CVE-2025-22000 to CVE-2025-22999
72 CVEs with public proof-of-concept exploits.
- CVE-2025-221315 PoCsCross-Site Scripting (XSS) vulnerability in generateNavigation() function
- CVE-2025-221321 PoCWeGIA has a Cross-Site Scripting (XSS) in File Upload Field
- CVE-2025-221331 PoCWeGIA Allows Arbitrary File Upload with Remote Code Execution (RCE)
- CVE-2025-221392 PoCsWeGIA Cross-Site Scripting (XSS) Reflected endpoint `configuracao_geral.php` parameter `msg`
- CVE-2025-221402 PoCsWeGIA SQL Injection (Blind Time-Based) endpoint 'dependente_listar_um.php' parameter 'id_dependente'
- CVE-2025-221412 PoCsWeGIA SQL Injection (Blind Time-Based) endpoint 'verificar_recursos_cargo.php' parameter 'cargo'
- CVE-2025-221421 PoCCross-site Scripting in NamelessMC
- CVE-2025-221431 PoCWeGIA Cross-Site Scripting (XSS) Reflected endpoint 'listar_permissoes.php' parameter 'msg_e'
- CVE-2025-221441 PoCAccount Takeover in NamelessMC
- CVE-2025-221531 PoCtry/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
- CVE-2025-222061 PoCExtension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.2 for Joomla
- CVE-2025-222081 PoCExtension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.3 for Joomla
- CVE-2025-222091 PoCExtension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.3 for Joomla
- CVE-2025-222101 PoCExtension - hikashop.com - SQL injection in Hikashop component version 3.3.0 - 5.1.4 for Joomla
- CVE-2025-222141 PoCLandray EIS 2001 through 2006 allows Message/fi_message_receiver.aspx?replyid= SQL injection.
- CVE-2025-222231 PoCSpring Security 6.4.0 - 6.4.3 may not correctly locate method security annotations on parameterized types or methods. This may cause an…
- CVE-2025-222241 PoCKEVVMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious…
- CVE-2025-222351 PoCSpring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
- CVE-2025-222941 PoCWordPress Custom Field For WP Job Manager plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2025-223521 PoCWordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin <= 1.4.9 - SQL Injection vulnerability
- CVE-2025-223811 PoCAggie 2.6.1 has a Host Header injection vulnerability in the forgot password functionality, allowing an attacker to reset a user's password.
- CVE-2025-224576 PoCsKEVA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti…
- CVE-2025-225101 PoCWordPress WC Price History for Omnibus plugin <= 2.1.4 - PHP Object Injection vulnerability
- CVE-2025-225961 PoCWeGIA has a Cross-Site Scripting (XSS) Reflected endpoint 'modulos_visiveis.php' parameter'msg_c'
- CVE-2025-225971 PoCWeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'CobrancaController.php' parameter 'local_recepcao'
- CVE-2025-225981 PoCWeGIA has a Cross-Site Scripting (XSS) Stored endpoint 'cadastrarSocio.php' parameter 'nome'
- CVE-2025-225991 PoCWeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `home.php` parameter `msg_c`
- CVE-2025-226001 PoCWeGIA has a Cross-Site Scripting (XSS) Reflected endpoint `configuracao_doacao.php` parameter `avulso`
- CVE-2025-226031 PoCAutoGPT SSRF vulnerability
- CVE-2025-226042 PoCsCacti has Authenticated RCE via multi-line SNMP responses
- CVE-2025-226051 PoCCoolify OS Command Injection Vulnerability in SSH Command Generation
- CVE-2025-226061 PoCCoolify Command Injection Vulnerability in Project Name
- CVE-2025-226081 PoCCoolify Vulnerable to Revocation of Arbitrary Team Invitations (DOS)
- CVE-2025-226091 PoCCoolify Vulnerable to Private Key Hijacking / Remote Command Execution (RCE)
- CVE-2025-226101 PoCCoolify Vulnerable to OAuth Secrets Leak
- CVE-2025-226111 PoCCoolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE)
- CVE-2025-226121 PoCCoolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE)
- CVE-2025-226131 PoCWeGIA Cross-Site Scripting (XSS) Stored endpoint 'informacao_adicional.php' parameter 'descricao'
- CVE-2025-226141 PoCWeGIA Cross-Site Scripting (XSS) Stored endpoint 'dependente_editarInfoPessoal.php ' parameters 'nome' 'SobrenomeForm'
- CVE-2025-226151 PoCWeGIA Cross-Site Scripting (XSS) Reflected endpoint 'Cadastro_Atendido.php' parameter 'cpf'
- CVE-2025-226161 PoCWeGIA Cross-Site Scripting (XSS) Stored endpoint 'dependente_parentesco_adicionar.php' parameter 'descricao'
- CVE-2025-226171 PoCWeGIA Cross-Site Scripting (XSS) Reflected endpoint 'editar_socio.php' parameter 'socio'
- CVE-2025-226181 PoCWeGIA Cross-Site Scripting (XSS) Stored endpoint 'adicionar_cargo.php' parameter 'cargo'
- CVE-2025-226191 PoCWeGIA Cross-Site Scripting (XSS) Reflected endpoint 'editar_permissoes.php' parameter 'msg_c'
- CVE-2025-226202 PoCsgix-worktree-state nonexclusive checkout sets executable files world-writable
- CVE-2025-226521 PoCWordPress Payment Forms for Paystack plugin <= 4.0.1 - SQL Injection vulnerability
- CVE-2025-227101 PoCWordPress Smart Manager Plugin <= 8.52.0 - SQL Injection vulnerability
- CVE-2025-227771 PoCWordPress GiveWP Plugin <= 3.19.3 - PHP Object Injection vulnerability
- CVE-2025-227831 PoCWordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerability
- CVE-2025-227852 PoCsWordPress Course Booking System plugin <= 6.0.6 - SQL Injection vulnerability
- CVE-2025-228281 PoCApache CloudStack: Unauthorised access to annotations
- CVE-2025-228701 PoCHTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net
- CVE-2025-229001 PoCTotolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the setWanConfig…
- CVE-2025-229041 PoCRE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.
- CVE-2025-229051 PoCRE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.
- CVE-2025-229061 PoCRE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.
- CVE-2025-229071 PoCRE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.
- CVE-2025-229112 PoCsRE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.
- CVE-2025-229121 PoCRE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
- CVE-2025-229131 PoCRE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.
- CVE-2025-229161 PoCRE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.
- CVE-2025-229371 PoCAn issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.
- CVE-2025-229381 PoCAdtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.
- CVE-2025-229401 PoCIncorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin password.
- CVE-2025-229411 PoCA command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate privileges to root…
- CVE-2025-229521 PoCelestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can…
- CVE-2025-229531 PoCA SQL injection vulnerability exists in Epicor HCM 2021 1.9, with patches available: 5.16.0.1033/HCM2022, 5.17.0.1146/HCM2023, and…
- CVE-2025-229541 PoCGetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid…
- CVE-2025-229632 PoCsTeedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.
- CVE-2025-229641 PoCDDSN Interactive cm3 Acora CMS version 10.1.1 has an unauthenticated time-based blind SQL Injection vulnerability caused by insufficient…
- CVE-2025-229682 PoCsAn issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions
- CVE-2025-229941 PoCO2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings.