CVE-2025-29000 to CVE-2025-29999
116 CVEs with public proof-of-concept exploits.
- CVE-2025-290093 PoCsWordPress Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Arbitrary File Upload Vulnerability
- CVE-2025-290151 PoCCode Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.
- CVE-2025-290171 PoCA Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in…
- CVE-2025-290181 PoCA Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking…
- CVE-2025-290291 PoCTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
- CVE-2025-290301 PoCTenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
- CVE-2025-290321 PoCTenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.
- CVE-2025-290402 PoCsAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737c
- CVE-2025-290412 PoCsAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41710c
- CVE-2025-290422 PoCsAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the function 0x42232c
- CVE-2025-290432 PoCsAn issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234
- CVE-2025-290452 PoCsBuffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_text_0 key value
- CVE-2025-290461 PoCBuffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the…
- CVE-2025-290471 PoCBuffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the…
- CVE-2025-290831 PoCSQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the…
- CVE-2025-290841 PoCSQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the…
- CVE-2025-290851 PoCSQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via…
- CVE-2025-290931 PoCFile Upload vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2025-290941 PoCCross Site Scripting vulnerability in Motivian Content Mangment System v.41.0.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2025-291211 PoCA vulnerability was found in Tenda AC6 V15.03.05.16. The vulnerability affects the functionality of the /goform/fast_setting_wifi_set file…
- CVE-2025-291491 PoCTenda i12 V1.0.0.10(3805) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.
- CVE-2025-291522 PoCsCross-Site Scripting vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via multiple…
- CVE-2025-291532 PoCsSQL Injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the Data export,…
- CVE-2025-291541 PoCHTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the…
- CVE-2025-291571 PoCAn issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server…
- CVE-2025-291921 PoCFlowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
- CVE-2025-292081 PoCCodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.
- CVE-2025-292131 PoCA zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via…
- CVE-2025-292141 PoCTenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_42F69C function at /goform/setMacFilterCfg.
- CVE-2025-292151 PoCTenda AX12 v22.03.01.46_CN was discovered to contain a stack overflow via the sub_43fdcc function at /goform/SetNetControlList.
- CVE-2025-292171 PoCTenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiSSID parameter at /goform/setModules. This vulnerability…
- CVE-2025-292181 PoCTenda W18E v2.0 v16.01.0.11 was discovered to contain a stack overflow in the wifiPwd parameter at /goform/setModules. This vulnerability…
- CVE-2025-292801 PoCStored cross-site scripting vulnerability exists in PerfreeBlog v4.0.11 in the website name field of the backend system settings interface…
- CVE-2025-292811 PoCIn PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload…
- CVE-2025-293068 PoCsAn issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
- CVE-2025-293651 PoCspimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.
- CVE-2025-293843 PoCsIn Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead…
- CVE-2025-293851 PoCIn Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can…
- CVE-2025-293861 PoCIn Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to…
- CVE-2025-293871 PoCIn Tenda AC9 v1.0 V15.03.05.14_multi, the wanSpeed parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead…
- CVE-2025-293901 PoCjerryhanjj ERP 1.0 is vulnerable to SQL Injection in the set_password function in application/controllers/home.php.
- CVE-2025-294251 PoCCode-projects Online Class and Exam Scheduling System 1.0 is vulnerable to SQL Injection in exam_save.php via the parameters member and…
- CVE-2025-294261 PoCCode-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/class.php via the id and…
- CVE-2025-294291 PoCCode-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id,…
- CVE-2025-294301 PoCCode-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and…
- CVE-2025-294311 PoCCode-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the…
- CVE-2025-294481 PoCBooking logic flaw in Easy!Appointments v1.5.1 allows unauthenticated attackers to create appointments with excessively long durations,…
- CVE-2025-294621 PoCA buffer overflow vulnerability has been discovered in Tenda Ac15 V15.13.07.13. The vulnerability occurs when the webCgiGetUploadFile…
- CVE-2025-294712 PoCsCross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into…
- CVE-2025-294761 PoCBuffer Overflow vulnerability in compress_chunk_fuzzer with oss-fuzz on commit 16450518afddcb3139de627157208e49bfef6987 in c-blosc2…
- CVE-2025-294771 PoCAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
- CVE-2025-294781 PoCAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
- CVE-2025-294801 PoCBuffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release…
- CVE-2025-294811 PoCBuffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of…
- CVE-2025-294821 PoCBuffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset)…
- CVE-2025-294831 PoClibming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.
- CVE-2025-294841 PoCAn out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to…
- CVE-2025-294852 PoCslibming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to…
- CVE-2025-294862 PoCslibming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.
- CVE-2025-294872 PoCsAn out-of-memory error in the parseABC_STRING_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to…
- CVE-2025-294882 PoCslibming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.
- CVE-2025-294892 PoCslibming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.
- CVE-2025-294902 PoCslibming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to…
- CVE-2025-294912 PoCsAn allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service…
- CVE-2025-294922 PoCslibming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.
- CVE-2025-294932 PoCslibming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers…
- CVE-2025-294942 PoCslibming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to…
- CVE-2025-294962 PoCslibming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers…
- CVE-2025-294972 PoCslibming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.
- CVE-2025-295141 PoCIncorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to…
- CVE-2025-295191 PoCA command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to…
- CVE-2025-295201 PoCIncorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows authenticated…
- CVE-2025-295291 PoCITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component…
- CVE-2025-295561 PoCExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users…
- CVE-2025-295571 PoCExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with…
- CVE-2025-295682 PoCsA vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown…
- CVE-2025-295731 PoCCross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.
- CVE-2025-295921 PoCoasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
- CVE-2025-296021 PoCflatpress 1.3.1 is vulnerable to Cross Site Scripting (XSS) in Administration area via Manage categories.
- CVE-2025-296251 PoCA buffer overflow vulnerability in Astrolog v7.70 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via an…
- CVE-2025-296321 PoCBuffer Overflow vulnerability in Free5gc v.4.0.0 allows a remote attacker to cause a denial of service via the AMF, NGAP, security.go,…
- CVE-2025-296352 PoCsKEVA command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on…
- CVE-2025-296401 PoCPhpgurukul Human Metapneumovirus (HMPV) – Testing Management System v1.0 is vulnerable to SQL Injection in /patient-report.php via the…
- CVE-2025-296411 PoCPhpgurukul Vehicle Record Management System v1.0 is vulnerable to SQL Injection in /index.php via the 'searchinputdata' parameter.
- CVE-2025-296462 PoCsAn issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP…
- CVE-2025-296471 PoCSeaCMS v13.3 has a SQL injection vulnerability in the component admin_tempvideo.php.
- CVE-2025-296592 PoCsYi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary.
- CVE-2025-296602 PoCsA vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789. This service…
- CVE-2025-296891 PoCA cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2025-296901 PoCA cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2025-296911 PoCA cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2025-296991 PoCNetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function.
- CVE-2025-297051 PoCcode-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such…
- CVE-2025-297191 PoCSourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name…
- CVE-2025-297221 PoCA CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The…
- CVE-2025-297441 PoCpg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.
- CVE-2025-297461 PoCCross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the collection, Wishlist…
- CVE-2025-297721 PoCOpenEMR allows Reflected XSS in CAMOS new.php
- CVE-2025-297731 PoCFroxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover
- CVE-2025-297751 PoCxml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue Comment
- CVE-2025-297782 PoCsKyverno ignores subjectRegExp and IssuerRegExp
- CVE-2025-297821 PoCWeGIA Cross-Site Scripting (XSS) Stored in endpoint `adicionar_tipo_docs_atendido.php` parameter `tipo`
- CVE-2025-297841 PoCNamelessMC Has Lack of Length Validation for s Parameter in GET Requests
- CVE-2025-297891 PoCOpenEMR Has Directory Traversal in Load Code feature
- CVE-2025-298244 PoCsKEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2025-298911 PoCApache Camel: Camel Message Header Injection through request parameters
- CVE-2025-299091 PoCCryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow Vulnerability
- CVE-2025-299101 PoCCryptoLib's crypto_handle_incrementing_nontransmitted_counter Function has Memory Leak
- CVE-2025-299111 PoCCryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity Function
- CVE-2025-299121 PoCCryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurity
- CVE-2025-299131 PoCCryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer Underflow
- CVE-2025-299251 PoCXWiki allows unregistered users to access private pages information through REST endpoint
- CVE-2025-29927118 PoCsAuthorization Bypass in Next.js Middleware
- CVE-2025-299431 PoCWrite what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline…
- CVE-2025-299691 PoCMS-EVEN RPC Remote Code Execution Vulnerability
- CVE-2025-299722 PoCsAzure Storage Resource Provider Spoofing Vulnerability