漏洞列表 353571
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-11782
Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50
HIGH 8.5 2025-12-02
SGE-PLC1000 SGE-PLC50 Circutor circutor sge-plc1000_firmware +1个
CVE NVD
CVE-2025-11781
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50
HIGH 8.6 2025-12-02
SGE-PLC1000 SGE-PLC50 Circutor circutor sge-plc1000_firmware +1个
CVE NVD
CVE-2025-11780
Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50
HIGH 8.7 2025-12-02
SGE-PLC1000 SGE-PLC50 Circutor circutor sge-plc1000_firmware +1个
CVE NVD
CVE-2025-11779
Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50
CRITICAL 9.4 2025-12-02
SGE-PLC1000 SGE-PLC50 Circutor circutor sge-plc1000_firmware +1个
CVE NVD
CVE-2025-11778
Stack-based buffer overflow vulnreability in Circutor SGE-PLC1000/SGE-PLC50
CRITICAL 10.0 2025-12-02
SGE-PLC1000 SGE-PLC50 Circutor circutor sge-plc1000_firmware +1个
CVE NVD
CVE-2025-13879
Directory traversal vulnerability in EfficientIP's SOLIDserver IPAM
MEDIUM 5.1 2025-12-02
SOLIDserver SOLIDserver IPAM efficientip solidserver_ip_address_management
CVE NVD
CVE-2025-12465
Blind SQL Injection in QuickCMS
HIGH 8.6 2025-12-02
OpenSolution QuickCMS
CVE NVD
CVE-2025-13090
WP Directory Kit <= 1.4.6 - Authenticated (Admin+) SQL Injection
MEDIUM 4.9 2025-12-02
listingthemes WP Directory Kit
CVE NVD
CVE-2025-13353
gokey allows secret recovery from a seed file without the master password
HIGH 7.1 2025-12-02
Cloudflare gokey cloudflare gokey
CVE NVD
CVE-2025-41742
Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptographic keys in system components
CRITICAL 9.8 2025-12-02
Sprecher Automation SPRECON-E-C Sprecher Automation SPRECON-E-P +1个
CVE NVD
CVE-2025-41743
Sprecher Automation: SPRECON-E series prone to weak encryption of update files
MEDIUM 4.0 2025-12-02
Sprecher Automation SPRECON-E-C Sprecher Automation SPRECON-E-P +1个
CVE NVD
CVE-2025-41744
Sprecher Automation: SPRECON-E series has static default key material for TLS connections
CRITICAL 9.1 2025-12-02
Sprecher Automation SPRECON-E-C Sprecher Automation SPRECON-E-P +1个
CVE NVD
CVE-2025-13873
The feature to import a survey is prone to stored Cross-Site Script attacks
MEDIUM 4.8 2025-12-02
ObjectPlanet Opinio objectplanet opinio
CVE NVD
CVE-2025-13872
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio
LOW 2.1 2025-12-02
ObjectPlanet Opinio objectplanet opinio
CVE NVD
CVE-2025-13871
The feature to manage resources is prone to Cross-Site Request Forgery attacks
LOW 2.3 2025-12-02
ObjectPlanet Opinio objectplanet opinio
CVE NVD
CVE-2025-13870
Unauthorized access and subscription vulnerability in Boards
LOW 3.1 2025-12-02
Mattermost Mattermost mattermost mattermost_server
CVE NVD
CVE-2025-13516
SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Unauthenticated Arbitrary File Upload
HIGH 8.1 2025-12-02
brainstormforce SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers
CVE NVD
CVE-2025-13724
VikRentCar Car Rental Management System <= 1.4.4 - Authenticated (Author+) SQL Injection via 'month' Parameter
HIGH 7.5 2025-12-02
e4jvikwp VikRentCar Car Rental Management System
CVE NVD
CVE-2025-13534
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action
MEDIUM 6.3 2025-12-02
elextensions ELEX WordPress HelpDesk & Customer Ticketing System elula wsdesk
CVE NVD
CVE-2025-10543
In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, pass...
MEDIUM 6.3 2025-12-02
Eclipse Foundation paho.mqtt.golang (Go MQTT v3.1 library) eclipse paho_mqtt
CVE NVD