CVE-2025-12000 to CVE-2025-12999
229 CVEs with public proof-of-concept exploits.
- CVE-2025-120291 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-120301 PoCACF to REST API <= 3.3.4 - Insecure Direct Object Reference to Authenticated (Contributor+) ACF Field/Option Modification
- CVE-2025-120551 PoCUnauthenticated Local File Disclosure in MPDV Mikrolab MIP 2 / FEDRA 2 / HYDRA X Manufacturing Execution System
- CVE-2025-120571 PoCWavePlayer < 3.8.0 - Unauthenticated Arbitrary File Upload
- CVE-2025-120611 PoCTax Service Electronic HDM < 1.2.1 - Unauthenticated Arbitrary SQL Execution
- CVE-2025-120731 PoCServer-Side Request Forgery (SSRF) in GitLab
- CVE-2025-120971 PoCRelative Path Traversal Vulnerability in NI System Web Server
- CVE-2025-121013 PoCsCross-Site Scripting (XSS)
- CVE-2025-121392 PoCsFile Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure
- CVE-2025-121631 PoCOmnipress <= 1.6.5 - Authenticated (Author+) Stored Cross-Site Scripting
- CVE-2025-122011 PoCajayrandhawa User-Management-PHP-MYSQL User Management edit-user.php unrestricted upload
- CVE-2025-122021 PoCajayrandhawa User-Management-PHP-MYSQL web cross-site request forgery
- CVE-2025-122031 PoCgivanz Vvveb Code Editor functions.php sanitizeFileName path traversal
- CVE-2025-122041 PoCKamailio Configuration File rvalue.c rve_destroy heap-based overflow
- CVE-2025-122051 PoCKamailio Configuration File cfg.lex sr_push_yy_state use after free
- CVE-2025-122061 PoCKamailio rvalue.c rve_is_constant null pointer dereference
- CVE-2025-122071 PoCKamailio Grammar Rule cfg.y yyerror_at null pointer dereference
- CVE-2025-122081 PoCSourceCodester Best House Rental Management System admin_class.php login2 sql injection
- CVE-2025-122091 PoCTenda O3 setDhcpConfig GetValue stack-based overflow
- CVE-2025-122101 PoCTenda O3 AdvSetLanip GetValue stack-based overflow
- CVE-2025-122111 PoCTenda O3 setDmzInfo GetValue stack-based overflow
- CVE-2025-122121 PoCTenda O3 setNetworkService GetValue stack-based overflow
- CVE-2025-122131 PoCTenda O3 setVlanConfig GetValue stack-based overflow
- CVE-2025-122141 PoCTenda O3 sysAutoReboot GetValue stack-based overflow
- CVE-2025-122151 PoCprojectworlds Online Shopping System login_submit.php sql injection
- CVE-2025-122221 PoCBdtask Flight Booking Software Deposit deposit unrestricted upload
- CVE-2025-122231 PoCBdtask Flight Booking Software Package Information package-information unrestricted upload
- CVE-2025-122241 PoCIqbolshoh php-business-website contact.php cross site scripting
- CVE-2025-122251 PoCTenda AC6 HTTP Request WifiGuestSet stack-based overflow
- CVE-2025-122261 PoCSourceCodester Best House Rental Management System admin_class.php save_house sql injection
- CVE-2025-122271 PoCprojectworlds Gate Pass Management System add-pass.php cross site scripting
- CVE-2025-122281 PoCprojectworlds Expense Management System Users Page create cross site scripting
- CVE-2025-122291 PoCprojectworlds Expense Management System Roles Page create cross site scripting
- CVE-2025-122301 PoCprojectworlds Expense Management System Currency create cross site scripting
- CVE-2025-122311 PoCprojectworlds Expense Management System Expense Categories create cross site scripting
- CVE-2025-122321 PoCTenda CH22 SafeClientFilter fromSafeClientFilter buffer overflow
- CVE-2025-122331 PoCTenda CH22 SafeUrlFilter fromSafeUrlFilter buffer overflow
- CVE-2025-122341 PoCTenda CH22 SafeMacFilter fromSafeMacFilter buffer overflow
- CVE-2025-122351 PoCTenda CH22 SetIpBind fromSetIpBind buffer overflow
- CVE-2025-122361 PoCTenda CH22 DhcpListClient fromDhcpListClient buffer overflow
- CVE-2025-122371 PoCprojectworlds Advanced Library Management System index.php sql injection
- CVE-2025-122381 PoCcode-projects Automated Voting System user.php sql injection
- CVE-2025-122391 PoCTOTOLINK A3300R cstecgi.cgi setDdnsCfg buffer overflow
- CVE-2025-122401 PoCTOTOLINK A3300R cstecgi.cgi setDmzCfg buffer overflow
- CVE-2025-122411 PoCTOTOLINK A3300R POST Parameter cstecgi.cgi setLanguageCfg stack-based overflow
- CVE-2025-122421 PoCCodeAstro Gym Management System check-attendance.php sql injection
- CVE-2025-122431 PoCcode-projects Client Details System GET Parameter welcome.php sql injection
- CVE-2025-122441 PoCcode-projects Simple E-Banking System register.php cross site scripting
- CVE-2025-122471 PoCHasleo Backup Suite HasleoImageMountService/HasleoBackupSuiteService unquoted search path
- CVE-2025-122481 PoCCLTPHP search.html sql injection
- CVE-2025-122491 PoCAxosoft Scrum and Bug Tracking Edit Ticket csv injection
- CVE-2025-122501 PoCOpenWGA TMLScript API WGA.File path traversal
- CVE-2025-122511 PoCOpenWGA Admin UI cross site scripting
- CVE-2025-122521 PoCcode-projects Online Event Judging System action.php sql injection
- CVE-2025-122531 PoCAMTT Hotel Broadband Operation System get_expiredtime.php sql injection
- CVE-2025-122541 PoCcode-projects Online Event Judging System add_judge.php sql injection
- CVE-2025-122551 PoCcode-projects Online Event Judging System add_contestant.php sql injection
- CVE-2025-122561 PoCcode-projects Online Event Judging System edit_contestant.php sql injection
- CVE-2025-122571 PoCSourceCodester Online Student Result System view_result.php sql injection
- CVE-2025-122591 PoCTOTOLINK A3300R POST Parameter cstecgi.cgi setScheduleCfg stack-based overflow
- CVE-2025-122601 PoCTOTOLINK A3300R POST Parameter cstecgi.cgi setSyslogCfg stack-based overflow
- CVE-2025-122611 PoCCodeAstro Gym Management System remove-announcement.php sql injection
- CVE-2025-122621 PoCcode-projects Online Event Judging System edit_criteria.php sql injection
- CVE-2025-122631 PoCcode-projects Online Event Judging System edit_judge.php sql injection
- CVE-2025-122651 PoCTenda CH22 VirtualSer fromVirtualSer buffer overflow
- CVE-2025-122661 PoCZytec Dalian Zhuoyun Technology Central Authentication Service widget _empty code injection
- CVE-2025-122671 PoCabhicodebox ModernShop search cross site scripting
- CVE-2025-122681 PoCLearnHouse Course Thumbnail courses unrestricted upload
- CVE-2025-122691 PoCLearnHouse Account Setting previews cross site scripting
- CVE-2025-122701 PoCLearnHouse Student Assignment Submission sub_file resource injection
- CVE-2025-122711 PoCTenda CH22 RouteStatic fromRouteStatic buffer overflow
- CVE-2025-122721 PoCTenda CH22 addressNat fromAddressNat buffer overflow
- CVE-2025-122731 PoCTenda CH22 webExcptypemanFilter fromwebExcptypemanFilter buffer overflow
- CVE-2025-122741 PoCTenda CH22 P2pListFilter fromP2pListFilter buffer overflow
- CVE-2025-122761 PoCLearnHouse Image information disclosure
- CVE-2025-122771 PoCAbdullah-Hasan-Sajjad Online-School studentLogin.php sql injection
- CVE-2025-122791 PoCcode-projects Client Details System welcome.php cross site scripting
- CVE-2025-122801 PoCcode-projects Client Details System update-clients.php cross site scripting
- CVE-2025-122811 PoCcode-projects Client Details System clientview.php cross site scripting
- CVE-2025-122821 PoCcode-projects Client Details System manage-users.php cross site scripting
- CVE-2025-122831 PoCcode-projects Client Details System authorization
- CVE-2025-122871 PoCBdtask Wholesale Inventory Control and Inventory Management System edit_profile sql injection
- CVE-2025-122881 PoCBdtask Pharmacy Management System User Profile edit_user authorization
- CVE-2025-122891 PoCSui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1001 cross site scripting
- CVE-2025-122901 PoCSui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 359 cross site scripting
- CVE-2025-122911 PoCashymuzuro Full-Ecommece-Website/Muzuro Ecommerce System Add Product index.php unrestricted upload
- CVE-2025-122921 PoCSourceCodester Point of Sales index.php sql injection
- CVE-2025-122931 PoCSourceCodester Point of Sales category.php sql injection
- CVE-2025-122941 PoCSourceCodester Point of Sales delete_category.php sql injection
- CVE-2025-122951 PoCD-Link DAP-2695 Firmware Update sub_40C6B8 signature verification
- CVE-2025-122961 PoCD-Link DAP-2695 Firmware Update sub_4174B0 os command injection
- CVE-2025-122971 PoCatjiu pybbs UserApiController.java information disclosure
- CVE-2025-122981 PoCcode-projects Simple Food Ordering System editcategory.php cross site scripting
- CVE-2025-122991 PoCcode-projects Simple Food Ordering System addproduct.php cross site scripting
- CVE-2025-123001 PoCcode-projects Simple Food Ordering System addcategory.php cross site scripting
- CVE-2025-123011 PoCcode-projects Simple Food Ordering System editproduct.php unrestricted upload
- CVE-2025-123021 PoCcode-projects Simple Food Ordering System editproduct.php cross site scripting
- CVE-2025-123031 PoCPHPGurukul Curfew e-Pass Management System admin-profile.php cross site scripting
- CVE-2025-123041 PoCdulaiduwang003 TIME-SEA-PLUS Order Status PayController.java alipayIsSucceed improper authorization
- CVE-2025-123051 PoCquequnlong shiyi-blog Job SysJobController.java deserialization
- CVE-2025-123061 PoCcode-projects Nero Social Networking Site acceptoffres.php sql injection
- CVE-2025-123071 PoCcode-projects Nero Social Networking Site addfriend.php sql injection
- CVE-2025-123081 PoCcode-projects Nero Social Networking Site deletemessage.php sql injection
- CVE-2025-123091 PoCcode-projects Nero Social Networking Site friendprofile.php sql injection
- CVE-2025-123111 PoCPHPGurukul Curfew e-Pass Management System edit-category-detail.php cross site scripting
- CVE-2025-123121 PoCPHPGurukul Curfew e-Pass Management System view-pass-detail.php cross site scripting
- CVE-2025-123131 PoCD-Link DI-7001 MINI msp_info.htm command injection
- CVE-2025-123141 PoCcode-projects Food Ordering System deleteitem.php sql injection
- CVE-2025-123151 PoCcode-projects Food Ordering System menu.php sql injection
- CVE-2025-123161 PoCcode-projects Courier Management System edit-courier.php sql injection
- CVE-2025-123221 PoCTenda CH22 NatStaticSetting fromNatStaticSetting buffer overflow
- CVE-2025-123251 PoCSourceCodester Best Salon Management System forgot-password.php sql injection
- CVE-2025-123301 PoCWillow CMS Add Post add cross site scripting
- CVE-2025-123311 PoCWillow CMS add unrestricted upload
- CVE-2025-123321 PoCSourceCodester Student Grades Management System admin.php delete_user cross site scripting
- CVE-2025-123331 PoCcode-projects E-Commerce Website supplier_add.php cross site scripting
- CVE-2025-123341 PoCcode-projects E-Commerce Website product_add.php cross site scripting
- CVE-2025-123351 PoCcode-projects E-Commerce Website supplier_update.php cross site scripting
- CVE-2025-123361 PoCCampcodes Retro Basketball Shoes Online Store admin_index.php sql injection
- CVE-2025-123371 PoCCampcodes Retro Basketball Shoes Online Store admin_feature.php sql injection
- CVE-2025-123381 PoCCampcodes Retro Basketball Shoes Online Store admin_product.ph sql injection
- CVE-2025-123391 PoCCampcodes Retro Basketball Shoes Online Store admin_football.php sql injection
- CVE-2025-123421 PoCSerdar Bayram Ghost Hot Spot Login Auth.php sql injection
- CVE-2025-123441 PoCYonyou U8 Cloud Request Header NCloudGatewayServlet unrestricted upload
- CVE-2025-123453 PoCsLLM-Claw Agent Deployment initiate.c agent_deploy_init buffer overflow
- CVE-2025-123461 PoCMaxSite CMS HTTP Header uploads-require-maxsite.php unrestricted upload
- CVE-2025-123471 PoCMaxSite CMS save-file-ajax.php unrestricted upload
- CVE-2025-123781 PoCcode-projects Simple Food Ordering System addproduct.php unrestricted upload
- CVE-2025-123861 PoCMissing Authentication for Critical Endpoint in Pix-Link LV-WR21Q
- CVE-2025-123871 PoCDenial of Service in Pix-Link LV-WR21Q
- CVE-2025-123941 PoCBackup Migration < 2.0.0 - Unauthenticated Backup Download
- CVE-2025-123991 PoCAlex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload
- CVE-2025-124801 PoCKEVTriofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages…
- CVE-2025-125021 PoCAttention Bar <= 0.7.2.1 - Admin+ SQLi
- CVE-2025-125061 PoCUse of Incorrectly-Resolved Name or Reference in GitLab
- CVE-2025-125361 PoCSureForms <= 1.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure
- CVE-2025-125391 PoCTNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover
- CVE-2025-125461 PoCLogicalDOC Community Edition API Key creation UI cross site scripting
- CVE-2025-125471 PoCLogicalDOC Community Edition Admin Login login.jsp excessive authentication
- CVE-2025-125481 PoCGithub.com/che-incubator/che-code: eclipse che — unauthenticated rce and secret exfiltration via tcp/3333
- CVE-2025-125551 PoCIncorrect Authorization in GitLab
- CVE-2025-125621 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-125691 PoCWP Front User Submit < 5.0.0 - Open Redirect
- CVE-2025-125711 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-125731 PoCBookingor <= 1.0.12 - Subscriber+ Category Deletion
- CVE-2025-125751 PoCServer-Side Request Forgery (SSRF) in GitLab
- CVE-2025-125761 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-125931 PoCcode-projects Simple Online Hotel Reservation System Photo edit_room.php unrestricted upload
- CVE-2025-125941 PoCcode-projects Simple Online Hotel Reservation System add_account.php sql injection
- CVE-2025-125951 PoCTenda AC23 SetVirtualServerCfg formSetVirtualSer buffer overflow
- CVE-2025-125961 PoCTenda AC23 saveParentControlInfo buffer overflow
- CVE-2025-125971 PoCSourceCodester Best House Rental Management System admin_class.php save_category sql injection
- CVE-2025-125981 PoCSourceCodester Best House Rental Management System admin_class.php save_tenant sql injection
- CVE-2025-126041 PoCitsourcecode Online Loan Management System load_fields.php sql injection
- CVE-2025-126051 PoCitsourcecode Online Loan Management System manage_loan.php sql injection
- CVE-2025-126061 PoCitsourcecode Online Loan Management System manage_borrower.php sql injection
- CVE-2025-126071 PoCitsourcecode Online Loan Management System manage_payment.php sql injection
- CVE-2025-126081 PoCitsourcecode Online Loan Management System manage_user.php sql injection
- CVE-2025-126091 PoCCodeAstro Gym Management System update-progress.php sql injection
- CVE-2025-126101 PoCCodeAstro Gym Management System view-progress-report.php sql injection
- CVE-2025-126111 PoCTenda AC21 SetPptpServerCfg formSetPPTPServer buffer overflow
- CVE-2025-126121 PoCCampcodes School Fees Payment Management System ajax.php sql injection
- CVE-2025-126141 PoCSourceCodester Best House Rental Management System admin_class.php delete_payment sql injection
- CVE-2025-126151 PoCPHPGurukul News Portal settings.py hard-coded key
- CVE-2025-126161 PoCPHPGurukul News Portal settings.py insertion of sensitive information into debugging code
- CVE-2025-126171 PoCitsourcecode Billing System login_crud.php sql injection
- CVE-2025-126181 PoCTenda AC8 DatabaseIniSet buffer overflow
- CVE-2025-126191 PoCTenda A15 openNetworkGateway fromSetWirelessRepeat buffer overflow
- CVE-2025-126221 PoCTenda AC10 SysRunCmd formSysRunCmd buffer overflow
- CVE-2025-126231 PoCfushengqian fuint Authentication Token ClientSignController.java authorization
- CVE-2025-126261 PoCjeecgboot jeewx-boot WxActGoldeneggsPrizesController.java getImgUrl path traversal
- CVE-2025-126281 PoCWP 2FA < 3.0.0 - Second Factor Bypass
- CVE-2025-126291 PoCBroken Link Manager <= 0.6.5 - Reflected XSS
- CVE-2025-126301 PoCUpload.am File Hosting VPN < 1.0.1 - Contributor+ Arbitrary Option Disclosure
- CVE-2025-126531 PoCAuthentication Bypass by Spoofing in GitLab
- CVE-2025-126641 PoCImproper Validation of Specified Quantity in Input in GitLab
- CVE-2025-126691 PoCImproper Control of Generation of Code ('Code Injection') in GitLab
- CVE-2025-126742 PoCsKiotViet Sync <= 1.8.5 - Unauthenticated Arbitrary File Upload
- CVE-2025-126841 PoCURL Shortify < 1.11.3 - Reflected XSS
- CVE-2025-126851 PoCWPBookit <= 1.0.7 - Customer Deletion via CSRF
- CVE-2025-126961 PoCHelloLeads CRM Form Shortcode <= 1.0 - Unauthenticated Settings Reset
- CVE-2025-126971 PoCImproper Encoding or Escaping of Output in GitLab
- CVE-2025-127041 PoCMissing Authorization in GitLab
- CVE-2025-127161 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-127341 PoCImproper Encoding or Escaping of Output in GitLab
- CVE-2025-127352 PoCsCVE-2025-12735
- CVE-2025-127443 PoCsAbrt: command-injection in abrt leading to local privilege escalation
- CVE-2025-127451 PoCQuickJS quickjs.c js_array_buffer_slice buffer over-read
- CVE-2025-127481 PoCLibvirt: denial of service in xml parsing
- CVE-2025-127581 PoCVersions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in…
- CVE-2025-127621 PoCRemote Code Execution vulnerability when restoring PLAIN-format SQL dumps in server mode (pgAdmin 4)
- CVE-2025-128201 PoCPure WC Variation Swatches <= 1.1.7 - Unauthenticated Settings Update
- CVE-2025-128351 PoCWooMulti <= 1.7 - Subscriber+ Arbitrary File Deletion
- CVE-2025-128412 PoCsBookit < 2.5.1 – Unauthenticated Settings Update
- CVE-2025-128531 PoCSourceCodester Best House Rental Management System admin_class.php delete_house sql injection
- CVE-2025-128541 PoCnewbee-mall-plus seckillExecution executeSeckill authorization
- CVE-2025-128551 PoCcode-projects Responsive Hotel Site newsletterdel.php sql injection
- CVE-2025-128561 PoCcode-projects Responsive Hotel Site reservation.php sql injection
- CVE-2025-128571 PoCcode-projects Responsive Hotel Site roombook.php sql injection
- CVE-2025-128591 PoCDedeBIZ templets_one_edit.php sql injection
- CVE-2025-128601 PoCDedeBIZ freelist_main.php sql injection
- CVE-2025-128611 PoCDedeBIZ spec_add.php sql injection
- CVE-2025-128621 PoCprojectworlds Online Notes Sharing Platform userprofile.php unrestricted upload
- CVE-2025-128731 PoCCampcodes School File Management update_user.php sql injection
- CVE-2025-128751 PoCmruby array.c ary_fill_exec out-of-bounds write
- CVE-2025-129131 PoCcode-projects Responsive Hotel Site roomdel.php sql injection
- CVE-2025-129141 PoCaaPanel BaoTa Backend database sql injection
- CVE-2025-129151 PoC70mai X200 Init Script file inclusion
- CVE-2025-129162 PoCsSangfor Operation and Maintenance Security Management System Frontend portal_login command injection
- CVE-2025-129171 PoCTOZED ZLT T10 Reboot proc_post denial of service
- CVE-2025-129181 PoCyungifez Skuul School Management System View Fee Invoice fee-invoices resource injection
- CVE-2025-129191 PoCEverShop Order Order.resolvers.js resource injection
- CVE-2025-129201 PoCqianfox FoxCMS Product.php edit cross site scripting
- CVE-2025-129211 PoCOpenClinica Community Edition CRF Data Import ImportCRFData xml injection
- CVE-2025-129221 PoCOpenClinica Community Edition CRF Data Import ImportCRFData path traversal
- CVE-2025-129231 PoCliweiyi ChestnutCMS download resourceDownload path traversal
- CVE-2025-129261 PoCSourceCodester Farm Management System review.php sql injection
- CVE-2025-129271 PoCDedeBIZ archives_add.php sql injection
- CVE-2025-129281 PoCcode-projects Online Job Search Engine login.php sql injection
- CVE-2025-129291 PoCSourceCodester Survey Application System LoginRegistration.php update_user sql injection
- CVE-2025-129301 PoCSourceCodester Food Ordering System view-ticket.php sql injection
- CVE-2025-129311 PoCSourceCodester Food Ordering System edit-orders.php sql injection
- CVE-2025-129321 PoCSourceCodester Baby Care System admin.php sql injection
- CVE-2025-129331 PoCSourceCodester Baby Care System updatewelcome.php sql injection
- CVE-2025-129381 PoCprojectworlds Online Admission System process_login.php sql injection
- CVE-2025-129391 PoCSourceCodester Interview Management System addCandidate.php sql injection
- CVE-2025-129541 PoCTimetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR
- CVE-2025-129731 PoCS2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.8 - Authenticated (Editor+) Arbitrary File Upload
- CVE-2025-129831 PoCMemory Allocation with Excessive Size Value in GitLab