CVE-2025-28000 to CVE-2025-28999
67 CVEs with public proof-of-concept exploits.
- CVE-2025-280091 PoCA SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.20.
- CVE-2025-280101 PoCA cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to…
- CVE-2025-280172 PoCsTOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.
- CVE-2025-280181 PoCTOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.
- CVE-2025-280192 PoCsTOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in the downloadFile.cgi component
- CVE-2025-280202 PoCsTOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.
- CVE-2025-280212 PoCsTOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi through the v14 and v3…
- CVE-2025-280222 PoCsTOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.
- CVE-2025-280241 PoCTOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi
- CVE-2025-280252 PoCsTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129…
- CVE-2025-280262 PoCsTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129…
- CVE-2025-280272 PoCsTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129…
- CVE-2025-280282 PoCsTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129…
- CVE-2025-280292 PoCsTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129…
- CVE-2025-280301 PoCTOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in…
- CVE-2025-280321 PoCTOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903,…
- CVE-2025-280332 PoCsTOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903,…
- CVE-2025-280342 PoCsTOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903,…
- CVE-2025-280352 PoCsTOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function…
- CVE-2025-280362 PoCsTOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg…
- CVE-2025-280371 PoCTOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote command execution…
- CVE-2025-280381 PoCTOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx…
- CVE-2025-280391 PoCTOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setUpgradeFW…
- CVE-2025-280551 PoCupset-gal-web v7.1.0 /api/music/v1/cover.ts contains an arbitrary file read vulnerabilit
- CVE-2025-280561 PoCrebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.
- CVE-2025-280571 PoCowl-admin v3.2.2~ to v4.10.2 is vulnerable to SQL Injection in /admin-api/system/admin_menus/save_order.
- CVE-2025-280622 PoCsA Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to…
- CVE-2025-280731 PoCphpList before 3.6.15 is vulnerable to Reflected Cross-Site Scripting (XSS) via the /lists/dl.php endpoint. An attacker can inject…
- CVE-2025-280741 PoCphpList before 3.6.15 is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization in lt.php. The vulnerability is…
- CVE-2025-281001 PoCA SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the content correctly at…
- CVE-2025-281011 PoCAn arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles…
- CVE-2025-281021 PoCA cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted…
- CVE-2025-281041 PoCIncorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
- CVE-2025-281212 PoCscode-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing…
- CVE-2025-281373 PoCsThe TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg…
- CVE-2025-281422 PoCsEdimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the…
- CVE-2025-281432 PoCsEdimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the…
- CVE-2025-281442 PoCsEdimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a stack overflow vlunerability via peerPin…
- CVE-2025-281452 PoCsEdimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via…
- CVE-2025-281462 PoCsEdimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via fota_url…
- CVE-2025-282282 PoCsA credential exposure vulnerability in Electrolink 500W, 1kW, 2kW Medium DAB Transmitter Web v01.09, v01.08, v01.07, and Display v1.4,…
- CVE-2025-282291 PoCIncorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentication and gain…
- CVE-2025-282301 PoCIncorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credentials.
- CVE-2025-282321 PoCIncorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Admin panel without…
- CVE-2025-282421 PoCImproper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.
- CVE-2025-282431 PoCAn issue in Alteryx Server v.2023.1.1.460 allows HTML injection via a crafted script to the pages component.
- CVE-2025-282441 PoCInsecure Permissions vulnerability in the Local Storage in Alteryx Server 2023.1.1.460 allows remote attackers to obtain valid user…
- CVE-2025-282451 PoCCross-site scripting (XSS) vulnerability in Alteryx Server 2023.1.1.460 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2025-283551 PoCVolmarg Personal Management System 1.4.65 is vulnerable to Cross Site Request Forgery (CSRF) allowing attackers to execute arbitrary code…
- CVE-2025-283671 PoCmojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can…
- CVE-2025-283951 PoCD-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_road_asp function via the host_ip parameter.
- CVE-2025-283981 PoCD-LINK DI-8100 16.07.26A1 is vulnerable to Buffer Overflow in the ipsec_net_asp function via the remot_ip parameter.
- CVE-2025-283991 PoCAn issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address…
- CVE-2025-284001 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
- CVE-2025-284021 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
- CVE-2025-284031 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the…
- CVE-2025-284051 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
- CVE-2025-284061 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
- CVE-2025-284071 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not…
- CVE-2025-284081 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId}…
- CVE-2025-284091 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not…
- CVE-2025-284101 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate…
- CVE-2025-284111 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
- CVE-2025-284121 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
- CVE-2025-284131 PoCAn issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
- CVE-2025-289061 PoCWordPress Skitter Slideshow plugin <= 2.5.2 - Cross Site Scripting (XSS) vulnerability
- CVE-2025-289152 PoCsWordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability