CVE-2025-0 to CVE-2025-999
257 CVEs with public proof-of-concept exploits.
- CVE-2025-00111 PoCImproper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel…
- CVE-2025-00541 PoCCross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java
- CVE-2025-00722 PoCsMali GPU Kernel Driver allows improper GPU memory processing operations
- CVE-2025-00872 PoCsIn onCreate of UninstallerActivity.java, there is a possible way to uninstall a different user's app due to a missing permission check.…
- CVE-2025-01071 PoCExpedition: OS Command Injection Vulnerability
- CVE-2025-01087 PoCsKEVPAN-OS: Authentication Bypass in the Management Web Interface
- CVE-2025-01171 PoCGlobalProtect App: Local Privilege Escalation (PE) Vulnerability
- CVE-2025-01337 PoCsPAN-OS: Reflected Cross-Site Scripting (XSS) Vulnerability in GlobalProtect Gateway and Portal
- CVE-2025-01681 PoCcode-projects Job Recruitment _feedback_system.php sql injection
- CVE-2025-01711 PoCcode-projects Chat System deleteuser.php sql injection
- CVE-2025-01721 PoCcode-projects Chat System deleteroom.php sql injection
- CVE-2025-01731 PoCSourceCodester Online Eyewear Shop view_order.php sql injection
- CVE-2025-01741 PoCcode-projects Point of Sales and Inventory Management System Parameter search_result2.php sql injection
- CVE-2025-01751 PoCcode-projects Online Shop view.php cross site scripting
- CVE-2025-01761 PoCcode-projects Point of Sales and Inventory Management System add_cart.php sql injection
- CVE-2025-01821 PoCDenial of Service in danswer-ai/danswer
- CVE-2025-01841 PoCServer-Side Request Forgery (SSRF) in langgenius/dify
- CVE-2025-01861 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-01951 PoCcode-projects Point of Sales and Inventory Management System del_product.php sql injection
- CVE-2025-01961 PoCcode-projects Point of Sales and Inventory Management System plist.php sql injection
- CVE-2025-01971 PoCcode-projects Point of Sales and Inventory Management System search.php sql injection
- CVE-2025-01981 PoCcode-projects Point of Sales and Inventory Management System search_result.php sql injection
- CVE-2025-01991 PoCcode-projects Point of Sales and Inventory Management System minus_cart.php sql injection
- CVE-2025-02001 PoCcode-projects Point of Sales and Inventory Management System search_num.php sql injection
- CVE-2025-02011 PoCcode-projects Point of Sales and Inventory Management System update_account.php sql injection
- CVE-2025-02031 PoCcode-projects Student Management System DbFunction.php showSubject1 sql injection
- CVE-2025-02041 PoCcode-projects Online Shoe Store details.php sql injection
- CVE-2025-02051 PoCcode-projects Online Shoe Store details2.php sql injection
- CVE-2025-02061 PoCcode-projects Online Shoe Store index.php access control
- CVE-2025-02071 PoCcode-projects Online Shoe Store login.php sql injection
- CVE-2025-02081 PoCcode-projects Online Shoe Store summary.php sql injection
- CVE-2025-02101 PoCCampcodes School Faculty Scheduling System ajax.php sql injection
- CVE-2025-02111 PoCCampcodes School Faculty Scheduling System index.php file inclusion
- CVE-2025-02121 PoCCampcodes Student Grading System view_students.php sql injection
- CVE-2025-02131 PoCCampcodes Project Management System update_forms.php unrestricted upload
- CVE-2025-02141 PoCTMD Custom Header Menu index.php sql injection
- CVE-2025-02211 PoCIOBit Protected Folder IOCTL pffilter.sys 0x22200c null pointer dereference
- CVE-2025-02221 PoCIObit Protected Folder IOCTL IUProcessFilter.sys 0x8001E004 null pointer dereference
- CVE-2025-02231 PoCIObit Protected Folder IOCTL IURegistryFilter.sys 0x8001E010 null pointer dereference
