CVE-2025-10000 to CVE-2025-10999
447 CVEs with public proof-of-concept exploits.
- CVE-2025-100041 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-100111 PoCPortabilis i-Educar edit sql injection
- CVE-2025-100121 PoCPortabilis i-Educar educar_historico_escolar_lst.php sql injection
- CVE-2025-100131 PoCPortabilis i-Educar exportacao-para-o-seb access control
- CVE-2025-100141 PoCelunez eladmin Email Address updateEmail updateUserEmail improper authorization
- CVE-2025-100251 PoCPHPGurukul Online Course Registration semester.php sql injection
- CVE-2025-100261 PoCitsourcecode POS Point of Sale System -complex_header.php cross site scripting
- CVE-2025-100271 PoCitsourcecode POS Point of Sale System 2512.php cross site scripting
- CVE-2025-100281 PoCitsourcecode POS Point of Sale System 6776.php cross site scripting
- CVE-2025-100291 PoCitsourcecode POS Point of Sale System complex_header_2.php cross site scripting
- CVE-2025-100301 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-100311 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-100321 PoCCampcodes Grocery Sales and Inventory System index.php cross site scripting
- CVE-2025-100331 PoCitsourcecode Online Discussion Forum admin sql injection
- CVE-2025-100341 PoCD-Link DIR-825 httpd ping6_response.cg get_ping6_app_stat buffer overflow
- CVE-2025-100354 PoCsKEVDeserialization Vulnerability in GoAnywhere MFT's License Servlet
- CVE-2025-100412 PoCsFlex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload
- CVE-2025-100421 PoCQuiz Maker <= 6.7.0.56 - Unauthenticated SQL Injection
- CVE-2025-100462 PoCsELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
- CVE-2025-100621 PoCitsourcecode Student Information Management System login.php sql injection
- CVE-2025-100631 PoCitsourcecode POS Point of Sale System deferred_table.php cross site scripting
- CVE-2025-100641 PoCitsourcecode POS Point of Sale System dom_data_two_headers.php cross site scripting
- CVE-2025-100651 PoCitsourcecode POS Point of Sale System dom_data_th.php cross site scripting
- CVE-2025-100661 PoCitsourcecode POS Point of Sale System dymanic_table.php cross site scripting
- CVE-2025-100671 PoCitsourcecode POS Point of Sale System empty_table.php cross site scripting
- CVE-2025-100681 PoCitsourcecode Online Discussion Forum add_views.php sql injection
- CVE-2025-100701 PoCPortabilis i-Educar enturmacao-em-lote access control
- CVE-2025-100711 PoCPortabilis i-Educar cancelar-enturmacao-em-lote access control
- CVE-2025-100721 PoCPortabilis i-Educar enturmar access control
- CVE-2025-100731 PoCPortabilis i-Educar turma improper authorization
- CVE-2025-100741 PoCPortabilis i-Educar tipos cross site scripting
- CVE-2025-100751 PoCSourceCodester Online Polling System manage-profile.php cross site scripting
- CVE-2025-100761 PoCSourceCodester Online Polling System manage-profile.php sql injection
- CVE-2025-100771 PoCSourceCodester Online Polling System registeracc.php sql injection
- CVE-2025-100781 PoCSourceCodester Online Polling System candidates.php sql injection
- CVE-2025-100791 PoCPHPGurukul Small CRM get-quote.php sql injection
- CVE-2025-100801 PoCrunning-elephant Datart API AESUtil.java getTokensecret hard-coded key
- CVE-2025-100811 PoCSourceCodester Pet Management System profile.php unrestricted upload
- CVE-2025-100821 PoCSourceCodester Online Polling System manage-admins.php sql injection
- CVE-2025-100831 PoCSourceCodester Pet Grooming Management Software profile.php unrestricted upload
- CVE-2025-100841 PoCelunez eladmin SysLogController 1 queryErrorLogDetail improper authorization
- CVE-2025-100851 PoCSourceCodester Pet Grooming Management Software manage_website.php unrestricted upload
- CVE-2025-100861 PoCfuyang_lipengjun platform AdPositionController queryAll improper authorization
- CVE-2025-100871 PoCSourceCodester Pet Grooming Management Software profit_report.php sql injection
- CVE-2025-100881 PoCSourceCodester Time Tracker index.html cross site scripting
- CVE-2025-100902 PoCsJinher OA GetTreeDate.aspx sql injection
- CVE-2025-100911 PoCJinher OA XML Type xml external entity reference
- CVE-2025-100921 PoCJinher OA XML Type xml external entity reference
- CVE-2025-100931 PoCD-Link DIR-852 Device Configuration getcfg.php phpcgi_main information disclosure
- CVE-2025-100941 PoCImproper Validation of Specified Quantity in Input in GitLab
- CVE-2025-100961 PoCSimStudioAI sim route.ts server-side request forgery
- CVE-2025-100971 PoCSimStudioAI sim route.ts code injection
- CVE-2025-100981 PoCPHPGurukul User Management System edit-user-profile.php sql injection
- CVE-2025-100991 PoCPortabilis i-Educar Editar usuário educar_usuario_cad.php cross site scripting
- CVE-2025-101001 PoCSourceCodester Simple Forum Discussion System admin_class.php sql injection
- CVE-2025-101021 PoCcode-projects Online Event Judging System index.php sql injection
- CVE-2025-101031 PoCcode-projects Online Event Judging System home.php sql injection
- CVE-2025-101041 PoCcode-projects Online Event Judging System review_search.php sql injection
- CVE-2025-101051 PoCyanyutao0402 ChanCMS search sql injection
- CVE-2025-101061 PoCyanyutao0402 ChanCMS search sql injection
- CVE-2025-101081 PoCCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-101091 PoCCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-101101 PoCChanCMS search sql injection
- CVE-2025-101111 PoCitsourcecode Student Information Management System index.php sql injection
- CVE-2025-101121 PoCitsourcecode Student Information Management System index.php sql injection
- CVE-2025-101131 PoCitsourcecode Student Information Management System index.php sql injection
- CVE-2025-101141 PoCPHPGurukul Small CRM profile.php sql injection
- CVE-2025-101151 PoCSiempreCMS user_search_ajax.php sql injection
- CVE-2025-101161 PoCSiempreCMS file_upload.php unrestricted upload
- CVE-2025-101171 PoCSourceCodester Simple To-Do List System Add New Task fetch_tasks.php cross site scripting
- CVE-2025-101181 PoCitsourcecode E-Logbook with Health Monitoring System for COVID-19 login.php sql injection
- CVE-2025-101201 PoCTenda AC20 GetParentControlInfo strcpy buffer overflow
- CVE-2025-101211 PoCuverif kami_list addbatch sql injection
- CVE-2025-101221 PoCMaccms10 Database.php rep sql injection
- CVE-2025-101231 PoCD-Link DIR-823X set_static_leases sub_415028 command injection
- CVE-2025-101241 PoCBooking Manager < 2.1.15 - Contributor+ Booking Deletion
- CVE-2025-101552 PoCsPickleScan Security Bypass Using Misleading File Extension
- CVE-2025-101564 PoCsPickleScan Security Bypass via Bad CRC in ZIP Archive
- CVE-2025-101573 PoCsPickleScan Bypasses Unsafe Globals Check Using Submodule Imports
- CVE-2025-101611 PoCAuthentication Bypass in Turkguven's Perfektive
- CVE-2025-101624 PoCsOrderConvo < 14 - Unauthenticated Arbitrary File Read
- CVE-2025-101641 PoClmsys sglang update_weights_from_tensor main deserialization
- CVE-2025-101691 PoCUTT 1200GW ConfigWirelessBase buffer overflow
- CVE-2025-101701 PoCUTT 1200GW formApLbConfig sub_4B48F8 buffer overflow
- CVE-2025-101711 PoCUTT 1250GW formConfigApConfTemp sub_453DC buffer overflow
- CVE-2025-101721 PoCUTT 750W formPictureUrl buffer overflow
- CVE-2025-101844 PoCsOnePlus OxygenOS Telephony provider permission bypass
- CVE-2025-101951 PoCSeismic App com.seismic.doccenter AndroidManifest.xml improper export of android application components
- CVE-2025-101971 PoCHJSoft HCM Human Resources Management System downlawbase sql injection
- CVE-2025-102041 PoCUnauth Admin Reset Password on AC Smart II
- CVE-2025-102091 PoCPapermerge DMS Authorization Token improper authorization
- CVE-2025-102102 PoCsyanyutao0402 ChanCMS Api.js search sql injection
- CVE-2025-102112 PoCsyanyutao0402 ChanCMS getArticle CollectController server-side request forgery
- CVE-2025-102151 PoCDLL search path hijacking vulnerability
- CVE-2025-102181 PoClostvip-com ruoyi-go Background Management SysRoleDao.go SelectListPage sql injection
- CVE-2025-102291 PoCFreshwork logout redirect
- CVE-2025-102302 PoCsSamba: command injection in wins server hook script
- CVE-2025-102321 PoC299ko FileManagerAPIController.php delete path traversal
- CVE-2025-102331 PoCkalcaddle kodbox editor.class.php fileSave path traversal
- CVE-2025-102341 PoCScada-LTS Data Point Edit data_point_edit.shtm cross site scripting
- CVE-2025-102351 PoCScada-LTS Reports reports.shtm cross site scripting
- CVE-2025-102361 PoCbinary-husky gpt_academic LaTeX File latex_toolbox.py merge_tex_files_ path traversal
- CVE-2025-102451 PoCDisplay Painéis TGA Galeria rename path traversal
- CVE-2025-102471 PoCJEPaaS Filter doFilterInternal access control
- CVE-2025-102501 PoCDJI Mavic Spark/Mavic Air/Mavic Mini Telemetry Channel hard-coded key
- CVE-2025-102511 PoCFoxCMS Images.php batchCope sql injection
- CVE-2025-102531 PoCopenDCIM SVG File uploadifive.php cross site scripting
- CVE-2025-102541 PoCAscensio System SIA OnlyOffice SVG Image Messages.aspx cross site scripting
- CVE-2025-102551 PoCAscensio System SIA OnlyOffice Comment Messages.aspx cross site scripting
- CVE-2025-102681 PoCPrintcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenticated Folder Content Disclosure via Path Traversal
- CVE-2025-102711 PoCerjinzhi 10OA finder cross site scripting
- CVE-2025-102721 PoCerjinzhi 10OA catalogue cross site scripting
- CVE-2025-102731 PoCerjinzhi 10OA file.aspx path traversal
- CVE-2025-102741 PoCerjinzhi 10OA item cross site scripting
- CVE-2025-102751 PoCYunaiV yudao-cloud transfer improper authorization
- CVE-2025-102761 PoCYunaiV ruoyi-vue-pro transfer improper authorization
- CVE-2025-102771 PoCYunaiV yudao-cloud submit improper authorization
- CVE-2025-102781 PoCYunaiV ruoyi-vue-pro transfer improper authorization
- CVE-2025-102871 PoCroncoo roncoo-pay orderQuery direct request
- CVE-2025-102881 PoCroncoo roncoo-pay list improper authentication
- CVE-2025-102911 PoClinlinjava litemall cancel WxAftersaleController improper authorization
- CVE-2025-103181 PoCJeecgBoot WebSocket Message sendWebSocketMsg improper authorization
- CVE-2025-103191 PoCJeecgBoot Tenant Log Export exportLog improper authorization
- CVE-2025-103201 PoCiteachyou Dreamer CMS updatePwd weak password
- CVE-2025-103211 PoCWavlink WL-WN578W2 live_online.shtml information disclosure
- CVE-2025-103221 PoCWavlink WL-WN578W2 sysinit.html password recovery
- CVE-2025-103231 PoCWavlink WL-WN578W2 wizard_rep.shtml sub_409184 command injection
- CVE-2025-103241 PoCWavlink WL-WN578W2 firewall.cgi sub_401C5C command injection
- CVE-2025-103251 PoCWavlink WL-WN578W2 login.cgi sub_401BA4 command injection
- CVE-2025-103261 PoCMiczFlor RPi-Jukebox-RFID single.php os command injection
- CVE-2025-103272 PoCsMiczFlor RPi-Jukebox-RFID shuffle.php os command injection
- CVE-2025-103281 PoCMiczFlor RPi-Jukebox-RFID playsinglefile.php os command injection
- CVE-2025-103291 PoCcdevroe unmark Marks.php server-side request forgery
- CVE-2025-103301 PoCcdevroe unmark searchform.php cross site scripting
- CVE-2025-103311 PoCcdevroe unmark Marks.php cross site scripting
- CVE-2025-103321 PoCcdevroe unmark info.php cross site scripting
- CVE-2025-103401 PoCWhatCD Gazelle Commit Message change_log.php cross site scripting
- CVE-2025-103512 PoCsSQL injection vulnerability in Melis Platform
- CVE-2025-103521 PoCMissing Authorization vulnerability in Melis Platform
- CVE-2025-103533 PoCsMissing Authorization vulnerability in Melis Platform
- CVE-2025-103571 PoCSimple SEO < 2.0.32 - Contributor+ Stored XSS
- CVE-2025-103581 PoCWavlink WL-WN578W2 wireless.cgi sub_404850 os command injection
- CVE-2025-103591 PoCWavlink WL-WN578W2 wireless.cgi sub_404DBC os command injection
- CVE-2025-103661 PoCMiczFlor RPi-Jukebox-RFID inc.setWlanIpMail.php cross site scripting
- CVE-2025-103671 PoCMiczFlor RPi-Jukebox-RFID cardEdit.php cross site scripting
- CVE-2025-103681 PoCMiczFlor RPi-Jukebox-RFID manageFilesFolders.php cross site scripting
- CVE-2025-103691 PoCMiczFlor RPi-Jukebox-RFID cardRegisterNew.php cross site scripting
- CVE-2025-103702 PoCsMiczFlor RPi-Jukebox-RFID userScripts.php cross site scripting
- CVE-2025-103711 PoCeCharge Hardy Barth Salia PLCC api.php unrestricted upload
- CVE-2025-103721 PoCPortabilis i-Educar educar_modulo_cad.php cross site scripting
- CVE-2025-103731 PoCPortabilis i-Educar educar_turma_tipo_cad.php cross site scripting
- CVE-2025-103741 PoCShenzhen Sixun Business Management System OperatorStop improper authorization
- CVE-2025-103772 PoCsSystem Dashboard <= 2.8.20 - Cross-Site Request Forgery
- CVE-2025-103841 PoCyangzongzhuan RuoYi Role cancelAll improper authorization
- CVE-2025-103851 PoCMercury KM08-708H GiGA WiFi Wave2 mcr_setSysAdm sub_450B2C buffer overflow
- CVE-2025-103861 PoCYida ECMS Consulting Enterprise Management System POST Request login.do cross site scripting
- CVE-2025-103871 PoCcodesiddhant Jasmin Ransomware handshake.php sql injection
- CVE-2025-103881 PoCSelleo Mentingo Create New Course Basic Settings enroll-course cross site scripting
- CVE-2025-103891 PoCCRMEB Administrator Password SystemAdminServices.php save improper authorization
- CVE-2025-103901 PoCCRMEB UserAddressServices.php editAddress improper authorization
- CVE-2025-103911 PoCCRMEB OutAccountServices.php testOutUrl server-side request forgery
- CVE-2025-103921 PoCMercury KM08-708H GiGA WiFi Wave2 HTTP Header stack-based overflow
- CVE-2025-103931 PoCmiurla morphic HTTP Status Code 3xx advanced-search fetchHtml server-side request forgery
- CVE-2025-103941 PoCfcba_zzm ics-park Smart Park Management System Scheduled Task JobController.java code injection
- CVE-2025-103961 PoCSourceCodester Pet Grooming Management Software edit_role.php sql injection
- CVE-2025-103971 PoCMagicblack MacCMS API server-side request forgery
- CVE-2025-103981 PoCfcba_zzm ics-park Smart Park Management System FileUploadUtils.java unrestricted upload
- CVE-2025-104001 PoCSourceCodester Food Ordering Management System ticket-message.php sql injection
- CVE-2025-104011 PoCD-Link DIR-823x diag_ping command injection
- CVE-2025-104021 PoCPHPGurukul Beauty Parlour Management System readenq.php sql injection
- CVE-2025-104031 PoCPHPGurukul Beauty Parlour Management System view-enquiry.php sql injection
- CVE-2025-104041 PoCitsourcecode Baptism Information Management System rptbaptismal.php sql injection
- CVE-2025-104051 PoCitsourcecode Baptism Information Management System listbaptism.php sql injection
- CVE-2025-104061 PoCBlindMatrix e-Commerce < 3.1 - Contributor+ LFI
- CVE-2025-104071 PoCSourceCodester Student Grading System view_user.php sql injection
- CVE-2025-104081 PoCSourceCodester Student Grading System edit_user.php sql injection
- CVE-2025-104091 PoCSourceCodester Student Grading System rms.php sql injection
- CVE-2025-104111 PoCitsourcecode E-Logbook with Health Monitoring System for COVID-19 POST Request check_profile.php cross site scripting
- CVE-2025-104131 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-104141 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-104151 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-104161 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-104171 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-104181 PoCSourceCodester Student Grading System view_students.php sql injection
- CVE-2025-104191 PoCSourceCodester Student Grading System del_promote.php sql injection
- CVE-2025-104201 PoCSourceCodester Student Grading System form137.php sql injection
- CVE-2025-104211 PoCSourceCodester Student Grading System update_account.php sql injection
- CVE-2025-104221 PoCnewbee-mall Order Status paySuccess improper authorization
- CVE-2025-104231 PoCnewbee-mall kaptcha mallKaptcha Captcha
- CVE-2025-104241 PoC1000projects Online Student Project Report Submission and Evaluation System faculty_controller.php unrestricted upload
- CVE-2025-104251 PoC1000projects Online Student Project Report Submission and Evaluation System student_controller.php unrestricted upload
- CVE-2025-104261 PoCitsourcecode Online Laundry Management System login.php sql injection
- CVE-2025-104271 PoCSourceCodester Pet Grooming Management Software user.php unrestricted upload
- CVE-2025-104281 PoCSourceCodester Pet Grooming Management Software Setting seo_setting.php unrestricted upload
- CVE-2025-104291 PoCSourceCodester Pet Grooming Management Software ajax_product.php sql injection
- CVE-2025-104301 PoCSourceCodester Pet Grooming Management Software barcode.php sql injection
- CVE-2025-104311 PoCSourceCodester Pet Grooming Management Software ajax_represent.php sql injection
- CVE-2025-104321 PoCTenda AC1206 HTTP Request AdvSetMacMtuWa check_param_changed stack-based overflow
- CVE-2025-104331 PoC1Panel-dev MaxKB debug deserialization
- CVE-2025-104341 PoCIbuyuCMS Add Article article.php cross site scripting
- CVE-2025-104351 PoCCampcodes Computer Sales and Inventory System cust_edit1.php sql injection
- CVE-2025-104361 PoCCampcodes Computer Sales and Inventory System sup_searchfrm.php sql injection
- CVE-2025-104401 PoCD-Link DI-8100/DI-8100G/DI-8200/DI-8200G/DI-8003/DI-8003G jhttpd usb_paswd.asp sub_4621DC os command injection
- CVE-2025-104411 PoCD-Link DI-8100G/DI-8200G/DI-8003G jhttpd version_upgrade.asp sub_433F7C os command injection
- CVE-2025-104421 PoCTenda AC9/AC15 exeCommand formexeCommand os command injection
- CVE-2025-104431 PoCTenda AC9/AC15 exeCommand formexeCommand buffer overflow
- CVE-2025-104441 PoCCampcodes Online Job Finder System advancesearch.php sql injection
- CVE-2025-104451 PoCCampcodes Computer Sales and Inventory System us_transac.php sql injection
- CVE-2025-104461 PoCCampcodes Computer Sales and Inventory System cust_searchfrm.php sql injection
- CVE-2025-104471 PoCCampcodes Online Job Finder System applicationform.php unrestricted upload
- CVE-2025-104481 PoCCampcodes Online Job Finder System index.php sql injection
- CVE-2025-104591 PoCPHPGurukul Beauty Parlour Management System all-appointment.php sql injection
- CVE-2025-104711 PoCZKEACMS MediaController.cs Proxy server-side request forgery
- CVE-2025-104721 PoCharry0703 MoneyPrinterTurbo URL video.py stream_video path traversal
- CVE-2025-104731 PoCyangzongzhuan RuoYi Blacklist SqlUtil.java filterKeyword sql injection
- CVE-2025-104751 PoCSpyShelter IOCTL SpyShelter.sys denial of service
- CVE-2025-104771 PoCkidaze CourseSelectionSystem eligibility.php sql injection
- CVE-2025-104791 PoCSourceCodester Online Student File Management System index.php sql injection
- CVE-2025-104801 PoCSourceCodester Online Student File Management System save_file.php unrestricted upload
- CVE-2025-104811 PoCSourceCodester Online Student File Management System remove_file.php sql injection
- CVE-2025-104821 PoCSourceCodester Online Student File Management System index.php sql injection
- CVE-2025-104831 PoCSourceCodester Online Student File Management System save_user.php sql injection
- CVE-2025-104851 PoCpojoin h3blog HTTP Header login ppt_log cross site scripting
- CVE-2025-104931 PoCChained Quiz <= 1.3.5 - Unauthenticated Insecure Direct Object Reference via Cookie
- CVE-2025-104971 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-105621 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-105631 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-105641 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-105651 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-105661 PoCCampcodes Grocery Sales and Inventory System index.php cross site scripting
- CVE-2025-105671 PoCFunnelKit < 3.12.0.1 - Reflected XSS
- CVE-2025-105691 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-105761 PoCSound Research SECOMNService Escalation of Privilege
- CVE-2025-105841 PoCPortabilis i-Educar educar_calendario_anotacao_cad.php cross site scripting
- CVE-2025-105851 PoCKEVType confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2025-105901 PoCPortabilis i-Educar educar_usuario_det.php cross site scripting
- CVE-2025-105911 PoCPortabilis i-Educar Editar Função educar_funcao_cad.php cross site scripting
- CVE-2025-105921 PoCitsourcecode Online Public Access Catalog OPAC POST Parameter mysearch.php sql injection
- CVE-2025-105931 PoCSourceCodester Online Student File Management System update_student.php sql injection
- CVE-2025-105941 PoCSourceCodester Online Student File Management System delete_student.php sql injection
- CVE-2025-105951 PoCSourceCodester Online Student File Management System delete_user.php sql injection
- CVE-2025-105961 PoCSourceCodester Online Exam Form Submission index.php sql injection
- CVE-2025-105971 PoCkidaze CourseSelectionSystem COUNT2.php sql injection
- CVE-2025-105981 PoCSourceCodester Pet Grooming Management Software search_product.php sql injection
- CVE-2025-105991 PoCitsourcecode Web-Based Internet Laboratory Management System login.php AuthenticateUser sql injection
- CVE-2025-106001 PoCSourceCodester Online Exam Form Submission register.php unrestricted upload
- CVE-2025-106011 PoCSourceCodester Online Exam Form Submission index.php sql injection
- CVE-2025-106021 PoCSourceCodester Online Exam Form Submission delete_s1.php sql injection
- CVE-2025-106031 PoCPHPGurukul Online Discussion Forum search_result.php sql injection
- CVE-2025-106041 PoCPHPGurukul Online Discussion Forum edit_member.php sql injection
- CVE-2025-106051 PoCPortabilis i-Educar agenda_preferencias.php cross site scripting
- CVE-2025-106061 PoCPortabilis i-Educar ConfiguracaoMovimentoGeral cross site scripting
- CVE-2025-106071 PoCPortabilis i-Educar diarioApi information disclosure
- CVE-2025-106081 PoCPortabilis i-Educar enrollment-history access control
- CVE-2025-106131 PoCitsourcecode Student Information System leveledit1.php sql injection
- CVE-2025-106141 PoCitsourcecode E-Logbook with Health Monitoring System for COVID-19 print_reports_prev.php cross site scripting
- CVE-2025-106151 PoCitsourcecode E-Commerce Website products.php unrestricted upload
- CVE-2025-106161 PoCitsourcecode E-Commerce Website users.php unrestricted upload
- CVE-2025-106171 PoCSourceCodester Online Polling System positions.php sql injection
- CVE-2025-106181 PoCitsourcecode Online Clinic Management System transact.php sql injection
- CVE-2025-106191 PoCsequa-ai sequa-mcp OAuth Server Discovery node-oauth-client-provider.ts redirectToAuthorization os command injection
- CVE-2025-106201 PoCitsourcecode Online Clinic Management System editp2.php sql injection
- CVE-2025-106211 PoCSourceCodester Hotel Reservation System editroomimage.php sql injection
- CVE-2025-106231 PoCSourceCodester Hotel Reservation System deleteuser.php sql injection
- CVE-2025-106241 PoCPHPGurukul User Management System login.php sql injection
- CVE-2025-106251 PoCSourceCodester Online Exam Form Submission dashboard.php sql injection
- CVE-2025-106261 PoCSourceCodester Online Exam Form Submission update_s3.php sql injection
- CVE-2025-106271 PoCSourceCodester Online Exam Form Submission delete_user.php sql injection
- CVE-2025-106281 PoCD-Link DIR-852 Web Management hedwig.cgi command injection
- CVE-2025-106291 PoCD-Link DIR-852 Simple Service Discovery Protocol Service cgibin ssdpcgi_main command injection
- CVE-2025-106311 PoCitsourcecode Online Petshop Management System Available Products addcnp.php cross site scripting
- CVE-2025-106321 PoCitsourcecode Online Petshop Management System Admin Dashboard availableframe.php cross site scripting
- CVE-2025-106341 PoCD-Link DIR-823X Environment Variable goahead sub_412E7C command injection
- CVE-2025-106351 PoCFind Me On <= 2.0.9.1 - Subscriber+ SQL Injection
- CVE-2025-106361 PoCNS Maintenance Mode for WP <= 1.3.1 - Admin+ Stored XSS
- CVE-2025-106381 PoCNS Maintenance Mode for WP <= 1.3.1 - Unauthenticated Subscribers Export
- CVE-2025-106621 PoCSeaCMS admin_members.php sql injection
- CVE-2025-106631 PoCPHPGurukul Online Course Registration my-profile.php sql injection
- CVE-2025-106641 PoCPHPGurukul Small CRM create-ticket.php sql injection
- CVE-2025-106651 PoCkidaze CourseSelectionSystem COUNT3s3.php sql injection
- CVE-2025-106662 PoCsD-Link DIR-825 apply.cgi sub_4106d4 buffer overflow
- CVE-2025-106671 PoCitsourcecode Online Discussion Forum compose_msg.php sql injection
- CVE-2025-106681 PoCitsourcecode Online Discussion Forum compose_msg_admin.php sql injection
- CVE-2025-106691 PoCAirsonic-Advanced Playlist Upload unrestricted upload
- CVE-2025-106701 PoCitsourcecode E-Logbook with Health Monitoring System for COVID-19 check_profile.php sql injection
- CVE-2025-106711 PoCyouth-is-as-pale-as-poetry e-learning JWT Token JwtUtils.java encryptSecret random values
- CVE-2025-106721 PoCwhuan132 AIBattery com.collweb.AIBatteryHelper BatteryXPCService.swift missing authentication
- CVE-2025-106731 PoCitsourcecode Student Information Management System index.php sql injection
- CVE-2025-106741 PoCfuyang_lipengjun platform queryAll AttributeCategoryController improper authorization
- CVE-2025-106751 PoCfuyang_lipengjun platform queryAll AttributeController improper authorization
- CVE-2025-106761 PoCfuyang_lipengjun platform queryAll BrandController improper authorization
- CVE-2025-106841 PoCConstruction Light < 1.6.8 - Subscriber+ Arbitrary Plugin Activation
- CVE-2025-106861 PoCCreta Testimonial Showcase < 1.2.4 - Editor+ Local File Inclusion
- CVE-2025-106871 PoCSourceCodester Responsive E-Learning System add_teacher.php sql injection
- CVE-2025-106881 PoCSourceCodester Pet Grooming Management Software paid.php sql injection
- CVE-2025-106891 PoCD-Link DIR-645 soap.cgi soapcgi_main command injection
- CVE-2025-107071 PoCJeecgBoot sendMsg improper authorization
- CVE-2025-107081 PoCFour-Faith Water Conservancy Informatization Platform historyDownload.do;usrlogout.do path traversal
- CVE-2025-107091 PoCFour-Faith Water Conservancy Informatization Platform historyDownload.do;otheruserLogin.do;getfile path traversal
- CVE-2025-107101 PoC07FLYCMS/07FLY-CMS/07FlyCRM index.php cross site scripting
- CVE-2025-107111 PoC07FLYCMS/07FLY-CMS/07FlyCRM Login cross site scripting
- CVE-2025-107121 PoC07FLYCMS/07FLY-CMS/07FlyCRM login sql injection
- CVE-2025-107151 PoCAPEUni PTE Exam Practice App com.ape_edication AndroidManifest.xml improper export of android application components
- CVE-2025-107161 PoCCreality Cloud App com.cxsw.sdprinter AndroidManifest.xml improper export of android application components
- CVE-2025-107171 PoCintsig CamScanner App com.intsig.camscanner AndroidManifest.xml improper export of android application components
- CVE-2025-107181 PoCOoma Office Business Phone App com.ooma.office2 improper export of android application components
- CVE-2025-107203 PoCsWP Private Content Plus <= 3.6.2 - Password Protection Bypass
- CVE-2025-107211 PoCWebull Investing & Trading App AndroidManifest.xml improper export of android application components
- CVE-2025-107221 PoCSKTLab Mukbee App com.dw.android.mukbee AndroidManifest.xml improper export of android application components
- CVE-2025-107231 PoCPixelYourSite < 11.1.2 - Admin+ LFI
- CVE-2025-107411 PoCSelleo Mentingo Profile Picture unrestricted upload
- CVE-2025-107551 PoCSelleo Mentingo Content-Type unrestricted upload
- CVE-2025-107561 PoCUTT HiPER 840G getOneApConfTempEntry buffer overflow
- CVE-2025-107571 PoCUTT 1200GW formConfigDnsFilterGlobal buffer overflow
- CVE-2025-107581 PoChtmly Custom Field post cross site scripting
- CVE-2025-107591 PoCWebkul QloApps CSRF Token authorization
- CVE-2025-107601 PoCHarness lookup_repo.go LookupRepo server-side request forgery
- CVE-2025-107611 PoCHarness Login Endpoint login excessive authentication
- CVE-2025-107621 PoCkuaifan DooTask UsersController.php sql injection
- CVE-2025-107631 PoCacademico-sis academico Profile Picture edit-photo unrestricted upload
- CVE-2025-107641 PoCSeriaWei ZKEACMS Event Action System PendingTaskController.cs Edit server-side request forgery
- CVE-2025-107651 PoCSeriaWei ZKEACMS SEOSuggestions ZKEACMS.SEOSuggestions.dll server-side request forgery
- CVE-2025-107661 PoCSeriaWei ZKEACMS EventViewerController.cs Download path traversal
- CVE-2025-107671 PoCCosmodiumCS OnlyRAT Configuration File main.py remote_download os command injection
- CVE-2025-107681 PoCh2oai h2o-3 IBMDB2 JDBC Driver ImportSQLTable deserialization
- CVE-2025-107691 PoCh2oai h2o-3 H2 JDBC Driver ImportSQLTable deserialization
- CVE-2025-107701 PoCjeecgboot JimuReport MySQL JDBC testConnection deserialization
- CVE-2025-107711 PoCjeecgboot JimuReport DB2 JDBC testConnection deserialization
- CVE-2025-107731 PoCB-Link BL-AC2100 Web Management set_delshrpath_cfg delshrpath stack-based overflow
- CVE-2025-107741 PoCRuijie 6000-E10 sub_commit.php os command injection
- CVE-2025-107751 PoCWavlink WL-NU516U1 login.cgi sub_4012A0 os command injection
- CVE-2025-107761 PoCLionCoders SalePro POS Login cleartext transmission
- CVE-2025-107791 PoCD-Link DCS-935L HNAP1 sub_402280 stack-based overflow
- CVE-2025-107801 PoCCodeAstro Simple Pharmacy Management view.php sql injection
- CVE-2025-107811 PoCCampcodes Online Learning Management System edit_class.php sql injection
- CVE-2025-107821 PoCCampcodes Online Learning Management System class.php sql injection
- CVE-2025-107831 PoCCampcodes Online Learning Management System add_subject.php sql injection
- CVE-2025-107841 PoCCampcodes Online Learning Management System edit_subject.php sql injection
- CVE-2025-107851 PoCCampcodes Grocery Sales and Inventory System manage_user.php sql injection
- CVE-2025-107861 PoCCampcodes Grocery Sales and Inventory System ajax.php sql injection
- CVE-2025-107871 PoCMuYuCMS Add Fiend Link index.html server-side request forgery
- CVE-2025-107881 PoCSourceCodester Online Hotel Reservation System deleteroominventory.php sql injection
- CVE-2025-107891 PoCSourceCodester Online Hotel Reservation System deleteslide.php sql injection
- CVE-2025-107901 PoCSourceCodester Simple Forum Discussion System ajax.php sql injection
- CVE-2025-107911 PoCcode-projects Online Bidding System index.php sql injection
- CVE-2025-107921 PoCD-Link DIR-513 formWPS buffer overflow
- CVE-2025-107931 PoCcode-projects E-Commerce Website admin_account_delete.php sql injection
- CVE-2025-107941 PoCPHPGurukul Car Rental Project search.php cross site scripting
- CVE-2025-107951 PoCcode-projects Online Bidding System bidupdate.php sql injection
- CVE-2025-107961 PoCcode-projects Hostel Management System login.php sql injection
- CVE-2025-107971 PoCcode-projects Hostel Management System index.php sql injection
- CVE-2025-107981 PoCcode-projects Hostel Management System index.php sql injection
- CVE-2025-107991 PoCcode-projects Hostel Management System index.php sql injection
- CVE-2025-108001 PoCitsourcecode Online Discussion Forum index.php sql injection
- CVE-2025-108011 PoCSourceCodester Pet Grooming Management Software edit_tax.php sql injection
- CVE-2025-108021 PoCcode-projects Online Bidding System remove.php sql injection
- CVE-2025-108031 PoCTenda AC23 HTTP POST Request SetPptpServerCfg sscanf buffer overflow
- CVE-2025-108041 PoCCampcodes Online Beauty Parlor Management System add-customer.php sql injection
- CVE-2025-108051 PoCCampcodes Online Beauty Parlor Management System add-services.php sql injection
- CVE-2025-108061 PoCCampcodes Online Beauty Parlor Management System bwdates-reports-details.php sql injection
- CVE-2025-108071 PoCCampcodes Online Beauty Parlor Management System edit-customer-detailed.php sql injection
- CVE-2025-108081 PoCCampcodes Farm Management System uploadProduct.php sql injection
- CVE-2025-108091 PoCCampcodes Online Learning Management System department.php sql injection
- CVE-2025-108101 PoCCampcodes Online Learning Management System edit_user.php sql injection
- CVE-2025-108111 PoCcode-projects Hostel Management System index.php sql injection
- CVE-2025-108121 PoCcode-projects Hostel Management System index.php sql injection
- CVE-2025-108131 PoCcode-projects Hostel Management System index.php sql injection
- CVE-2025-108141 PoCD-Link DIR-823X goahead command injection
- CVE-2025-108151 PoCTenda AC20 HTTP POST Request SetPptpServerCfg strcpy buffer overflow
- CVE-2025-108161 PoCJinher OA XML text xml external entity reference
- CVE-2025-108171 PoCCampcodes Online Learning Management System admin_user.php sql injection
- CVE-2025-108191 PoCfuyang_lipengjun platform queryAll UserCouponController improper authorization
- CVE-2025-108201 PoCfuyang_lipengjun platform queryAll TopicController improper authorization
- CVE-2025-108211 PoCfuyang_lipengjun platform queryAll TopicCategoryController improper authorization
- CVE-2025-108221 PoCfuyang_lipengjun platform queryAll SysSmsLogController improper authorization
- CVE-2025-108231 PoCaxboe fio options.c str_buffer_pattern_cb null pointer dereference
- CVE-2025-108241 PoCaxboe fio init.c __parse_jobs_ini use after free
- CVE-2025-108251 PoCCampcodes Online Beauty Parlor Management System view-appointment.php sql injection
- CVE-2025-108261 PoCCampcodes Online Beauty Parlor Management System sales-reports-detail.php sql injection
- CVE-2025-108271 PoCPHPJabbers Restaurant Menu Maker preview.php cross site scripting
- CVE-2025-108281 PoCSourceCodester Pet Grooming Management Software edit.php sql injection
- CVE-2025-108291 PoCCampcodes Computer Sales and Inventory System sup_edit1.php sql injection
- CVE-2025-108301 PoCCampcodes Computer Sales and Inventory System inv_edit1.php sql injection
- CVE-2025-108311 PoCCampcodes Computer Sales and Inventory System pro_edit1.php sql injection
- CVE-2025-108321 PoCSourceCodester Pet Grooming Management Software fetch_product_details.php sql injection
- CVE-2025-108331 PoC1000projects Bookstore Management System login.php sql injection
- CVE-2025-108341 PoCitsourcecode Open Source Job Portal login.php sql injection
- CVE-2025-108351 PoCSourceCodester Pet Grooming Management Software view_payorder.php sql injection
- CVE-2025-108361 PoCSourceCodester Pet Grooming Management Software print1.php sql injection
- CVE-2025-108371 PoCcode-projects Simple Food Ordering System order.php cross site scripting
- CVE-2025-108381 PoCTenda AC21 WifiExtraSet sub_45BB10 buffer overflow
- CVE-2025-108391 PoCSourceCodester Pet Grooming Management Software inv-print.php sql injection
- CVE-2025-108401 PoCSourceCodester Pet Grooming Management Software print-payment.php sql injection
- CVE-2025-108411 PoCcode-projects Online Bidding System weweee.php sql injection
- CVE-2025-108421 PoCcode-projects Online Bidding System wew.php sql injection
- CVE-2025-108431 PoCReservation Online Hotel Reservation System paypalpayout.php sql injection
- CVE-2025-108441 PoCPortabilis i-Educar aluno sql injection
- CVE-2025-108451 PoCPortabilis i-Educar view sql injection
- CVE-2025-108461 PoCPortabilis i-Educar edit sql injection
- CVE-2025-108481 PoCCampcodes Society Membership Information System check_student.php sql injection
- CVE-2025-108511 PoCCampcodes Gym Management System ajax.php sql injection
- CVE-2025-108571 PoCCampcodes Point of Sale System POS login.php sql injection
- CVE-2025-108731 PoCElementinvader Addons for Elementor < 1.4.1 – Unauthenticated Arbitrary Email Sending
- CVE-2025-108742 PoCsOrbit Fox < 3.0.2 - Author+ Server-Side Request Forgery
- CVE-2025-108972 PoCsWooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read
- CVE-2025-109031 PoCLoop with Unreachable Exit Condition ('Infinite Loop') in GitLab
- CVE-2025-109061 PoCMagnetism Studios Endurance NSXPC com.MagnetismStudios.endurance.helper loadModuleNamed:WithReply missing authentication
- CVE-2025-109091 PoCMangati NovoSGA SVG File admin cross site scripting
- CVE-2025-109151 PoCDreamer Blog <= 1.2 - Subscriber+ Arbitrary Plugin Installation
- CVE-2025-109161 PoCFormGent < 1.0.4 - Unauthenticated Arbitrary File Deletion
- CVE-2025-109421 PoCH3C Magic B3 aspForm EditMacList buffer overflow
- CVE-2025-109471 PoCSistemas Pleno Gestão de Locação CPF validarCpf authorization
- CVE-2025-109481 PoCMikroTik RouterOS libjson.so print parse_json_element buffer overflow
- CVE-2025-109491 PoCChangsha Developer Technology iView Editor Markdown cross site scripting
- CVE-2025-109501 PoCgeyang ml-logger Ping server.py log_handler deserialization
- CVE-2025-109512 PoCsgeyang ml-logger server.py log_handler path traversal
- CVE-2025-109522 PoCsgeyang ml-logger File server.py stream_handler information disclosure
- CVE-2025-109531 PoCUTT 1200GW/1250GW formApMail buffer overflow
- CVE-2025-109541 PoCVersions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic Correctness of…
- CVE-2025-109581 PoCWavlink NU516U1 AddMac wireless.cgi sub_403010 command injection
- CVE-2025-109591 PoCWavlink NU516U1 firewall.cgi sub_401778 command injection
- CVE-2025-109601 PoCWavlink NU516U1 DeleteMac wireless.cgi sub_402D1C command injection
- CVE-2025-109611 PoCWavlink NU516U1 Delete_Mac_list wireless.cgi sub_4030C0 command injection
- CVE-2025-109621 PoCWavlink NU516U1 SetName wireless.cgi sub_403198 command injection
- CVE-2025-109631 PoCWavlink NU516U1 firewall.cgi sub_4016F0 command injection
- CVE-2025-109641 PoCWavlink NU516U1 firewall.cgi sub_401B30 command injection
- CVE-2025-109651 PoCLazyAGI LazyLLM server.py lazyllm_call deserialization
- CVE-2025-109671 PoCMuFen-mker PHP-Usermm chkuser.php sql injection
- CVE-2025-109731 PoCJackieDYH Resume-management-system show.php sql injection
- CVE-2025-109741 PoCgiantspatula SewKinect Endpoint calculate pickle.loads deserialization
- CVE-2025-109751 PoCGuanxingLu vlarl ZeroMQ reasoning_server.py run_reasoning_server deserialization
- CVE-2025-109761 PoCJeecgBoot getDepartUserList improper authorization
- CVE-2025-109771 PoCJeecgBoot deleteBatch improper authorization
- CVE-2025-109781 PoCJeecgBoot Filter exportXls improper authorization
- CVE-2025-109791 PoCJeecgBoot exportXls improper authorization
- CVE-2025-109801 PoCJeecgBoot exportXls improper authorization
- CVE-2025-109811 PoCJeecgBoot exportXls improper authorization
- CVE-2025-109871 PoCYunaiV yudao-cloud HTTP Request transfer improper authorization
- CVE-2025-109881 PoCYunaiV ruoyi-vue-pro transfer improper authorization
- CVE-2025-109891 PoCyangzongzhuan RuoYi selectAll improper authorization
- CVE-2025-109921 PoCroncoo roncoo-pay lookupList improper authorization
- CVE-2025-109942 PoCsOpen Babel gamessformat.cpp ReadMolecule use after free
- CVE-2025-109952 PoCsOpen Babel zipstreamimpl.h underflow memory corruption
- CVE-2025-109962 PoCsOpen Babel smilesformat.cpp ParseSmiles heap-based overflow
- CVE-2025-109972 PoCsOpen Babel chemkinformat.cpp CheckSpecies heap-based overflow
- CVE-2025-109981 PoCOpen Babel chemkinformat.cpp ReadReactionQualifierLines null pointer dereference
- CVE-2025-109992 PoCsOpen Babel cacaoformat.cpp SetHilderbrandt null pointer dereference