VulnSea

Daily digest

Tuesday 2 December 2025

A heavy day: 78 new CVEs, well above the recent average of about 14. Of those, 15 critical and 21 high. One arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. entrust was the most-affected vendor with 13.

78
New CVEs
15
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 78 published.

CVE-2025-65896Critical· 9.8
10mo ago

asyncmy is vulnerable to SQL injection via crafted dict keys

asyncmy is vulnerable to SQL injection via crafted dict keys

▾ Midnightasyncmy · asyncmyEPSS 0.43%via OSV
CVE-2025-59695Critical· 9.8
10mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication)

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). T…

▾ Midnightentrust · nshield_5c_firmwareEPSS 0.67%via NVD
CVE-2025-59693Critical· 9.8
10mo ago

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate pri…

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate pri…

▾ Midnightentrust · nshield_5c_firmwareEPSS 0.90%via NVD
CVE-2025-41742Critical· 9.8
10mo ago

Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys

Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and dat…

▾ Midnightsprecher-automation · sprecon-e-c_firmwareEPSS 0.46%via NVD
CVE-2025-41013Critical· 9.8
10mo ago

SQL injection vulnerability in TCMAN GIM v11 in version 20250304

SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

▾ Midnighttcman · gimEPSS 0.29%via NVD
CVE-2025-12060Critical· 9.8
10mo ago

Keras Directory Traversal Vulnerability

Keras Directory Traversal Vulnerability

▾ Midnightkeras · kerasEPSS 0.63%via OSV
CVE-2025-11788Critical· 9.8
10mo ago

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(me…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.33%via NVD
CVE-2025-11786Critical· 9.8
10mo ago

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisatio…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.37%via NVD
CVE-2025-11784Critical· 9.8
10mo ago

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' …

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.37%via NVD
CVE-2025-11783Critical· 9.8
10mo ago

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundar…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.58%via NVD
CVE-2025-11782Critical· 9.8
10mo ago

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buff…

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 0.37%via NVD
CVE-2025-11779Critical· 9.8
10mo ago

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2

Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can …

▾ Midnightcircutor · sge-plc1000_firmwareEPSS 1.3%via NVD

Most-affected vendors

By CVEs published in the period.