 2026, 5:15 p.m.
Total resulsts: 345139
Page 2448 of 34,514
« previous page » next page
Filters