CVE-2025-25000 to CVE-2025-25999
101 CVEs with public proof-of-concept exploits.
- CVE-2025-250141 PoCKibana arbitrary code execution via prototype pollution
- CVE-2025-250344 PoCsSugarCRM PHP Deserialization RCE
- CVE-2025-250373 PoCsAquatronica Controller System Complete Information Disclosure
- CVE-2025-250384 PoCsMiniDVBLinux Root Command Injection
- CVE-2025-250623 PoCsAn XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text…
- CVE-2025-250631 PoCAn XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It does not sufficiently validate uploaded SVG…
- CVE-2025-251011 PoCWordPress Munk Sites plugin <= 1.0.7 - CSRF to Arbitrary Plugin Installation vulnerability
- CVE-2025-251631 PoCWordPress Plugin A/B Image Optimizer Plugin <= 3.3 - Arbitrary File Download vulnerability
- CVE-2025-251841 PoCPossible Log Injection in Rack::CommonLogger
- CVE-2025-251861 PoCNet::IMAP vulnerable to possible DoS by memory exhaustion
- CVE-2025-251871 PoCCross-site Scripting in Goto Anything allows arbitrary code execution in Joplin
- CVE-2025-251911 PoCGroup-Office has a Stored XSS Vulnerability via user's name field
- CVE-2025-251941 PoCServer-Side Request Forgery (SSRF) in activitypub_federation
- CVE-2025-251983 PoCsmailcow: dockerized vulnerable to password reset poisoning
- CVE-2025-252001 PoCKoa has Inefficient Regular Expression Complexity
- CVE-2025-252052 PoCsRemote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
- CVE-2025-252312 PoCsOmnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to…
- CVE-2025-252562 PoCsAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM…
- CVE-2025-2525714 PoCsKEVAn improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiWeb…
- CVE-2025-252792 PoCsArbitrary file read in Mattermost Boards via import & export board archive
- CVE-2025-252821 PoCPotential Insecure Direct Object Reference (IDOR) vulnerability in ragflow
- CVE-2025-252831 PoCparse-duraton vulnerable to Regex Denial of Service that results in event loop delay and out of memory
- CVE-2025-252851 PoC@octokit/endpoint has a Regular Expression in parse that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
- CVE-2025-252881 PoC@octokit/plugin-paginate-rest has a Regular Expression in iterator that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
- CVE-2025-252891 PoC@octokit/request-error has a Regular Expression in index that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
- CVE-2025-252901 PoC@octokit/request has a Regular Expression in fetchWrapper that Leads to ReDoS Vulnerability Due to Catastrophic Backtracking
- CVE-2025-252912 PoCsruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
- CVE-2025-252921 PoCRuby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
- CVE-2025-252931 PoCruby-saml vulnerable to Remote Denial of Service (DoS) with compressed SAML responses
- CVE-2025-252951 PoCLabel Studio has a Path Traversal Vulnerability via image Field
- CVE-2025-252965 PoCsLabel Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint
- CVE-2025-252971 PoCLabel Studio allows Server-Side Request Forgery in the S3 Storage Endpoint
- CVE-2025-253051 PoCSSL validation for outgoing requests in Home Assistant Core and used libs not correct
- CVE-2025-253431 PoCTenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
- CVE-2025-253611 PoCAn arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to…
- CVE-2025-254261 PoCyshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface.
- CVE-2025-254542 PoCsTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanSpeed2.
- CVE-2025-254552 PoCsTenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via wanMTU2.
- CVE-2025-254601 PoCA stored Cross-Site Scripting (XSS) vulnerability was identified in FlatPress 1.3.1 within the "Add Entry" feature. This vulnerability…
- CVE-2025-254611 PoCA Stored Cross-Site Scripting (XSS) vulnerability exists in SeedDMS 6.0.29. A user or rogue admin with the "Add Category" permission can…
- CVE-2025-254621 PoCA SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote…
- CVE-2025-254681 PoCFFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/mem.c.
- CVE-2025-254691 PoCFFmpeg git-master before commit d5873b was discovered to contain a memory leak in the component libavutil/iamf.c.
- CVE-2025-254761 PoCA stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary…
- CVE-2025-254771 PoCA host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would…
- CVE-2025-254781 PoCThe account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads…
- CVE-2025-255051 PoCTenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.
- CVE-2025-255071 PoCThere is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote…
- CVE-2025-255101 PoCTenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the get_parentControl_list_Info function.
- CVE-2025-255281 PoCMultiple buffer overflow vulnerabilities in Wavlink WL-WN575A3 RPT75A3.V4300, which are caused by not performing strict length checks on…
- CVE-2025-255701 PoCVue Vben Admin 2.10.1 allows unauthorized login to the backend due to an issue with hardcoded credentials.
- CVE-2025-255792 PoCsTOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
- CVE-2025-256121 PoCFS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration…
- CVE-2025-256141 PoCIncorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation, which allows teachers to update the personal data of…
- CVE-2025-256151 PoCUnifiedtransform 2.0 is vulnerable to Incorrect Access Control which allows viewing attendance list for all class sections.
- CVE-2025-256161 PoCUnifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows students to modify rules for exams. The affected endpoint is…
- CVE-2025-256171 PoCIncorrect Access Control in Unifiedtransform 2.X leads to Privilege Escalation allowing teachers to create syllabus.
- CVE-2025-256181 PoCIncorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by…
- CVE-2025-256201 PoCUnifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in the Create assignment function.
- CVE-2025-256211 PoCUnifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected…
- CVE-2025-256321 PoCTenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.
- CVE-2025-256341 PoCA vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo.…
- CVE-2025-256351 PoCTOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input…
- CVE-2025-256631 PoCA vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExtraSet. The…
- CVE-2025-256641 PoCTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 function.
- CVE-2025-256671 PoCTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentControl_list_Info.
- CVE-2025-256681 PoCTenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 function.
- CVE-2025-256911 PoCA PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a…
- CVE-2025-257231 PoCBuffer Overflow vulnerability in GPAC version 2.5 allows a local attacker to execute arbitrary code.
- CVE-2025-257471 PoCCross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive…
- CVE-2025-257491 PoCAn issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength…
- CVE-2025-257631 PoCcrmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
- CVE-2025-257741 PoCAn issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may…
- CVE-2025-257841 PoCAn arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary…
- CVE-2025-257931 PoCSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.
- CVE-2025-257941 PoCSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.
- CVE-2025-257961 PoCSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.
- CVE-2025-257971 PoCSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.
- CVE-2025-258001 PoCSeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.
- CVE-2025-258021 PoCSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.
- CVE-2025-258131 PoCSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.
- CVE-2025-258751 PoCA vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The…
- CVE-2025-258761 PoCA vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /delete.php. The…
- CVE-2025-258771 PoCA vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /admin.php. The…
- CVE-2025-258781 PoCA vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The…
- CVE-2025-259071 PoCtianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows…
- CVE-2025-259141 PoCSQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter
- CVE-2025-259161 PoCwuzhicms v4.1.0 has a Cross Site Scripting (XSS) vulnerability in del function in \coreframe\app\member\admin\group.php.
- CVE-2025-259421 PoCAn issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid…
- CVE-2025-259431 PoCBuffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom…
- CVE-2025-259441 PoCBuffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically…
- CVE-2025-259451 PoCAn issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in…
- CVE-2025-259461 PoCAn issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in…
- CVE-2025-259471 PoCAn issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in…
- CVE-2025-259671 PoCAcora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into…
- CVE-2025-259681 PoCDDSN Interactive cm3 Acora CMS version 10.1.1 contains an improper access control vulnerability. An editor-privileged user can access…
- CVE-2025-259751 PoCAn issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function
- CVE-2025-259771 PoCAn issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
- CVE-2025-259831 PoCAn issue in Macro-video Technologies Co.,Ltd V380 Pro android application 2.1.44 and V380 Pro android application 2.1.64 allows an…
- CVE-2025-259841 PoCAn issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to…
- CVE-2025-259851 PoCAn issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to…