CVE-2025-14000 to CVE-2025-14999
307 CVEs with public proof-of-concept exploits.
- CVE-2025-140041 PoCdayrui XunRuiCMS Email Setting admind45f74adbd95.php server-side request forgery
- CVE-2025-140051 PoCdayrui XunRuiCMS Add Display Name Field admind45f74adbd95.php cross site scripting
- CVE-2025-140061 PoCdayrui XunRuiCMS Add Data Validation admind45f74adbd95.php cross site scripting
- CVE-2025-140071 PoCdayrui XunRuiCMS Domain Name Binding admin79f2ec220c7e.php cross site scripting
- CVE-2025-140081 PoCdayrui XunRuiCMS Project Domain Change Test admin79f2ec220c7e.php server-side request forgery
- CVE-2025-140111 PoCJIZHICMS Add Display Name Field addcomment.html commentlist sql injection
- CVE-2025-140121 PoCJIZHICMS Batch Delete Comments deleteAll.html delete sql injection
- CVE-2025-140131 PoCJIZHICMS Comment addcomment.html cross site scripting
- CVE-2025-140151 PoCH3C Magic B0 aspForm EditWlanMacList buffer overflow
- CVE-2025-140161 PoCmacrozheng mall-swarm delete improper authorization
- CVE-2025-140182 PoCsUnquoted Service Path in NetBT Consultancy's e-Fatura
- CVE-2025-140471 PoCWP User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion
- CVE-2025-140511 PoCyoulaitech youlai-mall addresses deleteAddress improper control of dynamically-identified variables
- CVE-2025-140521 PoCyoulaitech youlai-mall members getMemberById access control
- CVE-2025-140721 PoCNinja Forms < 3.13.3 - Unauthenticated Token Generation and Submission Disclosure
- CVE-2025-140851 PoCyoulaitech youlai-mall orders improper control of dynamically-identified variables
- CVE-2025-140861 PoCyoulaitech youlai-mall openid access control
- CVE-2025-140881 PoCketr JEPaaS load improper authorization
- CVE-2025-140891 PoCHimool ERP AdminActionViewSet update_account improper authorization
- CVE-2025-140901 PoCAMTT Hotel Broadband Operation System cardmake_down.php sql injection
- CVE-2025-140911 PoCTrippWasTaken PHP-Guitar-Shop Product Details product.php sql injection
- CVE-2025-140921 PoCEdimax BR-6478AC V3 formDebugDiagnosticRun sub_416898 os command injection
- CVE-2025-140931 PoCEdimax BR-6478AC V3 formTracerouteDiagnosticRun sub_416990 os command injection
- CVE-2025-140941 PoCEdimax BR-6478AC V3 formSysCmd sub_44CCE4 os command injection
- CVE-2025-141031 PoCMissing Authorization in GitLab
- CVE-2025-141051 PoCTOZED ZLT M30S/ZLT M30S PRO Web proc_post denial of service
- CVE-2025-141061 PoCZSPACE Q2C NAS HTTP POST Request close zfilev2_api.CloseSafe command injection
- CVE-2025-141071 PoCZSPACE Q2C NAS HTTP POST Request status zfilev2_api.SafeStatus command injection
- CVE-2025-141081 PoCZSPACE Q2C NAS HTTP POST Request open zfilev2_api.OpenSafe command injection
- CVE-2025-141111 PoCRarlab RAR App com.rarlab.rar path traversal
- CVE-2025-141161 PoCxerrors Yuxi-Know embed.py OtherEmbedding.aencode server-side request forgery
- CVE-2025-141171 PoCfit2cloud Halo cross-site request forgery
- CVE-2025-141243 PoCsTeam < 5.0.11 - Unauthenticated SQLi
- CVE-2025-141261 PoCTOZED ZLT M30S/ZLT M30S PRO Web hard-coded credentials
- CVE-2025-141331 PoCLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wireless_clientlist_setClientsName stack-based overflow
- CVE-2025-141341 PoCLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflow
- CVE-2025-141351 PoCLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so AP_get_wired_clientlist_setClientsName stack-based overflow
- CVE-2025-141361 PoCLinksys RE6500/RE6250/RE6300/RE6350/RE7000/RE9000 mod_form.so stack-based overflow