- CVE-2025-02241 PoCProvision-ISR SH-4050A-2 server.js information disclosure
- CVE-2025-02251 PoCTsinghua Unigroup Electronic Archives System exampleDownload.html path traversal
- CVE-2025-02261 PoCTsinghua Unigroup Electronic Archives System downLoad.html download information disclosure
- CVE-2025-02271 PoCTsinghua Unigroup Electronic Archives System downLoad.html information disclosure
- CVE-2025-02291 PoCcode-projects Travel Management System enquiry.php sql injection
- CVE-2025-02301 PoCcode-projects Responsive Hotel Site print.php sql injection
- CVE-2025-02311 PoCCodezips Gym Management System submit_payments.php sql injection
- CVE-2025-02321 PoCCodezips Blood Bank Management System successadmin.php sql injection
- CVE-2025-02331 PoCCodezips Project Management System course.php sql injection
- CVE-2025-028214 PoCsKEVA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti…
- CVE-2025-02871 PoCCVE-2025-0287
- CVE-2025-02882 PoCsCVE-2025-0288
- CVE-2025-02911 PoCType Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
- CVE-2025-02941 PoCSourceCodester Home Clean Services Management System process.php sql injection
- CVE-2025-02951 PoCcode-projects Online Book Shop booklist.php cross site scripting
- CVE-2025-02961 PoCcode-projects Online Book Shop booklist.php sql injection
- CVE-2025-02971 PoCcode-projects Online Book Shop detail.php sql injection
- CVE-2025-02981 PoCcode-projects Online Book Shop process_login.php sql injection
- CVE-2025-02991 PoCcode-projects Online Book Shop search_result.php sql injection
- CVE-2025-03001 PoCcode-projects Online Book Shop subcat.php sql injection
- CVE-2025-03011 PoCcode-projects Online Book Shop subcat.php cross site scripting
- CVE-2025-03141 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-03161 PoCWP Directorybox Manager <= 2.5 - Authentication Bypass
- CVE-2025-03241 PoCThe VAPIX Device Configuration framework allowed a privilege escalation, enabling a lower-privileged user to gain administrator privileges.
- CVE-2025-03281 PoCKaiYuanTong ECT Platform HTTP POST Request runCode.php command injection
- CVE-2025-03291 PoCAI ChatBot for WordPress – WPBot < 6.2.4 - Admin+ Stored XSS
- CVE-2025-03311 PoCYunzMall HTTP POST Request ResetpwdController.php changePwd password recovery
- CVE-2025-03331 PoCleiyuxi cy-fast listData sql injection
- CVE-2025-03341 PoCleiyuxi cy-fast listData sql injection
- CVE-2025-03351 PoCcode-projects Online Bike Rental System Change Image unrestricted upload
- CVE-2025-03361 PoCCodezips Project Management System teacher.php sql injection
- CVE-2025-03411 PoCCampCodes Computer Laboratory Management System edit unrestricted upload
- CVE-2025-03421 PoCCampCodes Computer Laboratory Management System edit cross site scripting
- CVE-2025-03441 PoCleiyuxi cy-fast listData sql injection
- CVE-2025-03451 PoCleiyuxi cy-fast listData sql injection
- CVE-2025-03461 PoCcode-projects Content Management System Publish News Page publishnews.php unrestricted upload
- CVE-2025-03471 PoCcode-projects Admission Management System Login index.php sql injection
- CVE-2025-03481 PoCCampCodes DepEd Equipment Inventory System add_employee.php cross site scripting
- CVE-2025-03491 PoCTenda AC6 GetParentControlInfo stack-based overflow
- CVE-2025-03621 PoCImproper Restriction of Rendered UI Layers or Frames in GitLab
- CVE-2025-03641 PoCBigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE
- CVE-2025-03681 PoCBanner Garden Plugin for WordPress <= 0.1.3 - Reflected XSS
- CVE-2025-03761 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-03901 PoCGuangzhou Huayi Intelligent Technology Jeewms wmOmNoticeHController.do path traversal
- CVE-2025-03911 PoCGuangzhou Huayi Intelligent Technology Jeewms CgFormBuildController. java saveOrUpdate sql injection
- CVE-2025-03921 PoCGuangzhou Huayi Intelligent Technology Jeewms graphReportController.do datagridGraph sql injection
- CVE-2025-03971 PoCreckcn SPPanAdmin edit cross site scripting
- CVE-2025-03981 PoClongpi1 warehouse Backend updateInport cross site scripting
- CVE-2025-03991 PoCStarSea99 starsea-mall uploadController.java UploadController unrestricted upload
- CVE-2025-04001 PoCStarSea99 starsea-mall update cross site scripting
- CVE-2025-04014 PoCs1902756969 reggie CommonController.java download path traversal
- CVE-2025-04021 PoC1902756969 reggie CommonController.java upload unrestricted upload
- CVE-2025-04031 PoC1902756969 reggie Phone Number Validation sendMsg information disclosure
- CVE-2025-04041 PoCliujianview gymxmjpa CoachController.java CoachController sql injection
- CVE-2025-04051 PoCliujianview gymxmjpa GoodsController.java GoodsDaoImpl sql injection
- CVE-2025-04061 PoCliujianview gymxmjpa SubjectController.java SubjectDaoImpl sql injection
- CVE-2025-04071 PoCliujianview gymxmjpa EquipmentController.java EquipmentDaoImpl sql injection
- CVE-2025-04081 PoCliujianview gymxmjpa LoosController.java LoosDaoImpl sql injection
- CVE-2025-04091 PoCliujianview gymxmjpa MembertypeController.java MembertypeDaoImpl sql injection
- CVE-2025-04101 PoCliujianview gymxmjpa MenberConntroller.java MenberDaoInpl sql injection
- CVE-2025-04116 PoCsKEV7-Zip Mark-of-the-Web Bypass Vulnerability
- CVE-2025-04341 PoCOut of bounds memory access in V8 in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption…
- CVE-2025-04351 PoCInappropriate implementation in Navigation in Google Chrome on Android prior to 132.0.6834.83 allowed a remote attacker to perform UI…
- CVE-2025-04361 PoCInteger overflow in Skia in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2025-04412 PoCsInappropriate implementation in Fenced Frames in Google Chrome prior to 132.0.6834.83 allowed a remote attacker to obtain potentially…
- CVE-2025-04421 PoCInappropriate implementation in Payments in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to engage…
- CVE-2025-04431 PoCInsufficient data validation in Extensions in Google Chrome prior to 132.0.6834.83 allowed a remote attacker who convinced a user to…
- CVE-2025-04601 PoCBlog Botz for Journal Theme blog_add unrestricted upload
- CVE-2025-04611 PoCShanghai Lingdang Information Technology Lingdang CRM index.php path traversal
- CVE-2025-04621 PoCShanghai Lingdang Information Technology Lingdang CRM index.php sql injection
- CVE-2025-04631 PoCShanghai Lingdang Information Technology Lingdang CRM index.php unrestricted upload
- CVE-2025-04651 PoCAquilaCMS categories deserialization
- CVE-2025-04661 PoCSensei LMS < 4.24.4 - Unauthenticated sensei_email/sensei_message Disclosure
- CVE-2025-04711 PoCUnrestricted Upload of File with Dangerous Type vulnerability in PMB platform
- CVE-2025-04721 PoCInformation exposure vulnerability in PMB platform
- CVE-2025-04731 PoCIncomplete Cleanup vulnerability in PMB platform
- CVE-2025-04751 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-04801 PoCwuzhicms config.php test server-side request forgery
- CVE-2025-04811 PoCD-Link DIR-878 HTTP POST Request dllog.cgi information disclosure
- CVE-2025-04821 PoCFanli2012 native-php-cms user_recoverpwd.php default credentials
- CVE-2025-04831 PoCFanli2012 native-php-cms jump.php cross site scripting
- CVE-2025-04841 PoCFanli2012 native-php-cms Backend sysconfig_doedit.php improper authorization
- CVE-2025-04851 PoCFanli2012 native-php-cms sysconfig_doedit.php cross site scripting
- CVE-2025-04861 PoCFanli2012 native-php-cms login.php sql injection
- CVE-2025-04871 PoCFanli2012 native-php-cms cat_edit.php sql injection
- CVE-2025-04881 PoCFanli2012 native-php-cms product_list.php sql injection
- CVE-2025-04891 PoCFanli2012 native-php-cms friendlink_dodel.php sql injection
- CVE-2025-04901 PoCFanli2012 native-php-cms article_dodel.php sql injection
- CVE-2025-04911 PoCFanli2012 native-php-cms cat_dodel.php sql injection
- CVE-2025-04921 PoCD-Link DIR-823X FUN_00412244 null pointer dereference
- CVE-2025-05161 PoCIncorrect Authorization in GitLab
- CVE-2025-05202 PoCsShowDoc < 2.8.7 Unauthenticated File Upload Remote Code Execution
- CVE-2025-05221 PoCLikeBot – Decentralized like-system <= 0.85 - Admin+ Stored XSS via CSRF
- CVE-2025-05271 PoCcode-projects Admission Management System signupconfirm.php sql injection
- CVE-2025-05281 PoCTenda AC8/AC10/AC18 HTTP Request telnet command injection
- CVE-2025-05291 PoCcode-projects Train Ticket Reservation System Login Form stack-based overflow
- CVE-2025-05301 PoCcode-projects Job Recruitment _feedback_system.php cross site scripting
- CVE-2025-05311 PoCcode-projects Chat System leaveroom.php sql injection
- CVE-2025-05321 PoCCodezips Gym Management System new_submit.php sql injection
- CVE-2025-05331 PoC1000 Projects Campaign Management System Platform for Women sc_login.php sql injection
- CVE-2025-05341 PoC1000 Projects Campaign Management System Platform for Women loginnew.php sql injection
- CVE-2025-05351 PoCCodezips Gym Management System edit_mem_submit.php sql injection
- CVE-2025-05361 PoC1000 Projects Attendance Tracking Management System edit_action.php sql injection
- CVE-2025-05371 PoCcode-projects Car Rental Management System manage-pages.php cross site scripting
- CVE-2025-05381 PoCcode-projects Tourism Management System manage-pages.php cross site scripting
- CVE-2025-05401 PoCitsourcecode Tailoring Management System expadd.php sql injection
- CVE-2025-05411 PoCCodezips Gym Management System edit_member.php sql injection
- CVE-2025-05491 PoCAuthentication Bypass Using an Alternate Path or Channel in GitLab
- CVE-2025-05551 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-05581 PoCTDuckCloud tduck-platform QueryProThemeRequest.java QueryProThemeRequest sql injection
- CVE-2025-05591 PoCCampcodes School Management Software Create Id Card Page create-id-card cross site scripting
- CVE-2025-05601 PoCCampCodes School Management Software Photo Gallery Page photo-gallery cross site scripting
- CVE-2025-05611 PoCitsourcecode Farm Management System add-pig.php sql injection
- CVE-2025-05621 PoCCodezips Gym Management System health_status_entry.php sql injection
- CVE-2025-05631 PoCcode-projects Fantasy-Cricket update.php sql injection
- CVE-2025-05641 PoCcode-projects Fantasy-Cricket authenticate.php sql injection
- CVE-2025-05651 PoCZZCMS index.php sql injection
- CVE-2025-05661 PoCTenda AC15 SetDevNetName formSetDevNetName stack-based overflow
- CVE-2025-05751 PoCUnion Bank of India Vyom Rooting Detection protection mechanism
- CVE-2025-05791 PoCShiprocket Module REST API Module restapi sql injection
- CVE-2025-05801 PoCShiprocket Module REST API Module rest_api authorization
- CVE-2025-05811 PoCCampCodes School Management Software Chat History send cross site scripting
- CVE-2025-06051 PoCWeak Authentication in GitLab
- CVE-2025-06131 PoCPhoto Gallery < 1.8.34 - Unauthenticated Stored XSS
- CVE-2025-06251 PoCCampCodes School Management Software Attachment resource injection
- CVE-2025-06271 PoCAI Autotagger < 3.30.0 - Admin+ Stored XSS
- CVE-2025-06291 PoCCoronavirus (COVID-19) Notice Message <= 1.1.2 - Admin+ Stored XSS
- CVE-2025-06391 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-06521 PoCIncorrect Authorization in GitLab
- CVE-2025-06691 PoCBOINC Server Cross-Site Request Forgery
- CVE-2025-06711 PoCEmail Subscribers < 5.7.50 - Admin+ Stored XSS in Template
- CVE-2025-06731 PoCLoop with Unreachable Exit Condition ('Infinite Loop') in GitLab
- CVE-2025-06741 PoCElber Communications Equipment Authentication Bypass Using an Alternate Path or Channel
- CVE-2025-06791 PoCExposure of Private Personal Information to an Unauthorized Actor in GitLab
- CVE-2025-06871 PoCSpiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSS
- CVE-2025-06881 PoCSpiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSS
- CVE-2025-06921 PoCSimple Video Management System <= 1.0.4 - Admin+ Stored XSS
- CVE-2025-06981 PoCJoeyBling bootplus list sql injection
- CVE-2025-06991 PoCJoeyBling bootplus list sql injection
- CVE-2025-07001 PoCJoeyBling bootplus list sql injection
- CVE-2025-07011 PoCJoeyBling bootplus list sql injection
- CVE-2025-07021 PoCJoeyBling bootplus SysFileController.java unrestricted upload
- CVE-2025-07031 PoCJoeyBling bootplus SysFileController.java path traversal
- CVE-2025-07041 PoCJoeyBling bootplus QrCodeController.java qrCode resource consumption
- CVE-2025-07051 PoCJoeyBling bootplus QrCodeController.java qrCode redirect
- CVE-2025-07061 PoCJoeyBling bootplus admin.html cross site scripting
- CVE-2025-07081 PoCfumiao opencms Add Model Management Page addOrUpdate cross site scripting
- CVE-2025-07091 PoCDcat-Admin Roles Page roles cross site scripting
- CVE-2025-07101 PoCCampCodes School Management Software Notice Board Page notice-list cross site scripting
- CVE-2025-07161 PoCAngularJS improper sanitization in SVG '<image>' element
- CVE-2025-07171 PoCSocial Slider Feed < 2.2.9 - Admin+ Stored XSS
- CVE-2025-07181 PoCNested Pages < 3.2.13 - Contributor+ Stored XSS
- CVE-2025-07211 PoCneedyamin image_gallery view.php cross site scripting
- CVE-2025-07221 PoCneedyamin image_gallery Cover Image gallery.php unrestricted upload
- CVE-2025-07301 PoCTP-Link TL-SG108E HTTP GET Request usr_account_set.cgi get request method with sensitive query strings
- CVE-2025-07341 PoCy_project RuoYi Whitelist getBeanName deserialization
- CVE-2025-07511 PoCAxiomatic Bento4 mp42aac ReadBits heap-based overflow
- CVE-2025-07531 PoCAxiomatic Bento4 mp42aac ReadPartial heap-based overflow
- CVE-2025-07651 PoCIncorrect Authorization in GitLab
- CVE-2025-07831 PoCpankajindevops scale API Endpoint access control
- CVE-2025-07841 PoCIntelbras InControl Registered User usuario cleartext transmission
- CVE-2025-07851 PoCESAFENET CDG SysConfig.jsp cross site scripting
- CVE-2025-07861 PoCESAFENET CDG appDetail.jsp sql injection
- CVE-2025-07871 PoCESAFENET CDG appDetail.jsp cross site scripting
- CVE-2025-07881 PoCESAFENET CDG content_top.jsp sql injection
- CVE-2025-07891 PoCESAFENET CDG doneDetail.jsp sql injection
- CVE-2025-07901 PoCESAFENET CDG doneDetail.jsp cross site scripting
- CVE-2025-07911 PoCESAFENET CDG sdDoneDetail.jsp sql injection
- CVE-2025-07921 PoCESAFENET CDG sdTodoDetail.jsp sql injection
- CVE-2025-07931 PoCESAFENET CDG todoDetail.jsp sql injection
- CVE-2025-07941 PoCESAFENET CDG todoDetail.jsp cross site scripting
- CVE-2025-07951 PoCESAFENET CDG todolistjump.jsp cross site scripting
- CVE-2025-07971 PoCMicroWorld eScan Antivirus Quarantine Microworld default permission
- CVE-2025-07981 PoCMicroWorld eScan Antivirus Quarantine rtscanner os command injection
- CVE-2025-08021 PoCSourceCodester Best Employee Management System Administrative Endpoint View_user.php access control
- CVE-2025-08031 PoCCodezips Gym Management System submit_plan_new.php sql injection
- CVE-2025-08061 PoCcode-projects Job Recruitment _call_job_search_ajax.php cross site scripting
- CVE-2025-08111 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-08401 PoCGNU Binutils objdump.c disassemble_bytes stack-based overflow
- CVE-2025-08411 PoCAridius XYZ News loadMore deserialization
- CVE-2025-08421 PoCneedyamin Library Card System Login admin.php sql injection
- CVE-2025-08431 PoCneedyamin Library Card System Admin Panel admindashboard.php sql injection
- CVE-2025-08441 PoCneedyamin Library Card System Registration Page signup.php cross site scripting
- CVE-2025-08461 PoC1000 Projects Employee Task Management System AdminLogin.php sql injection
- CVE-2025-08471 PoC1000 Projects Employee Task Management System Login index.php sql injection
- CVE-2025-08481 PoCTenda A18 HTTP POST Request SetCmdlineRun stack-based overflow
- CVE-2025-08491 PoCCampCodes School Management Software Staff edit-staff improper authorization
- CVE-2025-08511 PoCPath traversal issue in Deep Java Library
- CVE-2025-08684 PoCsRemote Code Execution in DocsGPT
- CVE-2025-08701 PoCAxiomatic Bento4 Ap4DataBuffer.h GetData heap-based overflow
- CVE-2025-08711 PoCMaybecms Add Article index.php cross site scripting
- CVE-2025-08721 PoCitsourcecode Tailoring Management System addpayment.php sql injection
- CVE-2025-08731 PoCitsourcecode Tailoring Management System customeredit.php sql injection
- CVE-2025-08741 PoCcode-projects Simple Plugins Car Rental Management approve.php sql injection
- CVE-2025-08801 PoCCodezips Gym Management System updateplan.php sql injection
- CVE-2025-08811 PoCCodezips Gym Management System saveroutine.php sql injection
- CVE-2025-08821 PoCcode-projects Chat System addnewmember.php sql injection
- CVE-2025-08861 PoCAn incorrect permissions vulnerability was reported in Elliptic Labs Virtual Lock Sensor that could allow a local, authenticated user to…
- CVE-2025-08901 PoC**UNSUPPORTED WHEN ASSIGNED**Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware…
- CVE-2025-09241 PoCWP Activity Log <= 5.2.2 - Unauthenticated Stored Cross-Site Scripting
- CVE-2025-09282 PoCsArbitrary executable upload via authenticated endpoint
- CVE-2025-09341 PoCcode-projects Job Recruitment _call_job_search_ajax.php sql injection
- CVE-2025-09431 PoCitsourcecode Tailoring Management System deldoc.php sql injection
- CVE-2025-09441 PoCitsourcecode Tailoring Management System customerview.php sql injection
- CVE-2025-09451 PoCitsourcecode Tailoring Management System typedelete.php sql injection
- CVE-2025-09461 PoCitsourcecode Tailoring Management System templatedelete.php sql injection
- CVE-2025-09471 PoCitsourcecode Tailoring Management System expview.php sql injection
- CVE-2025-09481 PoCitsourcecode Tailoring Management System incview.php sql injection
- CVE-2025-09491 PoCitsourcecode Tailoring Management System partview.php sql injection
- CVE-2025-09501 PoCitsourcecode Tailoring Management System staffview.php sql injection
- CVE-2025-09611 PoCcode-projects Job Recruitment load_job-details.php cross site scripting
- CVE-2025-09671 PoCcode-projects Chat System add_chatroom.php sql injection
- CVE-2025-09721 PoCZenvia Movidesk New Ticket cross site scripting
- CVE-2025-09731 PoCCmsEasy index.php backAll_action path traversal
- CVE-2025-09741 PoCMaxD Lightning Module deserialization
- CVE-2025-09811 PoCSession Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM GroupEditor.php Description Field
- CVE-2025-09931 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-09941 PoCKEVTrimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization…