CVE-2025-24000 to CVE-2025-24999
82 CVEs with public proof-of-concept exploits.
- CVE-2025-240001 PoCWordPress Post SMTP plugin <= 3.2.0 - Account Takeover Vulnerability
- CVE-2025-240021 PoCMQTT DoS Vulnerability in German EV Charging Stations
- CVE-2025-240031 PoCMQTT OOB Write Vulnerability in EichrechtAgents of German EV Charging Stations
- CVE-2025-240041 PoCUSB-C Buffer Overflow via Display Interface in EV Charging Stations
- CVE-2025-240051 PoCLocal Privilege Escalation via Vulnerable SSH Script
- CVE-2025-240061 PoCPrivilege Escalation via Insecure SSH Permissions
- CVE-2025-240102 PoCsVite allows any websites to send any requests to the development server and read the response
- CVE-2025-240111 PoCUmbraco CMS Vulnerable to User Enumeration Feasible Based On Management API Timing and Response Codes
- CVE-2025-240151 PoCDeno's AES GCM authentication tags are not verified
- CVE-2025-2401611 PoCsKEVRemote code execution in Wazuh server
- CVE-2025-240171 PoCYesWiki Vulnerable to Unauthenticated DOM Based XSS
- CVE-2025-240181 PoCYesWiki Vulnerable to Authenticated Stored XSS
- CVE-2025-240191 PoCYesWiki vulnerable to authenticated arbitrary file deletion
- CVE-2025-240201 PoCWeGIA Open Redirect vulnerability
- CVE-2025-240281 PoCCross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in Joplin
- CVE-2025-240351 PoCWindows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2025-2405420 PoCsKEVNTLM Hash Disclosure Spoofing Vulnerability
- CVE-2025-2407131 PoCsMicrosoft Windows File Explorer Spoofing Vulnerability
- CVE-2025-240762 PoCsMicrosoft Windows Cross Device Service Elevation of Privilege Vulnerability
- CVE-2025-240853 PoCsKEVA use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS…
- CVE-2025-241042 PoCsThis issue was addressed with improved handling of symlinks. This issue is fixed in iPadOS 17.7.4, iOS 18.3 and iPadOS 18.3. Restoring a…
- CVE-2025-241181 PoCThe issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An…
- CVE-2025-241323 PoCsThe issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126,…
- CVE-2025-241981 PoCThis issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and…
- CVE-2025-242012 PoCsKEVAn out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2,…
- CVE-2025-242032 PoCsThe issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma…
- CVE-2025-242041 PoCThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
- CVE-2025-242251 PoCAn injection issue was addressed with improved input validation. This issue is fixed in iPadOS 17.7.7, iOS 18.5 and iPadOS 18.5.…
- CVE-2025-242522 PoCsA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura…
- CVE-2025-242572 PoCsAn out-of-bounds write issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4,…
- CVE-2025-242711 PoCAn access issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura…
- CVE-2025-242931 PoCActive Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image…
- CVE-2025-243532 PoCsDirectus privilege escalation vulnerability using Share feature
- CVE-2025-243542 PoCsimgproxy is vulnerable to SSRF against 0.0.0.0
- CVE-2025-243551 PoCUpdatecli may expose Maven credentials in console output
- CVE-2025-243591 PoCASTEVAL Vulnerable to Maliciously Crafted Format Strings Leading to Sandbox Escape
- CVE-2025-243611 PoCOpening a malicious website while running a Nuxt dev server could allow read-only access to code
- CVE-2025-243641 PoCvaultwarden allows RCE in the admin panel
- CVE-2025-243651 PoCvaultwarden allows escalation of privilege via variable confusion in OrgHeaders trait
- CVE-2025-243678 PoCsCacti allows Arbitrary File Creation leading to RCE
- CVE-2025-243681 PoCCacti has a SQL Injection vulnerability when using tree rules through Automation API
- CVE-2025-243701 PoCDjango-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
- CVE-2025-244721 PoCKEVAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy…
- CVE-2025-245149 PoCsingress-nginx controller - configuration injection via unsanitized auth-url annotation
- CVE-2025-245821 PoCWordPress 12 Step Meeting List plugin <= 3.16.5 - Sensitive Data Exposure vulnerability
- CVE-2025-245871 PoCWordPress Email Subscription Popup plugin <= 1.2.23 - SQL Injection vulnerability
- CVE-2025-246591 PoCWordPress Premium Packages – Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection vulnerability
- CVE-2025-246621 PoCWordPress LearnDash LMS Plugin <= 4.20.0.1 - Broken Access Control vulnerability
- CVE-2025-247523 PoCsWordPress Essential Addons for Elementor plugin <= 6.0.14 - Reflected Cross Site Scripting (XSS) vulnerability
- CVE-2025-247863 PoCsPath traversal opening Sqlite3 database in WhoDB
- CVE-2025-247871 PoCParameter injection in DB connection URIs leading to local file inclusion in WhoDB
- CVE-2025-247933 PoCsSnowflake Connector for Python has an SQL Injection in write_pandas
- CVE-2025-247971 PoCMeshtastic incorrectly hands malformed packets leads to controlled buffer overflow
- CVE-2025-247981 PoCMeshtastic crashes via an unimplemented routing module reply
- CVE-2025-247995 PoCsGLPI allows unauthenticated SQL injection through the inventory endpoint
- CVE-2025-248013 PoCsGLPI allows authenticated remote code execution
- CVE-2025-2481360 PoCsKEVApache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
- CVE-2025-2489350 PoCsKEVRemote code execution as guest via SolrSearchMacros request in xwiki
- CVE-2025-248941 PoCSAML Response Signature Verification Bypass in SPID.AspNetCore.Authentication
- CVE-2025-248951 PoCSAML Response Signature Verification Bypass in CIE.AspNetCore.Authentication
- CVE-2025-248991 PoCDisclosure of Sensitive User Information via API in reNgine
- CVE-2025-249011 PoCSQL Injection endpoint 'deletar_permissao.php' parameter 'c', 'a', 'r' in WeGIA
- CVE-2025-249021 PoCSQL Injection endpoint 'salvar_cargo.php' parameter 'id_cargo' in WeGIA
- CVE-2025-249051 PoCSQL Injection endpoint 'get_codigobarras_cobranca.php' parameter 'codigo' in WeGIA
- CVE-2025-249061 PoCSQL Injection endpoint 'get_detalhes_cobranca.php' parameter 'codigo' in WeGIA
- CVE-2025-249571 PoCSQL Injection endpoint 'get_detalhes_socio.php' parameter 'id_socio' in WeGIA
- CVE-2025-249581 PoCSQL Injection endpoint 'salvar_tag.php' parameter 'id_tag' in WeGIA
- CVE-2025-249621 PoCCommand Injection in reNgine
- CVE-2025-249634 PoCsBrowser mode serves arbitrary files in vitest
- CVE-2025-249642 PoCsRemote Code Execution when accessing a malicious website while Vitest API server is listening
- CVE-2025-249661 PoCHTML Injection in reNgine
- CVE-2025-249671 PoCStored XSS on Admin Panel When Deleting a User in reNgine
- CVE-2025-249681 PoCBusiness Logic And Unrestricted Project Deletion Lead To Take Over the System in reNgine
- CVE-2025-249702 PoCsSslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
- CVE-2025-249711 PoCOS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop
- CVE-2025-249752 PoCsFirebird Non-Authorized Access to Encrypted Database Using Execute Statement on External
- CVE-2025-249801 PoCPimcore Admin Classic Bundle allows user enumeration
- CVE-2025-249811 PoCParsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc
- CVE-2025-249831 PoCKEVWindows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
- CVE-2025-249851 PoCKEVWindows Fast FAT File System Driver Remote Code Execution Vulnerability
- CVE-2025-249901 PoCKEVWindows Agere Modem Driver Elevation of Privilege Vulnerability
- CVE-2025-249991 PoCMicrosoft SQL Server Elevation of Privilege Vulnerability