- CVE-2025-141391 PoCUTT 进取 520W formConfigDnsFilterGlobal strcpy buffer overflow
- CVE-2025-141401 PoCUTT 进取 520W websHostFilter strcpy buffer overflow
- CVE-2025-141411 PoCUTT 进取 520W formArpBindConfig strcpy buffer overflow
- CVE-2025-141551 PoCPremium Addons for Elementor <= 4.11.53 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content'
- CVE-2025-141561 PoCFox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder'
- CVE-2025-141741 PoCKEVOut of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds…
- CVE-2025-141771 PoCInformation Leak of Memory in getimagesize
- CVE-2025-141821 PoCSobey Media Convergence System upload path traversal
- CVE-2025-141831 PoCSGAI Space1 NAS N1211DS gsaiagent JSONAPI GET_USER_INFO credentials storage
- CVE-2025-141841 PoCSGAI Space1 NAS N1211DS gsaiagent JSONAPI NGNIX_UPLOAD command injection
- CVE-2025-141851 PoCYonyou U8 Cloud AppServletService.class sql injection
- CVE-2025-141861 PoCGrandstream GXP1625 Network Status api.values.post cross site scripting
- CVE-2025-141871 PoCUGREEN DH2100+ nas_svr create handler_file_backup_create buffer overflow
- CVE-2025-141881 PoCUGREEN DH2100+ nas_svr create handler_file_backup_create command injection
- CVE-2025-141891 PoCChanjet CRM jxf_dump_table_demo.php sql injection
- CVE-2025-141901 PoCChanjet TPlus sql injection
- CVE-2025-141911 PoCUTT 进取 512W formP2PLimitConfig strcpy buffer overflow
- CVE-2025-141921 PoCRashminDungrani online-banking auth_login.php sql injection
- CVE-2025-141931 PoCcode-projects Employee Profile Management System view_personnel.php sql injection
- CVE-2025-141941 PoCcode-projects Employee Profile Management System view_personnel.php cross site scripting
- CVE-2025-141951 PoCcode-projects Employee Profile Management System add_file_query.php unrestricted upload
- CVE-2025-141961 PoCH3C Magic B1 aspForm sub_44de0 buffer overflow
- CVE-2025-141971 PoCVerysync 微力同步 Web Administration f96956469e7be39d information disclosure
- CVE-2025-141981 PoCVerysync 微力同步 Web Administration download information disclosure
- CVE-2025-141991 PoCVerysync 微力同步 Web Administration text.txt unrestricted upload
- CVE-2025-142001 PoCalokjaiswal Hotel-Management-services-using-MYSQL-and-php Request Pending usersub.php cross site scripting
- CVE-2025-142011 PoCalokjaiswal Hotel-Management-services-using-MYSQL-and-php dishsub.php cross site scripting
- CVE-2025-142031 PoCcode-projects Question Paper Generator selectquestionuser.php sql injection
- CVE-2025-142041 PoCTykoDev cherry-studio-TykoFork OAuth Server Discovery oauth-authorization-server redirectToAuthorization os command injection
- CVE-2025-142051 PoCcode-projects Chamber of Commerce Membership Management System Your Info membership_profile.php cross site scripting
- CVE-2025-142061 PoCSourceCodester Online Student Clearance System Fee Table delete-fee.php improper authorization
- CVE-2025-142071 PoCtushar-2223 Hotel-Management-System invoiceprint.php sql injection
- CVE-2025-142081 PoCD-Link DIR-823X set_wan_settings sub_415028 command injection
- CVE-2025-142091 PoCCampcodes School File Management System update_query.php sql injection
- CVE-2025-142101 PoCprojectworlds Advanced Library Management System delete_member.php sql injection
- CVE-2025-142111 PoCprojectworlds Advanced Library Management System delete_book.php sql injection
- CVE-2025-142121 PoCprojectworlds Advanced Library Management System member_search.php sql injection
- CVE-2025-142141 PoCitsourcecode Student Information System section_edit1.php sql injection
- CVE-2025-142151 PoCcode-projects Currency Exchange System edit.php sql injection
- CVE-2025-142161 PoCcode-projects Currency Exchange System viewserial.php sql injection
- CVE-2025-142171 PoCcode-projects Currency Exchange System edittrns.php sql injection
- CVE-2025-142181 PoCcode-projects Currency Exchange System editotheraccount.php sql injection
- CVE-2025-142191 PoCCampcodes Retro Basketball Shoes Online Store admin_running.php unrestricted upload
- CVE-2025-142201 PoCORICO CD3510 File Upload path traversal
- CVE-2025-142212 PoCsSourceCodester Online Banking System page cross site scripting
- CVE-2025-142221 PoCcode-projects Employee Profile Management System print_personnel_report.php sql injection
- CVE-2025-142231 PoCcode-projects Simple Leave Manager request.php sql injection
- CVE-2025-142241 PoCYottamaster DM2/DM3/DM200 File Upload path traversal
- CVE-2025-142251 PoCD-Link DCS-930L alphapd setSystemAdmin command injection
- CVE-2025-142261 PoCitsourcecode Student Management System edit_user.php sql injection
- CVE-2025-142271 PoCPhilipinho Simple-PHP-Blog edit.php sql injection
- CVE-2025-142281 PoCYealink SIP-T21P E2 Local Directory cross site scripting
- CVE-2025-142291 PoCSourceCodester Inventory Management System SVC Report Export csv injection
- CVE-2025-142301 PoCcode-projects Daily Time Recording System add_payroll.php sql injection
- CVE-2025-142441 PoCGreenCMS Menu Management CustomController.class.php cross site scripting
- CVE-2025-142451 PoCIdeaCMS Coupon.php whereRaw sql injection
- CVE-2025-142461 PoCcode-projects Simple Shopping Cart settings.php sql injection
- CVE-2025-142471 PoCcode-projects Simple Shopping Cart additems.php sql injection
- CVE-2025-142481 PoCcode-projects Simple Shopping Cart adminlogin.php sql injection
- CVE-2025-142491 PoCcode-projects Online Ordering System user_school.php sql injection
- CVE-2025-142501 PoCcode-projects Online Ordering System user_contact.php sql injection
- CVE-2025-142511 PoCcode-projects Online Ordering System Admin Login admin sql injection
- CVE-2025-142561 PoCitsourcecode Student Management System newcurriculm.php sql injection
- CVE-2025-142571 PoCitsourcecode Student Management System newrecord.php sql injection
- CVE-2025-142581 PoCitsourcecode Student Management System newsubject.php sql injection
- CVE-2025-142591 PoCJihai Jshop MiniProgram Mall System api.html sql injection
- CVE-2025-142761 PoCIlevia EVE X1 Server leaf_search.php command injection
- CVE-2025-142851 PoCcode-projects Employee Profile Management System edit_personnel.php sql injection
- CVE-2025-142861 PoCTenda AC9 Configuration File DownloadCfg.jpg information disclosure
- CVE-2025-143121 PoCAdvance WP Query Search Filter <= 1.0.10 - Reflected XSS via counter
- CVE-2025-143131 PoCAdvance WP Query Search Filter <= 1.0.10 - Reflected XSS via taxo_ajax
- CVE-2025-143161 PoCAhaChat Messenger Marketing <= 1.1 - Reflected XSS
- CVE-2025-143211 PoCUse-after-free in the WebRTC: Signaling component
- CVE-2025-143341 PoCitsourcecode Student Management System new_adviser.php sql injection
- CVE-2025-143351 PoCitsourcecode Student Management System new_school_year.php sql injection
- CVE-2025-143361 PoCitsourcecode Student Management System promote.php sql injection
- CVE-2025-143371 PoCitsourcecode Student Management System new_grade.php sql injection
