CVE-2025-23000 to CVE-2025-23999
41 CVEs with public proof-of-concept exploits.
- CVE-2025-230011 PoCA Host header injection vulnerability exists in CTFd 3.7.5, due to the application failing to properly validate or sanitize the Host…
- CVE-2025-230261 PoCHTML templates containing Javascript template strings are subject to XSS in jte
- CVE-2025-230301 PoCCross-Site Scripting (XSS) Reflected endpoint 'cadastro_funcionario.php' parameter 'cpf' in WeGIA
- CVE-2025-230311 PoCCross-Site Scripting (XSS) Stored endpoint 'adicionar_alergia.php' parameter 'nome' in WeGIA
- CVE-2025-230321 PoCCross-Site Scripting (XSS) Stored endpoint 'adicionar_escala.php' parameter 'escala' in WeGIA
- CVE-2025-230331 PoCCross-Site Scripting (XSS) Stored endpoint 'adicionar_situacao.php' parameter 'situacao' in WeGIA
- CVE-2025-230341 PoCCross-Site Scripting (XSS) Reflected endpoint 'tags.php' parameter 'msg_e' in WeGIA
- CVE-2025-230351 PoCCross-Site Scripting (XSS) Stored endpoint 'adicionar_tipo_quadro_horario.php' parameter 'tipo' in WeGIA
- CVE-2025-230361 PoCCross-Site Scripting (XSS) Reflected endpoint 'pre_cadastro_funcionario.php' parameter 'msg_e' in WeGIA
- CVE-2025-230371 PoCCross-Site Scripting (XSS) Stored endpoint 'control.php' parameter 'cargo' in WeGIA
- CVE-2025-230381 PoCCross-Site Scripting (XSS) Stored endpoint 'remuneracao.php ' parameter 'descricao' in WeGIA
- CVE-2025-230401 PoCMaliciously crafted remote URLs could lead to credential leak in GitHub Desktop
- CVE-2025-230422 PoCsGradio Blocked Path ACL Bypass Vulnerability
- CVE-2025-230441 PoCCross-Site Request Forgery (CSRF) allows creating admin account with POST request
- CVE-2025-230481 PoCApache HTTP Server: mod_ssl access control bypass with session resumption
- CVE-2025-230612 PoCsMongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue…
- CVE-2025-231201 PoCA vulnerability allowing remote code execution (RCE) for domain users.
- CVE-2025-231671 PoCA flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`.This…
- CVE-2025-231982 PoCsStored-XSS-LibreNMS-Display-Name in librenms
- CVE-2025-231992 PoCsStored XSS-LibreNMS-Ports in librenms
- CVE-2025-232002 PoCsStored XSS-LibreNMS-Misc Section in librenms
- CVE-2025-232012 PoCsReflected Cross-site Scripting on error alert in librenms
- CVE-2025-232081 PoCIdP group membership revocation ignored in zot
- CVE-2025-232091 PoCKEVPotential RCE with a compromised security key in craft/cms
- CVE-2025-232113 PoCsTandoor Recipes - SSTI - Remote Code Execution
- CVE-2025-232121 PoCTandoor Recipes - Local file disclosure - Users can read the content of any file on the server
- CVE-2025-232131 PoCTandoor Recipes - Stored XSS through Unrestricted File Upload
- CVE-2025-232151 PoCPMD Designer's release key passphrase (GPG) available on Maven Central in cleartext
- CVE-2025-232181 PoCWeGIA has a SQL Injection endpoint 'adicionar_especie.php' parameter 'especie'
- CVE-2025-232191 PoCWeGIA has a SQL Injection endpoint 'adicionar_cor.php' parameter 'cor'
- CVE-2025-232201 PoCWeGIA has a SQL Injection endpoint 'adicionar_raca.php' parameter 'raca'
- CVE-2025-232211 PoCFedify has an Infinite loop and Blind SSRF found inside the Webfinger mechanism
- CVE-2025-232471 PoCNVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer…
- CVE-2025-232664 PoCsNVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker…
- CVE-2025-233391 PoCNVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by…
- CVE-2025-233681 PoCOrg.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli
- CVE-2025-233692 PoCsImproper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper Validation
- CVE-2025-234191 PoCTLS Session Resumption Vulnerability
- CVE-2025-239221 PoCWordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
- CVE-2025-239421 PoCWordPress WP Load Gallery Plugin <= 2.1.6 - Arbitrary File Upload vulnerability
- CVE-2025-239681 PoCWordPress AiBud WP plugin <= 1.9 - Arbitrary File Upload vulnerability