CVE-2025-15000 to CVE-2025-15999
332 CVEs with public proof-of-concept exploits.
- CVE-2025-150011 PoCFS Registration Password <= 1.0.1 - Unauthenticated Privilege Escalation via Account Takeover
- CVE-2025-150021 PoCSeaCMS mysqli.class.php sql injection
- CVE-2025-150031 PoCSeaCMS admin_video.php sql injection
- CVE-2025-150041 PoCDedeCMS freelist_main.php sql injection
- CVE-2025-150051 PoCCouchCMS reCAPTCHA config.example.php hard-coded key
- CVE-2025-150061 PoCTenda WH450 HTTP Request CheckTools stack-based overflow
- CVE-2025-150071 PoCTenda WH450 HTTP Request L7Im stack-based overflow
- CVE-2025-150081 PoCTenda WH450 HTTP Request L7Port stack-based overflow
- CVE-2025-150091 PoCliweiyi ChestnutCMS Filename upload FilenameUtils.getExtension unrestricted upload
- CVE-2025-150101 PoCTenda WH450 SafeUrlFilter stack-based overflow
- CVE-2025-150111 PoCcode-projects Simple Stock System logout.php sql injection
- CVE-2025-150121 PoCcode-projects Refugee Food Management System home.php sql injection
- CVE-2025-150131 PoCfloooh sokol sokol_gfx.h _sg_validate_pipeline_desc stack-based overflow
- CVE-2025-150301 PoCUser Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset
- CVE-2025-150331 PoCWooCommerce - Subscriber/Customer+ Order Data Disclosure
- CVE-2025-150341 PoCitsourcecode Student Management System record.php sql injection
- CVE-2025-150441 PoCTenda WH450 NatStaticSetting stack-based overflow
- CVE-2025-150451 PoCTenda WH450 HTTP Request Natlimit stack-based overflow
- CVE-2025-150461 PoCTenda WH450 HTTP Request PPTPClient stack-based overflow
- CVE-2025-150471 PoCTenda WH450 HTTP Request PPTPDClient stack-based overflow
- CVE-2025-150481 PoCTenda WH450 HTTP Request CheckTools command injection
- CVE-2025-150491 PoCcode-projects Online Farm System addProduct.php sql injection
- CVE-2025-150501 PoCcode-projects Student File Management System save_file.php unrestricted upload
- CVE-2025-150731 PoCitsourcecode Online Frozen Foods Ordering System contact_us.php sql injection
- CVE-2025-150741 PoCitsourcecode Online Frozen Foods Ordering System customer_details.php sql injection
- CVE-2025-150751 PoCitsourcecode Student Management System student_p.php sql injection
- CVE-2025-150761 PoCTenda CH22 public path traversal
- CVE-2025-150771 PoCitsourcecode Student Management System form137.php sql injection
- CVE-2025-150781 PoCitsourcecode Student Management System list_report.php sql injection
- CVE-2025-150811 PoCJD Cloud BE6500 jdcapi sub_4780 command injection
- CVE-2025-150821 PoCTOZED ZLT M30s Web Management proc_post information disclosure
- CVE-2025-150831 PoCTOZED ZLT M30s UART on-chip debug and test interface with improper access control
- CVE-2025-150841 PoCyoulaitech youlai-mall Order Payment OrderController.java orderService.payOrder access control
- CVE-2025-150851 PoCyoulaitech youlai-mall Balance MemberController.java deductBalance improper authorization
- CVE-2025-150861 PoCyoulaitech youlai-mall MemberController.java getMemberByMobile access control
- CVE-2025-150871 PoCyoulaitech youlai-mall OrderController.java submitOrderPayment improper authorization
- CVE-2025-150881 PoCketr JEPaaS loadPostil postilService.loadPostils sql injection
- CVE-2025-150891 PoCUTT 进取 512W APSecurity strcpy buffer overflow
- CVE-2025-150901 PoCUTT 进取 512W formConfigNoticeConfig strcpy buffer overflow
- CVE-2025-150911 PoCUTT 进取 512W formPictureUrl strcpy buffer overflow
- CVE-2025-150921 PoCUTT 进取 512W ConfigExceptMSN strcpy buffer overflow
- CVE-2025-150931 PoCsunkaifei FlyCMS Admin Login IndexAdminController.java cross site scripting
- CVE-2025-150941 PoCsunkaifei FlyCMS User Login UserController.java userLogin cross site scripting
- CVE-2025-150951 PoCpostmanlabs httpbin core.py cross site scripting
- CVE-2025-150971 PoCAlteryx Server status improper authentication
- CVE-2025-150981 PoCYunaiV yudao-cloud Business Process Management BpmSyncHttpRequestTrigger server-side request forgery
- CVE-2025-150991 PoCsimstudioai sim CRON Secret internal.ts improper authentication
- CVE-2025-151051 PoCgetmaxun auth.ts hard-coded key
- CVE-2025-151061 PoCgetmaxun Authentication Endpoint auth.ts router.get improper authorization
- CVE-2025-151071 PoCactiontech sqle JWT Secret jwt.go hard-coded key
- CVE-2025-151081 PoCPandaXGO PandaX JWT Secret config.yml hard-coded key
- CVE-2025-151091 PoCjackq XCMS upload.php unrestricted upload
- CVE-2025-151101 PoCjackq XCMS Backend ProductImageController.class.php upload unrestricted upload
- CVE-2025-151111 PoCKsenia Security lares Home Automation 1.6 Default Credentials Vulnerability
- CVE-2025-151121 PoCKsenia Security lares Home Automation 1.6 URL Redirection Vulnerability
- CVE-2025-151131 PoCKsenia Security lares Home Automation 1.6 Remote Code Execution via MPFS Upload
- CVE-2025-151141 PoCKsenia Security lares Home Automation 1.6 PIN Exposure Vulnerability
- CVE-2025-151161 PoCOpenCart Single-Use Coupon race condition
- CVE-2025-151181 PoCmacrozheng mall Member Endpoint update improper authorization
- CVE-2025-151191 PoCJeecgBoot list queryPageList improper authorization
- CVE-2025-151201 PoCJeecgBoot getDeptRoleList improper authorization
- CVE-2025-151221 PoCJeecgBoot datarule loadDatarule improper authorization
- CVE-2025-151231 PoCJeecgBoot datarule improper authorization
- CVE-2025-151241 PoCJeecgBoot list getParameterMap improper authorization
- CVE-2025-151251 PoCJeecgBoot queryDepartPermission improper authorization
- CVE-2025-151261 PoCJeecgBoot getPositionUserList improper authorization
- CVE-2025-151271 PoCFantasticLBP Hotels_Server Room.php sql injection
- CVE-2025-151281 PoCZKTeco BioTime Endpoint safe_setting credentials storage
- CVE-2025-151291 PoCChenJinchuang Lin-CMS-TP5 File Upload LocalUploader.php upload code injection
- CVE-2025-151301 PoCshanyu SyCms Administrative Panel FileManageController.class.php addPost code injection
- CVE-2025-151311 PoCZSPACE Z4Pro+ HTTP POST Request status zfilev2_api_SafeStatus command injection
- CVE-2025-151321 PoCZSPACE Z4Pro+ HTTP POST Request open zfilev2_api_open command injection
- CVE-2025-151331 PoCZSPACE Z4Pro+ HTTP POST Request close zfilev2_api_CloseSafe command injection
- CVE-2025-151341 PoCyourmaileyes MOOC Submission MainController.java subreview cross site scripting
- CVE-2025-151351 PoCjoey-zhou xiaozhi-esp32-server-java Cookie AuthenticationInterceptor.java tryAuthenticateWithCookies improper authentication
- CVE-2025-151361 PoCTRENDnet TEW-800MB Management wizardset do_setWizard_asp command injection
- CVE-2025-151371 PoCTRENDnet TEW-800MB NTPSyncWithHost.cgi sub_F934 command injection
- CVE-2025-151381 PoCprasathmani TinyFileManager tinyfilemanager.php path traversal
- CVE-2025-151391 PoCTRENDnet TEW-822DRE formWsc sub_43ACF4 command injection
- CVE-2025-151401 PoCsaiftheboss7 onlinemcqexam quesadd.php sql injection
- CVE-2025-151411 PoCHalo Configuration actuator information disclosure
- CVE-2025-151421 PoC9786 phpok3w show.php sql injection
- CVE-2025-151431 PoCEyouCMS Backend Template Management FilemanagerLogic.php sql injection
- CVE-2025-151441 PoCdayrui XunRuiCMS JSONP Callback Init.php dr_exit_msg cross site scripting
- CVE-2025-151451 PoCSohuTV CacheCloud TotalManageController.java doTotalList cross site scripting
- CVE-2025-151461 PoCSohuTV CacheCloud UserManageController.java doUserList cross site scripting
- CVE-2025-151481 PoCCmsEasy Backend Template Management template_admin.php savetemp_action code injection
- CVE-2025-151491 PoCrawchen ecms Add New Product updateProductServlet.java updateProductServlet cross site scripting
- CVE-2025-151511 PoCTaleLin Lin-CMS Tests Folder config.py password in configuration file
- CVE-2025-151531 PoCPbootCMS SQLite Database pbootcms.db file access
- CVE-2025-151541 PoCPbootCMS Header handle.php get_user_ip less trusted source
- CVE-2025-151551 PoCfloooh sokol sokol_gfx.h _sg_pipeline_desc_defaults stack-based overflow
- CVE-2025-151561 PoComec-project UPF PFCP Session Establishment Request messages_session.go handleSessionEstablishmentRequest null pointer dereference
- CVE-2025-151601 PoCTenda WH450 PPTPServer stack-based overflow
- CVE-2025-151611 PoCTenda WH450 PPTPUserSetting stack-based overflow
- CVE-2025-151621 PoCTenda WH450 RouteStatic stack-based overflow
- CVE-2025-151631 PoCTenda WH450 SafeEmailFilter stack-based overflow
- CVE-2025-151641 PoCTenda WH450 SafeMacFilter stack-based overflow
- CVE-2025-151651 PoCitsourcecode Online Cake Ordering System updatecustomer.php sql injection
- CVE-2025-151661 PoCitsourcecode Online Cake Ordering System updatesupplier.php sql injection
- CVE-2025-151671 PoCitsourcecode Online Cake Ordering System detailtransac.php sql injection
- CVE-2025-151681 PoCitsourcecode Student Management System statistical.php sql injection
- CVE-2025-151691 PoCBiggiDroid Simple PHP CMS editsite.php sql injection
- CVE-2025-151701 PoCAdvaya Softech GEMS ERP Portal Error Message home.jsp cross site scripting
- CVE-2025-151711 PoCSohuTV CacheCloud ServerController.java index cross site scripting
- CVE-2025-151721 PoCSohuTV CacheCloud RedisConfigTemplateController.java preview cross site scripting
- CVE-2025-151731 PoCSohuTV CacheCloud InstanceController.java advancedAnalysis cross site scripting
- CVE-2025-151741 PoCSohuTV CacheCloud AppManageController.java doAppAuditList cross site scripting
- CVE-2025-151751 PoCSohuTV CacheCloud AppController.java appCommandAnalysis cross site scripting
- CVE-2025-151761 PoCOpen5GS PFCP Session Establishment Request rule-match.c ogs_pfcp_pdr_rule_find_by_packet assertion
- CVE-2025-151771 PoCTenda WH450 HTTP Request SetIpBind stack-based overflow
- CVE-2025-151781 PoCTenda WH450 HTTP Request VirtualSer stack-based overflow
- CVE-2025-151791 PoCTenda WH450 qossetting stack-based overflow
- CVE-2025-151801 PoCTenda WH450 HTTP Request webExcptypemanFilte stack-based overflow
- CVE-2025-151811 PoCcode-projects Refugee Food Management System pagenateRefugeesList.php sql injection
- CVE-2025-151821 PoCcode-projects Refugee Food Management System served.php sql injection
- CVE-2025-151831 PoCcode-projects Refugee Food Management System viewtakenfd.php sql injection
- CVE-2025-151841 PoCcode-projects Refugee Food Management System refugeesreport2.php sql injection
- CVE-2025-151851 PoCcode-projects Refugee Food Management System refugeesreport.php sql injection
- CVE-2025-151861 PoCcode-projects Refugee Food Management System addusers.php sql injection
- CVE-2025-151871 PoCGreenCMS File DataController.class.php path traversal
- CVE-2025-151881 PoCCampcodes Complete Online Beauty Parlor Management System search-invoices.php cross site scripting
- CVE-2025-151891 PoCD-Link DWR-M920 formDefRoute sub_464794 buffer overflow
- CVE-2025-151901 PoCD-Link DWR-M920 formFilter sub_42261C stack-based overflow
- CVE-2025-151911 PoCD-Link DWR-M920 formLtefotaUpgradeFibocom sub_4155B4 command injection
- CVE-2025-151921 PoCD-Link DWR-M920 formLtefotaUpgradeQuectel sub_415328 command injection
- CVE-2025-151931 PoCD-Link DWR-M920 formParentControl sub_423848 buffer overflow
- CVE-2025-151941 PoCD-Link DIR-600 HTTP Header hedwig.cgi stack-based overflow
- CVE-2025-151951 PoCcode-projects Assessment Management add-module.php sql injection
- CVE-2025-151961 PoCcode-projects Assessment Management login.php sql injection
- CVE-2025-151971 PoCcode-projects/anirbandutta9 Content Management System/News-Buzz editposts.php unrestricted upload
- CVE-2025-151981 PoCcode-projects College Notes Uploading System login.php sql injection
- CVE-2025-151991 PoCcode-projects College Notes Uploading System userprofile.php unrestricted upload
- CVE-2025-152001 PoCSohuTV CacheCloud AppClientDataShowController.java doIndex cross site scripting
- CVE-2025-152011 PoCSohuTV CacheCloud WebResourceController.java redirectNoPower cross site scripting
- CVE-2025-152021 PoCSohuTV CacheCloud TaskController.java taskQueueList cross site scripting
- CVE-2025-152031 PoCSohuTV CacheCloud ResourceController.java index cross site scripting
- CVE-2025-152041 PoCSohuTV CacheCloud QuartzManageController.java doQuartzList cross site scripting
- CVE-2025-152051 PoCcode-projects Student File Management System download.php sql injection
- CVE-2025-152061 PoCCampcodes Supplier Management System add_area.php sql injection
- CVE-2025-152071 PoCCampcodes Supplier Management System view_products.php sql injection
- CVE-2025-152081 PoCcode-projects Refugee Food Management System editrefugee.php sql injection
- CVE-2025-152091 PoCcode-projects Refugee Food Management System editfood.php sql injection
- CVE-2025-152101 PoCcode-projects Refugee Food Management System editrefugee.php sql injection
- CVE-2025-152111 PoCcode-projects Refugee Food Management System refugee.php sql injection
- CVE-2025-152121 PoCcode-projects Refugee Food Management System regfood.php sql injection
- CVE-2025-152131 PoCcode-projects Student File Management System File Download download.php improper authorization
- CVE-2025-152141 PoCCampcodes Park Ticketing System admin_class.php save_pricing cross site scripting
- CVE-2025-152151 PoCTenda AC10U HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflow
- CVE-2025-152161 PoCTenda AC23 SetIpMacBind fromSetIpMacBind stack-based overflow
- CVE-2025-152181 PoCTenda AC10U POST Request Parameter AdvSetLanip fromadvsetlanip buffer overflow
- CVE-2025-152191 PoCSohuTV CacheCloud MachineManageController.java doPodList cross site scripting
- CVE-2025-152201 PoCSohuTV CacheCloud LoginController.java init cross site scripting
- CVE-2025-152211 PoCSohuTV CacheCloud AppDataMigrateController.java index cross site scripting
- CVE-2025-152221 PoCDromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserialization
- CVE-2025-152231 PoCPhilipinho Simple-PHP-Blog login.php cross site scripting
- CVE-2025-152291 PoCTenda CH22 DhcpListClient fromDhcpListClient denial of service
- CVE-2025-152301 PoCTenda M3 setVlanPolicyData formSetVlanPolicy heap-based overflow
- CVE-2025-152311 PoCTenda M3 setVlanInfo formSetRemoteVlanInfo stack-based overflow
- CVE-2025-152321 PoCTenda M3 setAdPushInfo formSetAdPushInfo stack-based overflow
- CVE-2025-152331 PoCTenda M3 setAdInfoDetail formSetAdInfoDetails heap-based overflow
- CVE-2025-152341 PoCTenda M3 setInternetLanInfo formSetRemoteInternetLanInfo heap-based overflow
- CVE-2025-152411 PoCCloudPanel Community Edition HTTP Header users redirect
- CVE-2025-152421 PoCPHPEMS Coupon race condition
- CVE-2025-152431 PoCcode-projects Simple Stock System login.php sql injection
- CVE-2025-152441 PoCPHPEMS Purchase Request race condition
- CVE-2025-152451 PoCD-Link DCS-850L Firmware Update Service uploadfirmware path traversal
- CVE-2025-152461 PoCaizuda snail-job API FurySerializer.deserialize deserialization
- CVE-2025-152471 PoCgmg137 snap7-rs client.rs download heap-based overflow
- CVE-2025-152481 PoCsunhailin12315 product-review 商品评价系统 Write a Review cross site scripting
- CVE-2025-152501 PoC08CMS Novel System Template mtpls.inc.php code injection
- CVE-2025-152521 PoCTenda M3 setDhcpAP formSetRemoteDhcpForAp stack-based overflow
- CVE-2025-152531 PoCTenda M3 exeCommand stack-based overflow
- CVE-2025-152541 PoCTenda W6-S ATE Service ate TendaAte os command injection
- CVE-2025-152551 PoCTenda W6-S R7websSsecurityHandler httpd stack-based overflow
- CVE-2025-152561 PoCEdimax BR-6208AC Web-based Configuration formStaDrvSetup command injection
- CVE-2025-152571 PoCEdimax BR-6208AC Web-based Configuration formRoute command injection
- CVE-2025-152581 PoCEdimax BR-6208AC Web-based Configuration formALGSetup redirect
- CVE-2025-152601 PoCMyRewards – Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty…
- CVE-2025-152621 PoCBiggiDroid Simple PHP CMS Site Logo edit.php unrestricted upload
- CVE-2025-152631 PoCBiggiDroid Simple PHP CMS Admin Login login.php sql injection
- CVE-2025-152761 PoCFontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
- CVE-2025-153531 PoCitsourcecode Society Management System edit_admin_query.php edit_admin_query sql injection
- CVE-2025-153541 PoCitsourcecode Society Management System add_admin.php sql injection
- CVE-2025-153561 PoCTenda AC20 PowerSaveSet sscanf buffer overflow
- CVE-2025-153571 PoCD-Link DI-7400G+ msp_info.htm command injection
- CVE-2025-153601 PoCnewbee-mall-plus Product Information Edit UploadController.java upload unrestricted upload
- CVE-2025-153631 PoCGet Use APIs < 2.0.10 - Contributor+ Stored XSS
- CVE-2025-153681 PoCSportsPress <= 2.7.26 - Authenticated (Contributor+) Local File Inclusion via Shortcode
- CVE-2025-153711 PoCTenda i24 Shadow File hard-coded credentials
- CVE-2025-153721 PoCyoulaitech vue3-element-admin Notice index.vue cross site scripting
- CVE-2025-153731 PoCEyouCMS function.php saveRemote server-side request forgery
- CVE-2025-153741 PoCEyouCMS Ask Module Ask.php cross site scripting
- CVE-2025-153751 PoCEyouCMS arcpagelist Ajax.php unserialize deserialization
- CVE-2025-153861 PoCResponsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSS
- CVE-2025-153901 PoCPHPGurukul Small CRM edit-user.php authorization
- CVE-2025-153911 PoCD-Link DIR-806A SSDP Request ssdpcgi_main command injection
- CVE-2025-153941 PoCiCMS POST Parameter ConfigAdmincp.php save code injection
- CVE-2025-153961 PoCLibrary Viewer < 3.2.0 - Reflected Cross-Site Scripting
- CVE-2025-153981 PoCUasoft badaso Token BadasoAuthController.php forgetPassword password recovery
- CVE-2025-154001 PoCOpenPix <= 2.13.3 - Subscriber+ Payment Gateway Settings Reset
- CVE-2025-154032 PoCsRegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order
- CVE-2025-154041 PoCcampcodes School File Management System save_file.php unrestricted upload
- CVE-2025-154051 PoCPHPEMS cross-site request forgery
- CVE-2025-154061 PoCPHPGurukul Online Course Registration authorization
- CVE-2025-154071 PoCcode-projects Online Guitar Store Create_category.php sql injection
- CVE-2025-154081 PoCcode-projects Online Guitar Store Create_product.php sql injection
- CVE-2025-154091 PoCcode-projects Online Guitar Store Delete_product.php sql injection
- CVE-2025-154101 PoCcode-projects Online Guitar Store login.php sql injection
- CVE-2025-154111 PoCWebAssembly wabt wasm-decompile InsertNode memory corruption
- CVE-2025-154121 PoCWebAssembly wabt wasm-decompile VarName out-of-bounds
- CVE-2025-154131 PoCwasm3 m3_exec.h op_CallIndirect memory corruption
- CVE-2025-154141 PoCgo-sonic Theme Fetching API git_fetcher.go FetchTheme server-side request forgery
- CVE-2025-154151 PoCxnx3 wangmarket XML File uploadImage.do uploadImage unrestricted upload
- CVE-2025-154161 PoCxnx3 wangmarket Add Global Variable save.do cross site scripting
- CVE-2025-154171 PoCOpen5GS GTPv2-C F-TEID s11-handler.c sgwc_s11_handle_create_session_request denial of service
- CVE-2025-154181 PoCOpen5GS Bearer QoS IE Length types.c ogs_gtp2_parse_bearer_qos denial of service
- CVE-2025-154191 PoCOpen5GS GTPv2-C Flow s5c-handler.c sgwc_s5c_handle_create_session_response denial of service
- CVE-2025-154201 PoCYonyou KSOA agent_work_report.jsp sql injection
- CVE-2025-154211 PoCYonyou KSOA HTTP GET Parameter agent_worksadd.jsp sql injection
- CVE-2025-154221 PoCEmpireSoft EmpireCMS IP Address connect.php egetip protection mechanism
- CVE-2025-154231 PoCEmpireSoft EmpireCMS connect.php CheckSaveTranFiletype unrestricted upload
- CVE-2025-154241 PoCYonyou KSOA HTTP GET Parameter agent_worksdel.jsp sql injection
- CVE-2025-154251 PoCYonyou KSOA HTTP GET Parameter del_user.jsp sql injection
- CVE-2025-154261 PoCjackying H-ui.admin preview.php unrestricted upload
- CVE-2025-154281 PoCUTT 进取 512W formRemoteControl strcpy buffer overflow
- CVE-2025-154291 PoCUTT 进取 512W formConfigCliForEngineerOnly strcpy buffer overflow
- CVE-2025-154301 PoCUTT 进取 512W formFtpServerShareDirSelcet strcpy buffer overflow
- CVE-2025-154311 PoCUTT 进取 512W formFtpServerDirConfig strcpy buffer overflow
- CVE-2025-154321 PoCyeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile path traversal
- CVE-2025-154331 PoCShared Files < 1.7.58 - Contributor+ Arbitrary File Download
- CVE-2025-154341 PoCYonyou KSOA PrintZPYG.jsp sql injection
- CVE-2025-154351 PoCYonyou KSOA work_update.jsp sql injection
- CVE-2025-154361 PoCYonyou KSOA work_edit.jsp sql injection
- CVE-2025-154371 PoCLigeroSmart Environment Variable cross site scripting
- CVE-2025-154381 PoCPluXml Media Management medias.php __destruct deserialization
- CVE-2025-154391 PoCDaptin Aggregate API resource_aggregate.go goqu.L sql injection
- CVE-2025-154411 PoCForm Maker < 1.15.38 - SQL Injection
- CVE-2025-154421 PoCCRMEB product_list sql injection
- CVE-2025-154431 PoCCRMEB product_export sql injection
- CVE-2025-154451 PoCRestaurant Cafeteria <= 0.4.6 - Subscriber+ Arbitrary Plugin Installation/Activation
- CVE-2025-154501 PoCsfturing hosp_order orderHos findOrderHosNum sql injection
- CVE-2025-154511 PoCxnx3 wangmarket System Variables variableSave.do cross site scripting
- CVE-2025-154521 PoCxnx3 wangmarket Backend Variable Search variableList.do variableList cross site scripting
- CVE-2025-154531 PoCmilvus HTTP Endpoint expr.go expr.Exec deserialization
- CVE-2025-154541 PoCzhanglun lettura RSS ContentRender.tsx cross site scripting
- CVE-2025-154551 PoCbg5sbk MiniCMS File Recovery Request page.php delete_page improper authentication
- CVE-2025-154561 PoCbg5sbk MiniCMS Publish page-edit.php improper authentication
- CVE-2025-154571 PoCbg5sbk MiniCMS Trash File Restore post.php improper authentication
- CVE-2025-154581 PoCbg5sbk MiniCMS Article post-edit.php improper authentication
- CVE-2025-154591 PoCUTT 进取 520W formUser strcpy buffer overflow
- CVE-2025-154601 PoCUTT 进取 520W formPptpClientConfig strcpy buffer overflow
- CVE-2025-154611 PoCUTT 进取 520W formTaskEdit strcpy buffer overflow
- CVE-2025-154621 PoCUTT 进取 520W ConfigAdvideo strcpy buffer overflow
- CVE-2025-154641 PoCKL-001-2026-01: yintibao Fun Print Mobile Unauthorized Access via Context Hijacking
- CVE-2025-154673 PoCsStack buffer overflow in CMS (Auth)EnvelopedData parsing
- CVE-2025-154711 PoCTRENDnet TEW-713RE formFSrvX os command injection
- CVE-2025-154721 PoCTRENDnet TEW-811DRU httpd uapply.cgi setDeviceURL os command injection
- CVE-2025-154731 PoCTimetics < 1.0.52 - Unauthenticated Payment/Booking Status Update
- CVE-2025-154742 PoCsAuntyFey Smart Combination Lock BLE Connection Flood DoS
- CVE-2025-154811 PoCNotification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure
- CVE-2025-154841 PoCOrder Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission Bypass
- CVE-2025-154851 PoCAuto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call
- CVE-2025-154881 PoCResponsive Plus < 3.4.3 - Unauthenticated Arbitrary Shortcode Execution
- CVE-2025-154891 PoCPassster < 4.2.24 - Password Protection Bypass
- CVE-2025-154901 PoCPassster < 4.2.26 - Global Protection Bypass
- CVE-2025-154911 PoCPost Slides <= 1.0.1 - Contributor+ Local File Inclusion
- CVE-2025-154921 PoCRainyGao DocSys GroupMemberMapper.xml sql injection
- CVE-2025-154931 PoCRainyGao DocSys ReposAuthMapper.xml sql injection
- CVE-2025-154941 PoCRainyGao DocSys UserMapper.xml sql injection
- CVE-2025-154951 PoCBiggiDroid Simple PHP CMS editsite.php unrestricted upload
- CVE-2025-154961 PoCguchengwuyue yshopmall jobs getPage sql injection
- CVE-2025-154991 PoCSangfor Operation and Maintenance Management System VersionController.java uploadCN os command injection
- CVE-2025-155001 PoCSangfor Operation and Maintenance Management System HTTP POST Request getHis os command injection
- CVE-2025-155011 PoCSangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection
- CVE-2025-155021 PoCSangfor Operation and Maintenance Management System session SessionController os command injection
- CVE-2025-155032 PoCsSangfor Operation and Maintenance Management System common.jsp unrestricted upload
- CVE-2025-155041 PoClief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference
- CVE-2025-155051 PoCLuxul XWR-600 Web Administration cross site scripting
- CVE-2025-155061 PoCAcademySoftwareFoundation OpenColorIO FileRules.cpp ConvertToRegularExpression out-of-bounds
- CVE-2025-155141 PoCOllama Multi-Modal Model Image Processing NULL Pointer Dereference
- CVE-2025-155201 PoCRegistrationMagic <= 6.0.7.2 - Subscriber+ Sensitive Data Disclosure
- CVE-2025-155211 PoCAcademy LMS – WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover
- CVE-2025-155281 PoCOpen5GS GTPv2 Bearer Response denial of service
- CVE-2025-155291 PoCOpen5GS s5c-handler.c sgwc_s5c_handle_create_session_response denial of service
- CVE-2025-155301 PoCOpen5GS s11-handler.c assertion
- CVE-2025-155311 PoCOpen5GS context.c sgwc_bearer_add assertion
- CVE-2025-155321 PoCOpen5GS Timer resource consumption
- CVE-2025-155331 PoCraysan5 raylib rtext.c GenImageFontAtlas heap-based overflow
- CVE-2025-155341 PoCraysan5 raylib rtext.c LoadFontData integer overflow
- CVE-2025-155351 PoCnicbarker clay clay.h Clay__MeasureTextCached null pointer dereference
- CVE-2025-155361 PoCBYVoid OpenCC MaxMatchSegmentation.cpp MaxMatchSegmentation heap-based overflow
- CVE-2025-155371 PoCMapnik dbfile.cpp string_value heap-based overflow
- CVE-2025-155381 PoCOpen Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after free
- CVE-2025-155391 PoCOpen5GS sgwc s11-handler.c sgwc_s11_handle_downlink_data_notification_ack denial of service
- CVE-2025-155451 PoCInsufficient Backup File Upload Input Validation on TP-Link Archer RE605X
- CVE-2025-155461 PoCIptanus File Upload < 5.1.7 - File Overwrite via Race Condition
- CVE-2025-155561 PoCKEVNotepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
- CVE-2025-155641 PoCMapnik value.cpp operator divide by zero
- CVE-2025-155701 PoCckolivas lrzip stream.c lzma_decompress_buf use after free
- CVE-2025-155711 PoCckolivas lrzip stream.c ucompthread null pointer dereference
- CVE-2025-155721 PoCwasm3 NewCodePage memory leak
- CVE-2025-155811 PoCOrthanc versions before 1.12.10 are affected by an authorisation logic flaw in the application's HTTP Basic Authentication implementation.…
- CVE-2025-155821 PoCdetronetdip E-commerce Product Management Update authorization
- CVE-2025-155831 PoCdetronetdip E-commerce function.php get_safe_value cross site scripting
- CVE-2025-155851 PoCFileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function.…
- CVE-2025-155891 PoCMuYuCMS Template Management Template.php delete_dir_file path traversal
- CVE-2025-155971 PoCDataease SQLBot API Endpoint assistant.py access control
- CVE-2025-155981 PoCDataease SQLBot JWT Token auth.py validateEmbedded signature verification
- CVE-2025-156021 PoCSnipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation
- CVE-2025-156091 PoCFortis For WooCommerce < 1.3.1 - Sensitive API Key Disclosure
- CVE-2025-156111 PoCPopup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF
- CVE-2025-156321 PoC1Panel-dev MaxKB MdPreview chat.ts cross site scripting
- CVE-2025-156621 PoCPrintcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery
- CVE-2025-156631 PoCBEAF < 4.7.19 - Author+ Stored XSS via After Label
- CVE-2025-156641 PoCBEAF < 4.7.19 - Author+ Stored XSS via Before Label
- CVE-2025-156651 PoCBEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field
- CVE-2025-156661 PoCOpen Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow
- CVE-2025-156671 PoCGPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free
- CVE-2025-156681 PoCGPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow
- CVE-2025-156691 PoCBit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
- CVE-2025-156711 PoCWelcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter
- CVE-2025-156721 PoCChama < 1.0.13 - Unauthenticated PHP Object Injection
- CVE-2025-156731 PoCImport and export users and customers < 2.4.3 - Admin+ Arbitrary File Read
- CVE-2025-156741 PoCContent Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
- CVE-2025-156751 PoCCharitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text
- CVE-2025-156771 PoCGeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
- CVE-2025-156781 PoCNexter Blocks < 5.0.2 - Author+ Stored XSS via SVG Upload
- CVE-2025-156841 PoCOpen5GS CER init.c diam_log_func assertion
- CVE-2025-156861 PoCOpen5GS HSS Service fd_msg_sess_get denial of service
- CVE-2025-156871 PoCOpen5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service
- CVE-2025-156921 PoCIcegram Express < 5.8.6 - Admin+ Stored XSS