CVE-2025-26000 to CVE-2025-26999
61 CVEs with public proof-of-concept exploits.
- CVE-2025-260141 PoCA Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.
- CVE-2025-260421 PoCUptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a…
- CVE-2025-260581 PoCWebkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected…
- CVE-2025-260621 PoCAn access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings…
- CVE-2025-260631 PoCAn issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted…
- CVE-2025-260641 PoCA cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts…
- CVE-2025-260651 PoCA cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows attackers to execute arbitrary web scripts…
- CVE-2025-261251 PoCAn exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate…
- CVE-2025-261531 PoCA Stored XSS vulnerability exists in the message compose feature of Chamilo LMS 1.11.28. Attackers can inject malicious scripts into…
- CVE-2025-261591 PoCLaravel Starter 11.11.0 is vulnerable to Cross Site Scripting (XSS) in the tags feature. Any user with the ability of create or modify…
- CVE-2025-261984 PoCsCloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails…
- CVE-2025-261991 PoCCloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over…
- CVE-2025-262021 PoCCross-Site Scripting (XSS) vulnerability exists in the WPA/WAPI Passphrase field of the Wireless Security settings (2.4GHz & 5GHz bands)…
- CVE-2025-262101 PoCDeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepseeksvc.com domain.…
- CVE-2025-262401 PoCIn JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server…
- CVE-2025-262411 PoCA SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to…
- CVE-2025-262603 PoCsPlenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as…
- CVE-2025-262632 PoCsGeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to credentials disclosure…
- CVE-2025-262642 PoCsGeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its…
- CVE-2025-263041 PoCA memory leak has been identified in the parseSWF_EXPORTASSETS function in util/parser.c of libming v0.4.8.
- CVE-2025-263051 PoCA memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a…
- CVE-2025-263061 PoCA memory leak has been identified in the readSizedString function in util/read.c of libming v0.4.8, which allows attackers to cause a…
- CVE-2025-263071 PoCA memory leak has been identified in the parseSWF_IMPORTASSETS2 function in util/parser.c of libming v0.4.8, which allows attackers to…
- CVE-2025-263081 PoCA memory leak has been identified in the parseSWF_FILTERLIST function in util/parser.c of libming v0.4.8, which allows attackers to cause…
- CVE-2025-263091 PoCA memory leak has been identified in the parseSWF_DEFINESCENEANDFRAMEDATA function in util/parser.c of libming v0.4.8, which allows…
- CVE-2025-263101 PoCMultiple memory leaks have been identified in the ABC file parsing functions (parseABC_CONSTANT_POOL and `parseABC_FILE) in util/parser.c…
- CVE-2025-263111 PoCMultiple memory leaks have been identified in the clip actions parsing functions (parseSWF_CLIPACTIONS and parseSWF_CLIPACTIONRECORD) in…
- CVE-2025-263181 PoChb.exe in TSplus Remote Access before 17.30 2024-10-30 allows remote attackers to retrieve a list of all domain accounts currently…
- CVE-2025-263194 PoCsFlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
- CVE-2025-263261 PoCA vulnerability was identified in the NVDA Remote (version 2.6.4) and Tele NVDA Remote (version 2025.3.3) remote connection add-ons, which…
- CVE-2025-263993 PoCsKEVSolarWinds Web Help Desk Deserialization of Untrusted Data Privilege Escalation Vulnerability
- CVE-2025-264171 PoCIn checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared…
- CVE-2025-264431 PoCIn parseHtml of HtmlToSpannedParser.java, there is a possible way to install apps without allowing installation from unknown sources due…
- CVE-2025-264651 PoCOpenssh: machine-in-the-middle attack if verifyhostkeydns is enabled
- CVE-2025-264664 PoCsOpenssh: denial-of-service in openssh
- CVE-2025-265291 PoCStored XSS risk in admin live log
- CVE-2025-266051 PoCSQL Injection endpoint 'deletar_cargo.php' parameter 'id_cargo' in WeGIA
- CVE-2025-266061 PoCSQL Injection endpoint 'informacao_adicional.php' parameter 'id_descricao' in WeGIA
- CVE-2025-266071 PoCSQL Injection endpoint 'documento_excluir.php' parameter 'id_funcionario' in WeGIA
- CVE-2025-266081 PoCSQL Injection endpoint 'dependente_docdependente.php' parameter 'id_dependente', 'id_doc' in WeGIA
- CVE-2025-266091 PoCSQL Injection endpoint 'familiar_docfamiliar.php' parameter 'id_dependente', 'id_doc' in WeGIA
- CVE-2025-266101 PoCSQL Injection endpoint 'restaurar_produto_desocultar.php' parameter 'id_produto' in WeGIA
- CVE-2025-266111 PoCSQL Injection endpoint 'remover_produto.php' parameter 'id_produto' in WeGIA
- CVE-2025-266121 PoCSQL Injection endpoint 'adicionar_almoxarife.php' parameter 'id_almoxarifado', 'id_funcionario' in WeGIA
- CVE-2025-266131 PoCOS Command Injection endpoint 'gerenciar_backup.php' parameter 'file' (RCE) in WeGIA
- CVE-2025-266141 PoCSQL Injection endpoint 'deletar_documento.php' parameter 'id_cargo' in WeGIA
- CVE-2025-266151 PoCPath Traversal endpoint 'examples.php' parameter 'src' in WeGIA
- CVE-2025-266161 PoCPath Traversal endpoint 'exportar_dump.php' parameter 'file' in WeGIA
- CVE-2025-266171 PoCSQL Injection endpoint 'historico_paciente.php' parameter 'id_fichamedica' in WeGIA
- CVE-2025-266191 PoCVega Cross-Site Scripting (XSS) via event filter when not using CSP mode `expressionInterpeter`
- CVE-2025-266231 PoCUse After Free in Exiv2
- CVE-2025-266251 PoCGit LFS may write to arbitrary files via crafted symlinks
- CVE-2025-266335 PoCsKEVMicrosoft Management Console Security Feature Bypass Vulnerability
- CVE-2025-266861 PoCWindows TCP/IP Remote Code Execution Vulnerability
- CVE-2025-267881 PoCStrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction.
- CVE-2025-267912 PoCsDOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
- CVE-2025-267931 PoCThe Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials…
- CVE-2025-267943 PoCsExim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection.
- CVE-2025-268491 PoCThere is a Hard-coded Cryptographic Key in Docusnap 13.0.1440.24261, and earlier and later versions. This key can be used to decrypt…
- CVE-2025-268651 PoCApache OFBiz: Server-Side Template Injection affecting the ecommerce plugin leading to possible RCE
- CVE-2025-268921 PoCWordPress Celestial Aura plugin <= 2.2 - Arbitrary File Upload vulnerability