2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60964 | CRITICAL | 9.1 | 1.4% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60963 | HIGH | 8.2 | 1.0% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60962 | HIGH | 8.2 | 0.8% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60961 | MEDIUM | 6.1 | 0.2% | Oct 6, 2025 | Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V... |
| CVE-2025-60960 | HIGH | 8.2 | 1.0% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60959 | HIGH | 8.2 | 0.8% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60958 | HIGH | 7.3 | 0.3% | Oct 6, 2025 | Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 V... |
| CVE-2025-60957 | CRITICAL | 9.9 | 1.3% | Oct 6, 2025 | OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0... |
| CVE-2025-60956 | HIGH | 8 | 0.2% | Oct 6, 2025 | Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-007... |
| CVE-2025-57247 | CRITICAL | 9.1 | 0.3% | Oct 6, 2025 | The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa... |
| CVE-2025-36356 | CRITICAL | 9.3 | 0.2% | Oct 6, 2025 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0... |
| CVE-2025-36355 | HIGH | 8.5 | 0.2% | Oct 6, 2025 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0... |
| CVE-2025-36354 | HIGH | 7.3 | 0.3% | Oct 6, 2025 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0... |
| CVE-2025-11341 | CRITICAL | 9.8 | 0.5% | Oct 6, 2025 | A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.... |
| CVE-2025-11339 | HIGH | 8.8 | 0.9% | Oct 6, 2025 | A vulnerability has been found in D-Link DI-7100G C1 up to 20250928. This issue affects the function sub_4BD4F8 of the f... |
| CVE-2025-10363 | CRITICAL | 10 | 0.5% | Oct 6, 2025 | Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote C... |
| CVE-2025-0038 | MEDIUM | 6.6 | 0.1% | Oct 6, 2025 | In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firm... |
| CVE-2025-61765 | MEDIUM | 6.4 | 0.5% | Oct 6, 2025 | python-socketio is a Python implementation of the Socket.IO realtime client and server. A remote code execution vulnerab... |
| CVE-2025-61687 | HIGH | 8.8 | 10.2% | Oct 6, 2025 | Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in ... |
| CVE-2025-61224 | MEDIUM | 6.5 | 1.3% | Oct 6, 2025 | Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitra... |
| CVE-2025-59159 | CRITICAL | 9.6 | 0.2% | Oct 6, 2025 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2025-59152 | HIGH | 7.5 | 0.4% | Oct 6, 2025 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely ... |
| CVE-2025-11338 | CRITICAL | 9.8 | 0.9% | Oct 6, 2025 | A flaw has been found in D-Link DI-7100G C1 up to 20250928. This vulnerability affects the function sub_4C0990 of the fi... |
| CVE-2025-52472 | CRITICAL | 9.3 | 2.2% | Oct 6, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver... |
| CVE-2025-49594 | CRITICAL | 9.2 | 0.5% | Oct 6, 2025 | XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to ver... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now