2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11356 | HIGH | 8.8 | 0.7% | Oct 7, 2025 | A vulnerability was found in Tenda AC23 up to 16.03.07.52. Affected by this issue is the function sscanf of the file /go... |
| CVE-2025-11355 | HIGH | 8.8 | 0.7% | Oct 7, 2025 | A vulnerability has been found in UTT 1250GW up to v2v3.2.2-200710. Affected by this vulnerability is the function strcp... |
| CVE-2025-11353 | HIGH | 8.8 | 0.3% | Oct 7, 2025 | A vulnerability was detected in code-projects Online Hotel Reservation System 1.0. This impacts an unknown function of t... |
| CVE-2025-10162 | HIGH | 7.5 | 3.7% | Oct 7, 2025 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the... |
| CVE-2025-11362 | HIGH | 8.7 | 0.3% | Oct 7, 2025 | Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Wit... |
| CVE-2025-11352 | HIGH | 8.8 | 0.3% | Oct 7, 2025 | A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0. This affects an unknown... |
| CVE-2025-11351 | HIGH | 8.8 | 0.3% | Oct 7, 2025 | A weakness has been identified in code-projects Online Hotel Reservation System 1.0. The impacted element is an unknown ... |
| CVE-2025-34251 | HIGH | 8.6 | 0.5% | Oct 7, 2025 | Tesla Telematics Control Unit (TCU) firmware prior to v2025.14 contains an authentication bypass vulnerability. The TCU ... |
| CVE-2025-6985 | HIGH | 7.5 | 0.6% | Oct 6, 2025 | The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attac... |
| CVE-2025-11343 | HIGH | 8.6 | 0.4% | Oct 6, 2025 | A security vulnerability has been detected in code-projects Student Crud Operation 3.3. Affected is an unknown function ... |
| CVE-2025-60967 | HIGH | 7.3 | 0.3% | Oct 6, 2025 | Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 V... |
| CVE-2025-60963 | HIGH | 8.2 | 1.0% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60962 | HIGH | 8.2 | 0.8% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60960 | HIGH | 8.2 | 1.0% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60959 | HIGH | 8.2 | 0.8% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60958 | HIGH | 7.3 | 0.3% | Oct 6, 2025 | Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V... |
| CVE-2025-60956 | HIGH | 8 | 0.2% | Oct 6, 2025 | Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-007... |
| CVE-2025-36355 | HIGH | 8.5 | 0.2% | Oct 6, 2025 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0... |
| CVE-2025-36354 | HIGH | 7.3 | 0.3% | Oct 6, 2025 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0... |
| CVE-2025-11339 | HIGH | 8.8 | 0.9% | Oct 6, 2025 | A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the f... |
| CVE-2025-61687 | HIGH | 8.8 | 11.1% | Oct 6, 2025 | Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in ... |
| CVE-2025-59152 | HIGH | 7.5 | 0.4% | Oct 6, 2025 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely ... |
| CVE-2025-61197 | HIGH | 8.9 | 0.3% | Oct 6, 2025 | An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - Sy... |
| CVE-2025-11335 | HIGH | 7.2 | 4.8% | Oct 6, 2025 | A weakness has been identified in D-Link DI-7100G C1 up to 20250928. Affected by this vulnerability is the function sub_... |
| CVE-2025-11331 | HIGH | 7.2 | 17.6% | Oct 6, 2025 | A vulnerability was found in IdeaCMS up to 1.8. The impacted element is an unknown function of the file app/common/logic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now