VulnSea

Weekly digest

Week 41, 2025 (6–12 Oct)

A busier-than-usual week with 42 new CVEs (recent average about 31). Severity skewed high: 3 critical and 19 high, 52% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. endruntechnologies was the most-affected vendor with 12.

42
New CVEs
3
Critical
3
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 42 published.

CVE-2025-61884High· 7.5CISA KEVPoC
11mo ago

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …

Abyssaloracle · configuratorEPSS 96%via NVD
CVE-2025-11371High· 7.5CISA KEVPoC
11mo ago

Gladinet CentreStack and TrioFox Local File Inclusion Flaw

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been obser…

AbyssalGladinet · CentreStack and TrioFoxEPSS 92%via CVEORG
CVE-2025-60957Critical· 9.9
11mo ago

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitiv…

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitiv…

Midnightendruntechnologies · sonoma_d12_firmwareEPSS 1.2%via NVD
CVE-2025-60965Critical· 9.1
11mo ago

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive in…

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive in…

Midnightendruntechnologies · sonoma_d12_firmwareEPSS 1.2%via NVD
CVE-2025-60964Critical· 9.1
11mo ago

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive in…

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive in…

Midnightendruntechnologies · sonoma_d12_firmwareEPSS 1.2%via NVD
CVE-2025-11561High· 8.8
11mo ago

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems

A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a f…

TwilightEPSS 0.80%via NVD
CVE-2025-61765Medium· 6.4PoC
11mo ago

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server depl…

python-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server deployments

Twilightpython-socketio · python-socketioEPSS 0.48%via OSV
CVE-2025-61773High· 8.1
11mo ago

pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters

pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters

Twilightpyload-ng · pyload-ngEPSS 0.41%via OSV
CVE-2025-60963High· 8.2
11mo ago

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitiv…

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitiv…

Twilightendruntechnologies · sonoma_d12_firmwareEPSS 0.92%via NVD
CVE-2025-60962High· 8.2
11mo ago

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.

Twilightendruntechnologies · sonoma_d12_firmwareEPSS 0.74%via NVD
CVE-2025-60960High· 8.2
11mo ago

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitiv…

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitiv…

Twilightendruntechnologies · sonoma_d12_firmwareEPSS 0.91%via NVD
CVE-2025-60959High· 8.2
11mo ago

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.

Twilightendruntechnologies · sonoma_d12_firmwareEPSS 0.74%via NVD

Most-affected vendors

By CVEs published in the period.