CVE-2025-1000 to CVE-2025-1999
328 CVEs with public proof-of-concept exploits.
- CVE-2025-10051 PoCElementsKit Elementor addons <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion Widget
- CVE-2025-10071 PoCImproper Authorization in /user/namespace/{namespace}/details
- CVE-2025-10151 PoCUnsanitized address book fields
- CVE-2025-10232 PoCsSQL Injection in ChurchCRM newCountName Parameter via EditEventTypes.php
- CVE-2025-10241 PoCSession Hijacking via Reflected Cross-Site Scripting (XSS) in ChurchCRM EditEventAttendees.php EID Parameter
- CVE-2025-10251 PoCVersions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different…
- CVE-2025-10331 PoCBadgearoo <= 1.0.14 - Admin+ Stored XSS
- CVE-2025-10351 PoCPath Traversal in Komtera Technolgies' KLog Server
- CVE-2025-10401 PoCServer-Side Template Injection (SSTI) in significant-gravitas/autogpt
- CVE-2025-10421 PoCFiles or Directories Accessible to External Parties in GitLab
- CVE-2025-10501 PoCSonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability
- CVE-2025-10551 PoCK7 Security Anti-Malware: IOCTL in K7RKScan.sys Allows Arbitrary Termination of High-Privilege and System Processes by a Low-Privilege User
- CVE-2025-10621 PoCSlider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS
- CVE-2025-10722 PoCsAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-10741 PoCWebkul QloApps URL mylogout cross-site request forgery
- CVE-2025-10781 PoCAppHouseKitchen AlDente Charge Limiter XPC Service com.apphousekitchen.aldente-pro.helper shouldAcceptNewConnection improper authorization
- CVE-2025-10791 PoCRCE In Google Web Designer
- CVE-2025-10811 PoCBharti Airtel Xstream Fiber WiFi Password weak credentials
- CVE-2025-10821 PoCMindskip xzs-mysql 学之思开源考试系统 Exam Edit edit cross site scripting
- CVE-2025-10831 PoCMindskip xzs-mysql 学之思开源考试系统 CORS cross-domain policy
- CVE-2025-10841 PoCMindskip xzs-mysql 学之思开源考试系统 cross-site request forgery
- CVE-2025-10946 PoCsPostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
- CVE-2025-10978 PoCsingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
- CVE-2025-10988 PoCsingress-nginx controller - configuration injection via unsanitized mirror annotations
- CVE-2025-11031 PoCD-Link DIR-823X HTTP POST Request set_wifi_blacklists null pointer dereference
- CVE-2025-11041 PoCD-Link DHP-W310AV authentication spoofing
- CVE-2025-11061 PoCCmsEasy database_admin.php restore_action path traversal
- CVE-2025-11101 PoCInsufficient Granularity of Access Control in GitLab
- CVE-2025-11131 PoCtaisan tarzan-cms Add Theme admin#themes upload deserialization
- CVE-2025-11141 PoCnewbee-mall Add Category Page save cross site scripting
- CVE-2025-11161 PoCDreamvention Live AJAX Search Free live_search.searchresults search sql injection
- CVE-2025-11171 PoCCoinRemitter sql injection
- CVE-2025-11221 PoCOut-Of-Bounds Write in TPM2 Reference Library in Google ChromeOS 15753.50.0 stable on Cr50 Boards allows an attacker with root access to…
- CVE-2025-11281 PoCEverest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletion
- CVE-2025-11321 PoCSQL Injection in ChurchCRM EN_tyid Parameter via EditEventAttendees.php
- CVE-2025-11331 PoCSQL Injection in ChurchCRM EID Parameter via EditEventAttendees.php
- CVE-2025-11341 PoCSQL Injection in ChurchCRM CurrentFundraiser Parameter via DonatedItemEditor.php
- CVE-2025-11351 PoCSQL Injection in ChurchCRM CurrentFundraiser Parameter via BatchWinnerEntry.php
- CVE-2025-11471 PoCGNU Binutils nm nm.c internal_strlen buffer overflow
- CVE-2025-11481 PoCGNU Binutils ld ldelfgen.c link_order_scan memory leak
- CVE-2025-11491 PoCGNU Binutils ld xmalloc.c xstrdup memory leak
- CVE-2025-11501 PoCGNU Binutils ld libbfd.c bfd_malloc memory leak
- CVE-2025-11511 PoCGNU Binutils ld xmemdup.c xmemdup memory leak
- CVE-2025-11521 PoCGNU Binutils ld xstrdup.c xstrdup memory leak
- CVE-2025-11531 PoCGNU Binutils format.c bfd_set_format memory corruption
- CVE-2025-11541 PoCxxyopen Novel books sql injection
- CVE-2025-11551 PoCWebkul QloApps Your Location Search stores cross site scripting
- CVE-2025-11581 PoCESAFENET CDG addPolicyToSafetyGroup.jsp sql injection
- CVE-2025-11591 PoCCampCodes School Management Software academic-calendar cross site scripting
- CVE-2025-11601 PoCSourceCodester Employee Management System index.php default credentials
- CVE-2025-11622 PoCscode-projects Job Recruitment load\_user-profile.php sql injection
- CVE-2025-11632 PoCscode-projects Vehicle Parking Management System Authentication login stack-based overflow
- CVE-2025-11642 PoCscode-projects Police FIR Record Management System Add Record stack-based overflow
- CVE-2025-11651 PoCLumsoft ERP FileUploadApi.ashx DoWebUpload unrestricted upload
- CVE-2025-11661 PoCSourceCodester Food Menu Manager update.php unrestricted upload
- CVE-2025-11701 PoCcode-projects Real Estate Property Management System Category.php cross site scripting
- CVE-2025-11712 PoCscode-projects Real Estate Property Management System CustomerReport.php cross site scripting
- CVE-2025-11721 PoC1000 Projects Bookstore Management System addtocart.php sql injection
- CVE-2025-11741 PoC1000 Projects Bookstore Management System Add Book Page process_book_add.php cross site scripting
- CVE-2025-11761 PoCGNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow
- CVE-2025-11771 PoCdayrui XunRuiCMS Linkage.php import_add deserialization
- CVE-2025-11781 PoCGNU Binutils ld libbfd.c bfd_putl64 memory corruption
- CVE-2025-11791 PoCGNU Binutils ld libbfd.c bfd_putl64 memory corruption
- CVE-2025-11801 PoCGNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption
- CVE-2025-11811 PoCGNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec memory corruption
- CVE-2025-11821 PoCGNU Binutils ld elflink.c bfd_elf_reloc_symbol_deleted_p memory corruption
- CVE-2025-11831 PoCCodeZips Gym Management System more-userprofile.php sql injection
- CVE-2025-11841 PoCpihome-shc PiHome ajax.php sql injection
- CVE-2025-11851 PoCpihome-shc PiHome ajax.php sql injection
- CVE-2025-11861 PoCdayrui XunRuiCMS Api.php deserialization
- CVE-2025-11871 PoCcode-projects Police FIR Record Management System Delete Record stack-based overflow
- CVE-2025-11881 PoCCodezips Gym Management System updateroutine.php sql injection
- CVE-2025-11891 PoC1000 Projects Attendance Tracking Management System chart1.php sql injection
- CVE-2025-11911 PoCSourceCodester Multi Restaurant Table Reservation System approve-reject.php sql injection
- CVE-2025-11921 PoCSourceCodester Multi Restaurant Table Reservation System select-menu.php sql injection
- CVE-2025-11951 PoCcode-projects Real Estate Property Management System EditCategory cross site scripting
- CVE-2025-11961 PoCcode-projects Real Estate Property Management System search.php cross site scripting
- CVE-2025-11971 PoCcode-projects Real Estate Property Management System load_user-profile.php sql injection
- CVE-2025-11991 PoCSourceCodester Best Church Management Software role_crud.php sql injection
- CVE-2025-12001 PoCSourceCodester Best Church Management Software slider_crud.php sql injection
- CVE-2025-12011 PoCSourceCodester Best Church Management Software profile_crud.php sql injection
- CVE-2025-12021 PoCSourceCodester Best Church Management Software edit_slider.php sql injection
- CVE-2025-12031 PoCSlider, Gallery, Carousel by MetaSlider < 3.95.0 - Editor+ Stored XSS
- CVE-2025-12061 PoCCodezips Gym Management System viewdetailroutine.php sql injection
- CVE-2025-12071 PoCphjounin TFTPD64 DNS denial of service
- CVE-2025-12081 PoCcode-projects Wazifa System Profile.php cross site scripting
- CVE-2025-12091 PoCcode-projects Wazifa System search_resualts.php searchuser cross site scripting
- CVE-2025-12101 PoCcode-projects Wazifa System control.php sql injection
- CVE-2025-12131 PoCpihome-shc PiHome index.php cross site scripting
- CVE-2025-12141 PoCpihome-shc PiHome Role-Based Access Control user_accounts.php authorization
- CVE-2025-12161 PoCywoa OaNoticeMapper.xml selectNoticeList sql injection
- CVE-2025-12171 PoCHeader parser of http stream wrapper does not handle folded headers
- CVE-2025-12191 PoClibxml streams use wrong content-type header when requesting a redirected resource
- CVE-2025-12201 PoCNull byte termination in hostnames
- CVE-2025-12241 PoCywoa UserMapper.xml listNameBySql sql injection
- CVE-2025-12251 PoCywoa WXCallBack Interface XMLParse.java extract xml external entity reference
- CVE-2025-12261 PoCywoa setup.jsp improper authorization
- CVE-2025-12271 PoCywoa AddressDao.xml selectList sql injection
- CVE-2025-12281 PoColajowon Loggrove Logfile Update page path traversal
- CVE-2025-12291 PoColajowon Loggrove page os command injection
- CVE-2025-12322 PoCsSite Reviews < 7.2.5 - Unauthenticated Stored XSS
- CVE-2025-12501 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-12571 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-12781 PoCInsufficient Granularity of Access Control in GitLab
- CVE-2025-12861 PoCDownload HTML TinyMCE Button <= 1.2 - Reflected XSS
- CVE-2025-12881 PoCwooexim <= 5.0.0 - CSRF to Reflected XSS
- CVE-2025-12891 PoCPlugin Oficial – Getnet para WooCommerce <= 1.7.3 - Admin+ Stored XSS
- CVE-2025-12901 PoCA race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS.…
- CVE-2025-12921 PoCTPM2 Out-Of-Bounds Write Leading to Potential Operating System Verification Bypass in ChromeOS
- CVE-2025-12991 PoCMissing Authorization in GitLab
- CVE-2025-13025 PoCsVersions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An…
- CVE-2025-13032 PoCsPlugin Oficial – Getnet para WooCommerce <= 1.7.3 - Unauthenticated Reflected XSS
- CVE-2025-13041 PoCNewsBlogger <= 0.2.5.1 - Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2025-13061 PoCNewscrunch <= 1.8.4 - Cross-Site Request Forgery to Arbitrary File Upload
- CVE-2025-13072 PoCsNewscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2025-13232 PoCsWP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection
- CVE-2025-13321 PoCFastCMS Template Menu menu cross site scripting
- CVE-2025-13351 PoCCmsEasy file_admin.php deleteimg_action path traversal
- CVE-2025-13361 PoCCmsEasy image_admin.php deleteimg_action path traversal
- CVE-2025-13371 PoCEastnets PaymentSafe BIC Search cross site scripting
- CVE-2025-13383 PoCsNUUO Camera handle_config.php print_file command injection
- CVE-2025-13391 PoCTOTOLINK X18 cstecgi.cgi setL2tpdConfig os command injection
- CVE-2025-13401 PoCTOTOLINK X18 cstecgi.cgi setPasswordCfg stack-based overflow
- CVE-2025-13411 PoCPMWeb Setting weak password
- CVE-2025-13521 PoCGNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruption
- CVE-2025-13551 PoCneedyamin Library Card System Add Picture signup.php unrestricted upload
- CVE-2025-13561 PoCneedyamin Library Card System card.php sql injection
- CVE-2025-13611 PoCIP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Function
- CVE-2025-13621 PoCeasy-broken-link-checker <= 9.0.2 - Bulk Actions via CSRF
- CVE-2025-13631 PoCeasy-broken-link-checker <= 9.0.2 - Admin+ Stored XSS
- CVE-2025-13641 PoCMicroWord eScan Antivirus USB Protection Service passPrompt stack-based overflow
- CVE-2025-13651 PoCGNU elfutils eu-readelf readelf.c process_symtab buffer overflow
- CVE-2025-13661 PoCMicroWord eScan Antivirus VirusPopUp strcpy stack-based overflow
- CVE-2025-13671 PoCMicroWord eScan Antivirus USB Password sprintf buffer overflow
- CVE-2025-13681 PoCMicroWord eScan Antivirus mwav.conf ReadConfiguration buffer overflow
- CVE-2025-13691 PoCMicroWord eScan Antivirus USB Password os command injection
- CVE-2025-13701 PoCMicroWorld eScan Antivirus Autoscan USB epsdaemon sprintf os command injection
- CVE-2025-13711 PoCGNU elfutils eu-read readelf.c handle_dynamic_symtab null pointer dereference
- CVE-2025-13721 PoCGNU elfutils eu-readelf readelf.c print_string_section buffer overflow
- CVE-2025-13732 PoCsFFmpeg MOV Parser mov.c mov_read_trak null pointer dereference
- CVE-2025-13741 PoCcode-projects Real Estate Property Management System search.php sql injection
- CVE-2025-13761 PoCGNU elfutils eu-strip elf_strptr.c elf_strptr denial of service
- CVE-2025-13771 PoCGNU elfutils eu-strip strip.c gelf_getsymshndx denial of service
- CVE-2025-13781 PoCradare2 rasm2 rasm2.c memory corruption
- CVE-2025-13791 PoCcode-projects Real Estate Property Management System CustomerReport.php sql injection
- CVE-2025-13801 PoCCodezips Gym Management System del_plan.php sql injection
- CVE-2025-13811 PoCcode-projects Real Estate Property Management System ajax_city.php sql injection
- CVE-2025-13821 PoCContact Us By Lord Linus <= 2.6 - Admin+ Stored XSS via CSRF
- CVE-2025-14011 PoCWP Click Info <= 2.7.4 - Reflected XSS
- CVE-2025-14241 PoCPrivilege Escalation Through SUID Binary and Developer Mode
- CVE-2025-14361 PoCLimit Bio <= 1.0 - Stored XSS via CSRF
- CVE-2025-14461 PoCPods < 3.2.8.2 - Admin+ SQL Injection
- CVE-2025-14481 PoCSynway SMG Gateway Management Software 9-12ping.php command injection
- CVE-2025-14521 PoCFavorites < 2.3.5 - Admin+ Stored XSS
- CVE-2025-14531 PoCCategory Posts Widget < 4.9.20 - Admin+ Stored XSS
- CVE-2025-14541 PoCNinja Pages <= 1.4.2 - Admin+ Stored XSS
- CVE-2025-14612 PoCsVuetify XSS through 'eventMoreText' prop of VCalendar
- CVE-2025-14641 PoCBaiyi Cloud Asset Management System admin.house.collect.php sql injection
- CVE-2025-14651 PoClmxcms Maintenance db.inc.php code injection
- CVE-2025-14771 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-14781 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-14851 PoCReal Cookie Banner < 5.1.6 - Admin+ Stored XSS
- CVE-2025-14861 PoCWoWPth <= 2.0 - Reflected XSS
- CVE-2025-14871 PoCWoWPth <= 2.0 - Reflected XSS
- CVE-2025-15161 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-15231 PoCUltimate Dashboard < 3.8.6 - Admin+ Stored XSS
- CVE-2025-15241 PoCUltimate Dashboard < 3.8.6 - Admin+ Stored XSS
- CVE-2025-15251 PoCUltimate Dashboard < 3.8.6 - Admin+ Stored XSS
- CVE-2025-15351 PoCBaiyi Cloud Asset Management System admin.ticket.close.php sql injection
- CVE-2025-15361 PoCRaisecom Multi-Service Intelligent Gateway Request Parameter vpn_template_style.php os command injection
- CVE-2025-15371 PoCHarpia DiagSystem atualatendimento_jpeg.php sql injection
- CVE-2025-15381 PoCD-Link DAP-1320 api set_ws_action heap-based overflow
- CVE-2025-15391 PoCD-Link DAP-1320 storagein.pd-XXXXXX replace_special_char stack-based overflow
- CVE-2025-15431 PoCiteachyou Dreamer CMS ueditor-1.4.3.3 path traversal
- CVE-2025-15441 PoCdingfanzu CMS loadShopInfo.php sql injection
- CVE-2025-15461 PoCBDCOM Behavior Management and Auditing System operate.mds log_operate_clear os command injection
- CVE-2025-15481 PoCiteachyou Dreamer CMS edit cross site scripting
- CVE-2025-15504 PoCsArbitrary Code Execution via Crafted Keras Config for Model Loading
- CVE-2025-15531 PoCpankajindevops scale project cross site scripting
- CVE-2025-15551 PoChzmanyun Education and Training System saveImage unrestricted upload
- CVE-2025-15561 PoCwestboy CicadasCMS Template Management system deserialization
- CVE-2025-15571 PoCOFCMS cross-site request forgery
- CVE-2025-15622 PoCsRecover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit <= 3.5.3 - Missing Authorization to…
- CVE-2025-15751 PoCHarpia DiagSystem atualatendimento_jpeg.php resource injection
- CVE-2025-15761 PoCcode-projects Real Estate Property Management System ajax_state.php sql injection
- CVE-2025-15771 PoCcode-projects Blood Bank System prostatus.php cross site scripting
- CVE-2025-15781 PoCPHPGurukul/Campcodes Online Shopping Portal search-result.php sql injection
- CVE-2025-15791 PoCcode-projects Blood Bank System user.php cross site scripting
- CVE-2025-15801 PoCPHPGurukul Nipah Virus Testing Management System search-report-result.php sql injection
- CVE-2025-15811 PoCPHPGurukul Online Nurse Hiring System book-nurse.php sql injection
- CVE-2025-15821 PoCPHPGurukul Online Nurse Hiring System all-request.php sql injection
- CVE-2025-15831 PoCPHPGurukul Online Nurse Hiring System search-report-details.php sql injection
- CVE-2025-15841 PoCopensolon Solon StaticMappings.java path traversal
- CVE-2025-15851 PoCotale header.html OptionsService cross site scripting
- CVE-2025-15861 PoCcode-projects Blood Bank System A-.php cross site scripting
- CVE-2025-15871 PoCSourceCodester Telecom Billing Management System Add New Record main.cpp addrecords buffer overflow
- CVE-2025-15881 PoCPHPGurukul Online Nurse Hiring System manage-nurse.php path traversal
- CVE-2025-15942 PoCsFFmpeg AAC Encoder aacenc_tns.c ff_aac_search_for_tns stack-based overflow
- CVE-2025-15952 PoCsAnhui Xufan Information Technology EasyCVR getbaseconfig information disclosure
- CVE-2025-15961 PoCSourceCodester Best Church Management Software fpassword.php sql injection
- CVE-2025-15971 PoCSourceCodester Best Church Management Software redirect.php cross site scripting
- CVE-2025-15981 PoCSourceCodester Best Church Management Software asset_crud.php unrestricted upload
- CVE-2025-15991 PoCSourceCodester Best Church Management Software profile_crud.php path traversal
- CVE-2025-16061 PoCSourceCodester Best Employee Management System backups.php information disclosure
- CVE-2025-16071 PoCSourceCodester Best Employee Management System salary_slip.php authorization
- CVE-2025-16081 PoCLB-LINK AC1900 Router set_manpwd websGetVar os command injection
- CVE-2025-16091 PoCLB-LINK AC1900 Router set_cmd websGetVar os command injection
- CVE-2025-16101 PoCLB-LINK AC1900 Router set_blacklist websGetVar os command injection
- CVE-2025-16111 PoCShopXO Template ThemeAdminService.php injection
- CVE-2025-16191 PoCGDPR Cookie Compliance < 4.15.7 - Admin+ Stored XSS
- CVE-2025-16201 PoCGDPR Cookie Compliance < 4.15.7 - Admin+ Stored XSS
- CVE-2025-16211 PoCGDPR Cookie Compliance < 4.15.7 - Admin+ Stored XSS
- CVE-2025-16221 PoCGDPR Cookie Compliance < 4.15.7 - Admin+ Stored XSS
- CVE-2025-16231 PoCGDPR Cookie Compliance < 4.15.9 - Admin+ Stored XSS
- CVE-2025-16241 PoCGDPR Cookie Compliance < 4.15.9 - Admin+ Stored XSS
- CVE-2025-16251 PoCQi Blocks < 1.4 - Contributor+ Stored XSS via Counter Block
- CVE-2025-16261 PoCQi Blocks < 1.4 - Contributor+ Stored XSS vi Countdown Block
- CVE-2025-16271 PoCQi Blocks < 1.4 - Contributor+ Stored XSS via ToC Block
- CVE-2025-16321 PoClibarchive bsdunzip.c list null pointer dereference
- CVE-2025-16391 PoCAnimation Addons for Elementor Pro <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
- CVE-2025-16461 PoCLumsoft ERP ASPX File UploadAjaxAPI.ashx unrestricted upload
- CVE-2025-16481 PoCYawave <= 2.9.1 - Unauthenticated SQL Injection
- CVE-2025-16614 PoCsHUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
- CVE-2025-16651 PoCAvada Builder <= 3.11.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
- CVE-2025-16761 PoChzmanyun Education and Training System pdf2swf os command injection
- CVE-2025-16771 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-16862 PoCsAll versions of the package io.pebbletemplates:pebble are vulnerable to External Control of File Name or Path via the include tag. A high…
- CVE-2025-17041 PoCComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access…
- CVE-2025-17165 PoCspicklescan - Security scanning bypass via 'pip main'
- CVE-2025-17311 PoCAn incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from…
- CVE-2025-17381 PoCMultiple vulnerabilities in Trivision Camera NC227WF
- CVE-2025-17391 PoCMultiple vulnerabilities in Trivision Camera NC227WF
- CVE-2025-17421 PoCpihome-shc PiHome home.php cross site scripting
- CVE-2025-17432 PoCszyx0814 Pichome index.php path traversal
- CVE-2025-17451 PoCLinZhaoguan pb-cms Logout cross-site request forgery
- CVE-2025-17541 PoCMissing Authentication for Critical Function in GitLab
- CVE-2025-17621 PoCEvent Tickets with Ticket Scanner < 2.5.4 - Arbitrary Tickets Deletion via CSRF
- CVE-2025-17631 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-17811 PoCThere is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce…
- CVE-2025-17862 PoCsrizinorg rizin pdb.c msf_stream_directory_free buffer overflow
- CVE-2025-17882 PoCsrizinorg rizin utf8.c rz_utf8_encode heap-based overflow
- CVE-2025-17911 PoCZorlan SkyCaiji Tool.php fileAction unrestricted upload
- CVE-2025-17971 PoCHunan Zhonghe Baiyi Information Technology Baiyiyun Asset Management and Operations System anyUserBoundHouse.php sql injection
- CVE-2025-17981 PoCDesign Comuni Italia < 1.1.2 - Unauthenticated Stored XSS
- CVE-2025-17991 PoCZorlan SkyCaiji Tool.php previewAction server-side request forgery
- CVE-2025-18001 PoCD-Link DAR-7000 HTTP POST Request sxh_vpnlic.php get_ip_addr_details command injection
- CVE-2025-18061 PoCEastnets PaymentSafe URL Default.aspx improper authorization
- CVE-2025-18071 PoCEastnets PaymentSafe Edit Manual Reply directRouter.rfc cross site scripting
- CVE-2025-18121 PoCzj1983 zz SuperZ.java GetUserOrg sql injection
- CVE-2025-18131 PoCzj1983 zz cross-site request forgery
- CVE-2025-18141 PoCTenda AC6 WifiExtraSet stack-based overflow
- CVE-2025-18151 PoCpbrong hrms resource.go HrmsDB improper authorization
- CVE-2025-18161 PoCFFmpeg IAMF File iamf_parse.c audio_element_obu memory leak
- CVE-2025-18171 PoCMini-Tmall Admin Name admin cross site scripting
- CVE-2025-18181 PoCzj1983 zz ZfileAction.upload unrestricted upload
- CVE-2025-18191 PoCTenda AC7 1200M telnet TendaTelnet os command injection
- CVE-2025-18201 PoCzj1983 zz ZworkflowAction.java getOaWid sql injection
- CVE-2025-18211 PoCzj1983 zz ZorgAction.java getUserOrgForUserId sql injection
- CVE-2025-18291 PoCTOTOLINK X18 cstecgi.cgi setMtknatCfg os command injection
- CVE-2025-18301 PoCzj1983 zz Customer Information cross site scripting
- CVE-2025-18311 PoCzj1983 zz ZorgAction.java GetDBUser sql injection
- CVE-2025-18321 PoCzj1983 zz ZroleAction.java getUserList sql injection
- CVE-2025-18331 PoCzj1983 zz HTTP Request Customer_noticeAction.java sendNotice server-side request forgery
- CVE-2025-18341 PoCzj1983 zz resolve unrestricted upload
- CVE-2025-18351 PoCosuuu LightPicture Api.php upload unrestricted upload
- CVE-2025-18401 PoCESAFENET CDG updateorg.jsp sql injection
- CVE-2025-18411 PoCESAFENET CDG ClientSortLog.jsp sql injection
- CVE-2025-18431 PoCMini-Tmall ProductMapper.java select sql injection
- CVE-2025-18441 PoCESAFENET CDG backupLogDetail.jsp sql injection
- CVE-2025-18451 PoCESAFENET DSM examExportPDF command injection
- CVE-2025-18461 PoCzj1983 zz File ZfileAction.java deleteLocalFile denial of service
- CVE-2025-18471 PoCzj1983 zz improper authorization
- CVE-2025-18481 PoCzj1983 zz import_data_check server-side request forgery
- CVE-2025-18491 PoCzj1983 zz import_data_todb server-side request forgery
- CVE-2025-18501 PoCCodezips College Management System university.php sql injection
- CVE-2025-18511 PoCTenda AC7 SetFirewallCfg formSetFirewallCfg stack-based overflow
- CVE-2025-18521 PoCTotolink EX1800T cstecgi.cgi loginAuth buffer overflow
- CVE-2025-18531 PoCTenda AC8 Parameter SetIpMacBind sub_49E098 stack-based overflow
- CVE-2025-18541 PoCCodezips Gym Management System del_member.php sql injection
- CVE-2025-18551 PoCPHPGurukul Online Shopping Portal product-details.php sql injection
- CVE-2025-18561 PoCCodezips Gym Management System gen_invoice.php sql injection
- CVE-2025-18571 PoCPHPGurukul Nipah Virus Testing Management System check_availability.php sql injection
- CVE-2025-18581 PoCCodezips Online Shopping Website success.php sql injection
- CVE-2025-18591 PoCPHPGurukul News Portal login.php sql injection
- CVE-2025-18761 PoCD-Link DAP-1562 HTTP Header http_request_parse stack-based overflow
- CVE-2025-18771 PoCD-Link DAP-1562 HTTP POST Request pure_auth_check null pointer dereference
- CVE-2025-18891 PoCpicklescan - Security scanning bypass via non-standard file extensions
- CVE-2025-18901 PoCshishuocms ManageUpLoadAction.java handleRequest unrestricted upload
- CVE-2025-18911 PoCshishuocms cross-site request forgery
- CVE-2025-18921 PoCshishuocms Directory Deletion Page add.json cross site scripting
- CVE-2025-18931 PoCOpen5GS AMF gmm-sm.c gmm_state_authentication denial of service
- CVE-2025-18941 PoCPHPGurukul Restaurant Table Booking System search-result.php sql injection
- CVE-2025-18951 PoCTenda TX3 setMacFilterCfg buffer overflow
- CVE-2025-18961 PoCTenda TX3 SetStaticRouteCfg buffer overflow
- CVE-2025-18971 PoCTenda TX3 SetNetControlList buffer overflow
- CVE-2025-18981 PoCTenda TX3 openSchedWifi buffer overflow
- CVE-2025-18991 PoCTenda TX3 setPptpUserList buffer overflow
- CVE-2025-19001 PoCPHPGurukul Restaurant Table Booking System add-table.php sql injection
- CVE-2025-19011 PoCPHPGurukul Restaurant Table Booking System check_availability.php sql injection
- CVE-2025-19021 PoCPHPGurukul Student Record System password-recovery.php sql injection
- CVE-2025-19031 PoCCodezips Online Shopping Website cart_add.php sql injection
- CVE-2025-19051 PoCSourceCodester Employee Management System employee.php cross site scripting
- CVE-2025-19061 PoCPHPGurukul Restaurant Table Booking System profile.php sql injection
- CVE-2025-19081 PoCBusiness Logic Errors in GitLab
- CVE-2025-19101 PoCWatchGuard Mobile VPN with SSL Local Privilege Escalation via Update Package
- CVE-2025-19131 PoCProduct Import Export for WooCommerce <= 2.5.0 - Authenticated (Admin+) PHP Object Injection via form_data Parameter
- CVE-2025-19252 PoCsOpen5GS AMF nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of service
- CVE-2025-19441 PoCpicklescan ZIP archive manipulation attack leads to crash
- CVE-2025-19452 PoCspicklescan - Zip Flag Bit Exploit Crashes Picklescan But Not PyTorch
- CVE-2025-19461 PoChzmanyun Education and Training System exportPDF command injection
- CVE-2025-19471 PoChzmanyun Education and Training System UploadImageController.java scorm command injection
- CVE-2025-19491 PoCZZCMS URL register_nodb.php cross site scripting
- CVE-2025-19521 PoCPHPGurukul Restaurant Table Booking System password-recovery.php sql injection
- CVE-2025-19541 PoCPHPGurukul Human Metapneumovirus Testing Management System login.php sql injection
- CVE-2025-19551 PoCcode-projects Online Class and Exam Scheduling System profile.php cross site scripting
- CVE-2025-19561 PoCcode-projects Shopping Portal Login index.php sql injection
- CVE-2025-19571 PoCcode-projects Blood Bank System o+.php cross site scripting
- CVE-2025-19581 PoCaaluoxiang oa_system address-mapper.xml sql injection
- CVE-2025-19591 PoCCodezips Gym Management System change_s_pwd.php sql injection
- CVE-2025-19611 PoCSourceCodester Best Church Management Software web_crud.php sql injection
- CVE-2025-19622 PoCsprojectworlds Online Hotel Booking addroom.php sql injection
- CVE-2025-19631 PoCprojectworlds Online Hotel Booking reservation.php sql injection
- CVE-2025-19641 PoCprojectworlds Online Hotel Booking booknow.php sql injection
- CVE-2025-19651 PoCprojectworlds Online Hotel Booking login.php sql injection
- CVE-2025-19661 PoCPHPGurukul Pre-School Enrollment System index.php sql injection
- CVE-2025-19671 PoCcode-projects Blood Bank Management System donor.php cross site scripting
- CVE-2025-197431 PoCsingress-nginx admission controller RCE escalation
- CVE-2025-19861 PoCGutentor < 3.4.7 - Admin+ SQL Injection