- CVE-2025-143402 PoCsAdmin Account Takeover via malicious URL payload
- CVE-2025-143431 PoCReflected XSS in Dokuzsoft Technology's E-Commerce Product
- CVE-2025-143641 PoCDemo Importer Plus <= 2.0.8 - Missing Authorization to Authenticated (Subscriber+) Site Reset and Privilege Escalation
- CVE-2025-144341 PoCUltimate Post Kit < 4.0.16 – Unauthenticated Arbitrary Post Content Disclosure
- CVE-2025-144371 PoCHummingbird <= 3.18.0 - Unauthenticated Sensitive Information Exposure via Log File
- CVE-2025-144401 PoCJAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
- CVE-2025-144851 PoCEFM ipTIME A3004T Administrator Password timepro.cgi show_debug_screen command injection
- CVE-2025-145051 PoCElliptic Cryptanalysis vulnerability when `k` has leading zeros
- CVE-2025-145111 PoCImproper Validation of Specified Quantity in Input in GitLab
- CVE-2025-145131 PoCImproper Validation of Specified Quantity in Input in GitLab
- CVE-2025-145141 PoCCampcodes Supplier Management System add_distributor.php sql injection
- CVE-2025-145151 PoCCampcodes Supplier Management System add_unit.php sql injection
- CVE-2025-145161 PoCYalantis uCrop URL com.yalantis.ucrop.task.BitmapLoadTask.java downloadFile server-side request forgery
- CVE-2025-145171 PoCYalantis uCrop AndroidManifest.xml UCropActivity improper export of android application components
- CVE-2025-145182 PoCsPowerJob Network Request PingPongUtils.java checkConnectivity server-side request forgery
- CVE-2025-145191 PoCbaowzh hfly advtext add cross site scripting
- CVE-2025-145201 PoCbaowzh hfly delfile path traversal
- CVE-2025-145211 PoCbaowzh hfly download path traversal
- CVE-2025-145221 PoCbaowzh hfly upload_json.php unrestricted upload
- CVE-2025-145261 PoCTenda CH22 L7Im frmL7ImForm buffer overflow
- CVE-2025-145271 PoCprojectworlds Advanced Library Management System view_book.php sql injection
- CVE-2025-145282 PoCsD-Link DIR-803 Configuration getcfg.php information disclosure
- CVE-2025-145291 PoCCampcodes Retro Basketball Shoes Online Store admin_running.php sql injection
- CVE-2025-145301 PoCSourceCodester Real Estate Property Listing App property.php unrestricted upload
- CVE-2025-145311 PoCcode-projects Rental Management System Log Transaction.java crlf injection
- CVE-2025-145341 PoCUTT 进取 512W Endpoint formNatStaticMap strcpy buffer overflow
- CVE-2025-145351 PoCUTT 进取 512W formConfigFastDirectionW strcpy buffer overflow
- CVE-2025-145361 PoCcode-projects Class and Exam Timetable Management Login index.php sql injection
- CVE-2025-145371 PoCcode-projects Class and Exam Timetable Management preview7.php sql injection
- CVE-2025-145381 PoCyangshare warehouseManager 仓库管理系统 CustomerManageHandler.java addCustomer cross site scripting
- CVE-2025-145451 PoCYML for Yandex Market < 5.0.26 - Shop Manager+ RCE via Feed Generation
- CVE-2025-145585 PoCsRemote code execution via ND6 Router Advertisements
- CVE-2025-145601 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-145621 PoCIncorrect Authorization in GitLab
- CVE-2025-145651 PoCkidaze CourseSelectionSystem login1.php sql injection
- CVE-2025-145661 PoCkidaze CourseSelectionSystem reg.php sql injection
- CVE-2025-145671 PoChaxxorsid Stock-Management-System employees missing authentication
- CVE-2025-145681 PoChaxxorsid Stock-Management-System User.php sql injection
- CVE-2025-145691 PoCggml-org whisper.cpp common-whisper.cpp read_audio_data use after free
- CVE-2025-145701 PoCprojectworlds Advanced Library Management System view_admin.php sql injection
- CVE-2025-145711 PoCprojectworlds Advanced Library Management System borrow_book.php sql injection
- CVE-2025-145721 PoCUTT 进取 512W formWebAuthGlobalConfig memory corruption
- CVE-2025-145781 PoCitsourcecode Student Management System update_account.php sql injection
- CVE-2025-145791 PoCQuiz Maker < 6.7.0.89 - Admin+ Stored XSS
- CVE-2025-145821 PoCcampcodes Online Student Enrollment System index.php unrestricted upload
- CVE-2025-145831 PoCcampcodes Online Student Enrollment System register.php unrestricted upload
- CVE-2025-145841 PoCitsourcecode COVID Tracking System Admin Login login.php sql injection
- CVE-2025-145851 PoCitsourcecode COVID Tracking System page sql injection
- CVE-2025-145861 PoCTOTOLINK X5000R cstecgi.cgi snprintf os command injection
- CVE-2025-145871 PoCitsourcecode Online Pet Shop Management System available.php sql injection
- CVE-2025-145881 PoCitsourcecode Student Management System update_program.php sql injection
- CVE-2025-145891 PoCcode-projects Prison Management System search.php sql injection
- CVE-2025-145901 PoCcode-projects Prison Management System search1.php sql injection
- CVE-2025-145921 PoCMissing Authorization in GitLab
- CVE-2025-145941 PoCAuthorization Bypass Through User-Controlled Key in GitLab
- CVE-2025-145951 PoCMissing Authorization in GitLab
- CVE-2025-146061 PoCtiny-rdm Tiny RDM Pickle Decoding pickle_convert.go pickle.loads deserialization
- CVE-2025-146114 PoCsKEVGladinet CentreStack and TrioFox Hard Coded AES Keys
- CVE-2025-146171 PoCJehovahs Witnesses JW Library App org.jw.jwlibrary.mobile.activity.SiloContainer path traversal
- CVE-2025-146191 PoCcode-projects Student File Management System login_query.php sql injection
- CVE-2025-146201 PoCcode-projects Student File Management System login_query.php sql injection
- CVE-2025-146211 PoCcode-projects Student File Management System update_user.php sql injection
- CVE-2025-146221 PoCcode-projects Student File Management System save_user.php sql injection
- CVE-2025-146231 PoCcode-projects Student File Management System update_student.php sql injection
- CVE-2025-146361 PoCTenda AX9 httpd image_check weak hash
- CVE-2025-146371 PoCitsourcecode Online Pet Shop Management System addcnp.php sql injection
- CVE-2025-146381 PoCitsourcecode Online Pet Shop Management System update_cnp.php sql injection
- CVE-2025-146391 PoCitsourcecode Student Management System uprec.php sql injection
- CVE-2025-146401 PoCcode-projects Student File Management System save_student.php sql injection
- CVE-2025-146411 PoCcode-projects Computer Laboratory System admin_pic.php unrestricted upload
- CVE-2025-146421 PoCcode-projects Computer Laboratory System technical_staff_pic.php unrestricted upload
- CVE-2025-146431 PoCcode-projects Simple Attendance Record System check.php sql injection
- CVE-2025-146441 PoCitsourcecode Student Management System update_subject.php sql injection
- CVE-2025-146451 PoCcode-projects Student File Management System delete_user.php sql injection
- CVE-2025-146461 PoCcode-projects Student File Management System delete_student.php sql injection
- CVE-2025-146471 PoCcode-projects Computer Book Store admin_delete.php sql injection
- CVE-2025-146481 PoCDedeBIZ catalog_add.php command injection
- CVE-2025-146491 PoCitsourcecode Online Cake Ordering System supplier.php sql injection
- CVE-2025-146501 PoCitsourcecode Online Cake Ordering System product.php sql injection
- CVE-2025-146511 PoCMartialBE one-hub docker-compose.yml hard-coded key
- CVE-2025-146521 PoCitsourcecode Online Cake Ordering System admindetail.php sql injection
- CVE-2025-146531 PoCitsourcecode Student Management System addrecord.php sql injection
- CVE-2025-146541 PoCTenda AC20 httpd setPptpUserList formSetPPTPUserList stack-based overflow
- CVE-2025-146551 PoCTenda AC20 httpd SetSysAutoRebbotCfg formSetRebootTimer stack-based overflow
- CVE-2025-146561 PoCTenda AC20 openSchedWifi httpd buffer overflow
- CVE-2025-146591 PoCD-Link DIR-860LB1/DIR-868LB1 DHCP command injection
- CVE-2025-146601 PoCDecoCMS Mesh Workspace Domain api.ts createTool access control
- CVE-2025-146611 PoCitsourcecode Student Managemen System advisers.php sql injection
- CVE-2025-146621 PoCcode-projects Student File Management System Update User update_user.php cross site scripting
- CVE-2025-146631 PoCcode-projects Student File Management System update_student.php cross site scripting
- CVE-2025-146641 PoCCampcodes Supplier Management System view_unit.php sql injection
- CVE-2025-146651 PoCTenda WH450 HTTP Request DhcpListClient stack-based overflow
- CVE-2025-146661 PoCitsourcecode COVID Tracking System page sql injection
- CVE-2025-146671 PoCitsourcecode COVID Tracking System page sql injection
- CVE-2025-146681 PoCcampcodes Advanced Online Examination System loginExe.php sql injection
- CVE-2025-146721 PoCgmg137 snap7-rs s7_micro_client.cpp opWriteArea heap-based overflow
- CVE-2025-146731 PoCgmg137 snap7-rs client.rs as_ct_write heap-based overflow
- CVE-2025-146911 PoCMayan EDMS authentication cross site scripting
- CVE-2025-146921 PoCMayan EDMS authentication redirect
- CVE-2025-146931 PoCUgreen DH2100+ USB symlink
- CVE-2025-146941 PoCketr JEPaaS readAllPostil sql injection
- CVE-2025-146951 PoCSamuNatsu HaloBot Inter-plugin API index.js html_renderer dynamically-managed code resources
- CVE-2025-146961 PoCShenzhen Sixun Software Sixun Shanghui Group Business Management System UpdatePasswordBatch password recovery
- CVE-2025-146971 PoCShenzhen Sixun Software Sixun Shanghui Group Business Management System ExportFiles file access
- CVE-2025-146981 PoCatlaszz AI Photo Team Galleryit App gallery.photogallery.pictures.vault.album path traversal
- CVE-2025-146991 PoCMunicorn FAX App biz.faxapp.app path traversal
- CVE-2025-147002 PoCsImproper Neutralization of Special Elements Used in a Template Engine in Crafty Controller
- CVE-2025-147021 PoCSmartbit CommV Smartschool App be.smartschool.mobile.SplashActivity path traversal
- CVE-2025-147031 PoCShiguangwu sgwbox N3 POST Message fsnotify improper authentication
- CVE-2025-147041 PoCShiguangwu sgwbox N3 API eshell path traversal
- CVE-2025-147051 PoCShiguangwu sgwbox N3 SHARESERVER Feature command injection
- CVE-2025-147061 PoCShiguangwu sgwbox N3 NETREBOOT http_eshell_server command injection
- CVE-2025-147071 PoCShiguangwu sgwbox N3 DOCKER Feature http_eshell_server command injection
- CVE-2025-147081 PoCShiguangwu sgwbox N3 WIREDCFGGET http_eshell_server buffer overflow
- CVE-2025-147091 PoCShiguangwu sgwbox N3 WIRELESSCFGGET http_eshell_server buffer overflow
- CVE-2025-147101 PoCFantasticLBP Hotels Server OrderList.php sql injection
- CVE-2025-147111 PoCFantasticLBP Hotels Server hotelList.php sql injection
- CVE-2025-147191 PoCRelevanssi (Free < 4.26.0, Premium < 2.29.0) - Contributor+ SQLi
- CVE-2025-147221 PoCvion707 DMadmin Backend AddonsController.class.php add cross site scripting
- CVE-2025-147261 PoCWidgets for Social Photo Feed <= 1.8 - Missing Authentication to Unauthenticated Plugin Settings Access/Update via…
- CVE-2025-147291 PoCCTCMS Content Management System Backend App Configuration Ct_App.php save code injection
- CVE-2025-147301 PoCCTCMS Content Management System Backend System Configuration Ct_Config.php code injection
- CVE-2025-147311 PoCCTCMS Content Management System Frontend/Template Management CT_Parser.php special elements used in a template engine
- CVE-2025-147331 PoCKEVWatchGuard Firebox iked Out of Bounds Write Vulnerability
- CVE-2025-147361 PoCFrontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form Field
- CVE-2025-147461 PoCNingyuanda TC155 RTSP Live Video Stream Endpoint improper authentication
- CVE-2025-147471 PoCNingyuanda TC155 RTSP Service denial of service
- CVE-2025-147481 PoCNingyuanda TC155 ONVIF Device Management Service device_service access control
- CVE-2025-147491 PoCNingyuanda TC155 ONVIF PTZ Control device_service access control
- CVE-2025-147651 PoCUse after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2025-147661 PoCOut of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap…
- CVE-2025-147801 PoCXiongwei Smart Catering Cloud Platform dish_trade_detail_get sql injection
- CVE-2025-147831 PoCEasy Digital Downloads <= 3.6.2 - Unvalidated Redirect in Password Reset Flow via edd_redirect
- CVE-2025-148011 PoCxiweicheng TMS create createComment cross site scripting
- CVE-2025-148031 PoCNex-Forms Express WP Form Builder < 9.1.8 - Authenticated Stored XSS
- CVE-2025-148041 PoCFrontend File Manager < 23.5 - Subscriber+ Arbitrary File Deletion
- CVE-2025-148291 PoCe-xact-hosted-payment <= 2.0 - Unauthenticated Arbitrary File Deletion
- CVE-2025-148321 PoCitsourcecode Online Cake Ordering System updateproduct.php sql injection
- CVE-2025-148331 PoCcode-projects Online Appointment Booking System deletemanagerclinic.php sql injection
- CVE-2025-148341 PoCcode-projects Simple Stock System checkuser.php sql injection
- CVE-2025-148361 PoCZZCMS User Data Storage user_save.php cleartext storage in file
- CVE-2025-148371 PoCZZCMS Backend Website Settings siteconfig.php stripfxg code injection
- CVE-2025-1484727 PoCsKEVZlib compressed protocol header length confusion may allow memory read
- CVE-2025-148551 PoCSureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting
- CVE-2025-148561 PoCy_project RuoYi getnames code injection
- CVE-2025-148571 PoCSemtech LR11xx Memory Write Access Control Bypass
- CVE-2025-148691 PoCImproper Validation of Specified Quantity in Input in GitLab
- CVE-2025-148701 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-148741 PoCNodemailer: nodemailer: denial of service via crafted email address header
- CVE-2025-148771 PoCCampcodes Supplier Management System add_retailer.php sql injection
- CVE-2025-148781 PoCTenda WH450 HTTP Request wirelessRestart stack-based overflow
- CVE-2025-148791 PoCTenda WH450 HTTP Request onSSIDChange stack-based overflow
- CVE-2025-148841 PoCD-Link DIR-605 Firmware Update Service command injection
- CVE-2025-148851 PoCSourceCodester Client Database Management System Leads Generation user_leads.php unrestricted upload
- CVE-2025-148891 PoCCampcodes Advanced Voting Management System Password voters_edit.php improper authorization
- CVE-2025-148921 PoCPrime Listing Manager <= 1.1 - Unauthenticated Privilege Escalation
- CVE-2025-148931 PoCIndieWeb <= 4.0.5 - Authenticated (Author+) Stored Cross-Site Scripting via 'Telephone' Parameter
- CVE-2025-148971 PoCCodeAstro Real Estate Management System Administrator Endpoint useragentdelete.php sql injection
- CVE-2025-148981 PoCCodeAstro Real Estate Management System Administrator Endpoint userbuilderdelete.php sql injection
- CVE-2025-148991 PoCCodeAstro Real Estate Management System Administrator Endpoint stateadd.php sql injection
- CVE-2025-149001 PoCCodeAstro Real Estate Management System Administrator Endpoint userdelete.php sql injection
- CVE-2025-149081 PoCJeecgBoot Multi-Tenant Management SysTenantController.java improper authentication
- CVE-2025-149091 PoCJeecgBoot SysUserOnlineController.java SysUserOnlineController user session
- CVE-2025-149101 PoCEdimax BR-6208AC FTP Daemon Service handle_retr path traversal
- CVE-2025-149391 PoCcode-projects Online Appointment Booking System deletemanager.php sql injection
- CVE-2025-149401 PoCcode-projects Scholars Tracking System delete_user.php sql injection
- CVE-2025-149501 PoCcode-projects Scholars Tracking System delete_post.php sql injection
- CVE-2025-149511 PoCcode-projects Scholars Tracking System home.php sql injection
- CVE-2025-149521 PoCCampcodes Supplier Management System add_category.php sql injection
- CVE-2025-149531 PoCOpen5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereference
- CVE-2025-149541 PoCOpen5GS QER/FAR/URR/PDR context.c ogs_pfcp_qer_find_or_add assertion
- CVE-2025-149551 PoCOpen5GS PFCP handler.c ogs_pfcp_handle_create_pdr initialization
- CVE-2025-149561 PoCWebAssembly Binaryen wasm-binary.cpp readExport heap-based overflow
- CVE-2025-149571 PoCWebAssembly Binaryen IRBuilder wasm-ir-builder.cpp makeLocalTee null pointer dereference
- CVE-2025-149581 PoCfloooh sokol sokol_gfx.h _sg_pipeline_common_init heap-based overflow
- CVE-2025-149591 PoCcode-projects Simple Stock System signup.php sql injection
- CVE-2025-149601 PoCcode-projects Simple Blood Donor Management System editeddonor.php sql injection
- CVE-2025-149611 PoCcode-projects Simple Blood Donor Management System editedcampaign.php sql injection
- CVE-2025-149621 PoCcode-projects Simple Stock System chatuser.php cross site scripting
- CVE-2025-149661 PoCFastAdmin Backend Controller Backend.php selectpage sql injection
- CVE-2025-149671 PoCitsourcecode Student Management System candidates_report.php sql injection
- CVE-2025-149681 PoCcode-projects Simple Stock System update.php sql injection
- CVE-2025-149731 PoCRecipe Card Blocks < 3.4.13 - Contributor+ SQLi
- CVE-2025-149751 PoCCustom Login Page Customizer < 2.5.4 - Unauthenticated Arbitrary Password Reset
- CVE-2025-149891 PoCCampcodes Complete Online Beauty Parlor Management System search-invoices.php sql injection
- CVE-2025-149901 PoCCampcodes Complete Online Beauty Parlor Management System view-appointment.php sql injection
- CVE-2025-149911 PoCCampcodes Complete Online Beauty Parlor Management System bwdates-reports-details.php cross site scripting
- CVE-2025-149921 PoCTenda AC18 HTTP Request GetParentControlInfo strcpy stack-based overflow
- CVE-2025-149931 PoCTenda AC18 HTTP Request SetDlnaCfg sprintf stack-based overflow
- CVE-2025-149941 PoCTenda FH1201/FH1206 HTTP Request webtypelibrary strcat stack-based overflow
- CVE-2025-149951 PoCTenda FH1201 SetIpBind sprintf stack-based overflow
- CVE-2025-149982 PoCsBranda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover