CVE-2025-2000 to CVE-2025-2999
408 CVEs with public proof-of-concept exploits.
- CVE-2025-20053 PoCsFront-End-Only-Users <= 3.2.32 - Unauthenticated Arbitrary File Upload
- CVE-2025-20101 PoCJobWP – Job Board, Job Listing, Career Page and Recruitment Plugin <= 2.3.9 - Unauthenticated SQL Injection
- CVE-2025-20116 PoCsSlider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection via 's' Parameter
- CVE-2025-20301 PoCSeeyon Zhiyuan Interconnect FE Collaborative Office Platform addUser.jsp sql injection
- CVE-2025-20311 PoCChestnutCMS upload uploadFile unrestricted upload
- CVE-2025-20321 PoCChestnutCMS rename renameFile path traversal
- CVE-2025-20331 PoCcode-projects Blood Bank Management System view_donor.php sql injection
- CVE-2025-20341 PoCPHPGurukul Pre-School Enrollment System edit-class.php sql injection
- CVE-2025-20351 PoCs-a-zhd Ecommerce-Website-using-PHP customer_register.php unrestricted upload
- CVE-2025-20361 PoCs-a-zhd Ecommerce-Website-using-PHP details.php sql injection
- CVE-2025-20371 PoCcode-projects Blood Bank Management System delete_requester.php sql injection
- CVE-2025-20381 PoCcode-projects Blood Bank Management System upload exposure of information through directory listing
- CVE-2025-20391 PoCcode-projects Blood Bank Management System delete_members.php sql injection
- CVE-2025-20401 PoCzhijiantianya ruoyi-vue-pro deploy special elements used in a template engine
- CVE-2025-20411 PoCs-a-zhd Ecommerce-Website-using-PHP shop.php sql injection
- CVE-2025-20421 PoChuang-yk student-manage cross-site request forgery
- CVE-2025-20431 PoCLinZhaoguan pb-cms Add New Topic admin#themes deserialization
- CVE-2025-20441 PoCcode-projects Blood Bank Management System delete_bloodGroup.php sql injection
- CVE-2025-20451 PoCIncorrect Authorization in GitLab
- CVE-2025-20461 PoCSourceCodester Best Employee Management System print1.php sql injection
- CVE-2025-20471 PoCPHPGurukul Art Gallery Management System search.php cross site scripting
- CVE-2025-20481 PoCLana Downloads Manager < 1.10.0 - Admin+ Arbitrary File Download via Path Traversal
- CVE-2025-20491 PoCcode-projects Blood Bank System AB+.php cross site scripting
- CVE-2025-20501 PoCPHPGurukul User Registration & Login and User Management System login.php sql injection
- CVE-2025-20511 PoCPHPGurukul Apartment Visitors Management System search-visitor.php sql injection
- CVE-2025-20521 PoCPHPGurukul Apartment Visitors Management System forgot-password.php sql injection
- CVE-2025-20531 PoCPHPGurukul Apartment Visitors Management System visitor-detail.php sql injection
- CVE-2025-20541 PoCcode-projects Blood Bank Management System edit_state.php sql injection
- CVE-2025-20551 PoCMapPress Maps for WordPress < 2.94.9 - Contributor+ Stored XSS
- CVE-2025-20571 PoCPHPGurukul Emergency Ambulance Hiring Portal about-us.php sql injection
- CVE-2025-20581 PoCPHPGurukul Emergency Ambulance Hiring Portal search.php sql injection
- CVE-2025-20591 PoCPHPGurukul Emergency Ambulance Hiring Portal booking-details.php sql injection
- CVE-2025-20601 PoCPHPGurukul Emergency Ambulance Hiring Portal admin-profile.php sql injection
- CVE-2025-20611 PoCcode-projects Online Ticket Reservation System passenger.php cross site scripting
- CVE-2025-20621 PoCprojectworlds Life Insurance Management System clientStatus.php sql injection
- CVE-2025-20631 PoCprojectworlds Life Insurance Management System deleteNominee.php sql injection
- CVE-2025-20641 PoCprojectworlds Life Insurance Management System deletePayment.php sql injection
- CVE-2025-20651 PoCprojectworlds Life Insurance Management System editAgent.php sql injection
- CVE-2025-20661 PoCprojectworlds Life Insurance Management System updateAgent.php sql injection
- CVE-2025-20671 PoCprojectworlds Life Insurance Management System search.php sql injection
- CVE-2025-20731 PoCOut-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to…
- CVE-2025-20751 PoCUncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
- CVE-2025-20822 PoCsTesla Model 3 VCSEC Integer Overflow Remote Code Execution Vulnerability
- CVE-2025-20841 PoCPHPGurukul Human Metapneumovirus Testing Management System Search Report Page search-report.php cross site scripting
- CVE-2025-20851 PoCStarSea99 starsea-mall save cross site scripting
- CVE-2025-20861 PoCStarSea99 starsea-mall update cross site scripting
- CVE-2025-20871 PoCStarSea99 starsea-mall update cross site scripting
- CVE-2025-20881 PoCPHPGurukul Pre-School Enrollment System profile.php sql injection
- CVE-2025-20891 PoCStarSea99 starsea-mall com.siro.mall.controller.mall.UserController updateInfo updateUserInfo access control
- CVE-2025-20901 PoCPHPGurukul Pre-School Enrollment System Sub Admin add-subadmin.php access control
- CVE-2025-20931 PoCPHPGurukul Online Library Management System change-password.php password recovery
- CVE-2025-20941 PoCTOTOLINK EX1800T cstecgi.cgi setWiFiExtenderConfig os command injection
- CVE-2025-20951 PoCTOTOLINK EX1800T cstecgi.cgi setDmzCfg os command injection
- CVE-2025-20961 PoCTOTOLINK EX1800T cstecgi.cgi setRebootScheCfg os command injection
- CVE-2025-20971 PoCTOTOLINK EX1800T cstecgi.cgi setRptWizardCfg stack-based overflow
- CVE-2025-21121 PoCuser-xiangpeng yaoqishan MediaInfoService.java getMediaLisByFilter sql injection
- CVE-2025-21141 PoCShenzhen Sixun Software Sixun Shanghui Group Business Management System Reset Password Interface OperatorStop.asp improper authorization
- CVE-2025-21151 PoCzzskzy Warehouse Refinement Management System AcceptZip.ashx ProcessRequest unrestricted upload
- CVE-2025-21161 PoCBeijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System File Protocol imageProxy.do server-side request forgery
- CVE-2025-21171 PoCBeijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System reportCenter.do electricDocList sql injection
- CVE-2025-21191 PoCThinkware Car Dashcam F800 Pro Device Registration default credentials
- CVE-2025-21201 PoCThinkware Car Dashcam F800 Pro Configuration File hostapd.conf cleartext storage in a file or on disk
- CVE-2025-21211 PoCThinkware Car Dashcam F800 Pro File Storage access control
- CVE-2025-21221 PoCThinkware Car Dashcam F800 Pro Connection denial of service
- CVE-2025-21232 PoCsGeSHi CSS cssgen.php get_var cross site scripting
- CVE-2025-21261 PoCJoomlaUX JUX Real Estate GET Parameter realties sql injection
- CVE-2025-21271 PoCJoomlaUX JUX Real Estate realties cross site scripting
- CVE-2025-21292 PoCsMage AI insecure default initialization of resource
- CVE-2025-21302 PoCsOpenXE Ticket Bearbeiten Page cross site scripting
- CVE-2025-21311 PoCdayrui XunRuiCMS Friendly Links cross site scripting
- CVE-2025-21321 PoCftcms Search ajax_all_lists sql injection
- CVE-2025-21331 PoCftcms edit cross site scripting
- CVE-2025-21352 PoCsType Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2025-21471 PoCBeijing Zhide Intelligent Internet Technology Modern Farm Digital Integrated Management System file access
- CVE-2025-21491 PoCPyTorch Quantized Sigmoid Module nnq_Sigmoid initialization
- CVE-2025-21512 PoCsOpen Asset Import Library Assimp File ParsingUtils.h GetNextLine stack-based overflow
- CVE-2025-21521 PoCOpen Asset Import Library Assimp File BaseImporter.cpp ConvertToUTF8 heap-based overflow
- CVE-2025-21532 PoCsHDF5 h5 File H5SM.c H5SM_delete heap-based overflow
- CVE-2025-21621 PoCMapPress Maps for WordPress < 2.94.10 - Admin+ Stored XSS
- CVE-2025-21921 PoCStoque Zeev.it Login Page server-side request forgery
- CVE-2025-21931 PoCMRCMS org.marker.mushroom.controller.FileController delete.do delete path traversal
- CVE-2025-21941 PoCMRCMS org.marker.mushroom.controller.FileController list.do list cross site scripting
- CVE-2025-21951 PoCMRCMS org.marker.mushroom.controller.FileController rename.do rename cross site scripting
- CVE-2025-21961 PoCMRCMS org.marker.mushroom.controller.FileController upload.do upload cross site scripting
- CVE-2025-22031 PoCWooCommerce Checkout & Funnel Builder by FunnelKit < 3.10.2 - Admin+ SQL Injection
- CVE-2025-22052 PoCsGDPR Cookie Compliance <= 4.15.6 - Authenticated (Admin+) Stored Cross-Site Scripting
- CVE-2025-22061 PoCaitangbao springboot-manager permission cross site scripting
- CVE-2025-22071 PoCaitangbao springboot-manager dept cross site scripting
- CVE-2025-22081 PoCaitangbao springboot-manager Filename upload cross site scripting
- CVE-2025-22091 PoCaitangbao springboot-manager add cross site scripting
- CVE-2025-22101 PoCaitangbao springboot-manager add cross site scripting
- CVE-2025-22111 PoCaitangbao springboot-manager add cross site scripting
- CVE-2025-22141 PoCMicroweber Settings index.php cross site scripting
- CVE-2025-22151 PoCDoufox s=doudou path traversal
- CVE-2025-22161 PoCzzskzy Warehouse Refinement Management System SaveCrash.ashx UploadCrash unrestricted upload
- CVE-2025-22171 PoCzzskzy Warehouse Refinement Management System getAdyData.ashx ProcessRequest sql injection
- CVE-2025-22181 PoCLoveCards LoveCardsV2 Setting other access control
- CVE-2025-22191 PoCLoveCards LoveCardsV2 image unrestricted upload
- CVE-2025-22201 PoCOdyssey CMS reCAPTCHA odyssey_contact_form.php key management
- CVE-2025-22211 PoCWPCOM Member <= 1.7.6 - Unauthenticated Time-Based SQL Injection
- CVE-2025-22461 PoCMissing Authorization in GitLab
- CVE-2025-22471 PoCWP-PManager <= 1.2 - Category Deletion via CSRF
- CVE-2025-22481 PoCWP-PManager <= 1.2 - Admin+ SQL Injection
- CVE-2025-22491 PoCSoJ Soundslides <= 1.2.2 - Authenticated (Contributor+) Arbitrary File Upload
- CVE-2025-22541 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-22551 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-22561 PoCImproper Validation of Specified Quantity in Input in GitLab
- CVE-2025-22632 PoCsSantesoft Sante PACS Server Stack-based Buffer Overflow
- CVE-2025-22643 PoCsSantesoft Sante PACS Server Path Traversal Information Disclosure
- CVE-2025-22661 PoCCheckout Mestres do WP for WooCommerce 8.6.5 - 8.7.5 - Unauthenticated Arbitrary Options Update
- CVE-2025-22791 PoCMaps - Google Maps <= 1.0.6 - Contributor+ Stored XSS
- CVE-2025-22921 PoCXorcom CompletePBX <= 5.2.35 Authenticated File Disclosure
- CVE-2025-229411 PoCsKubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion
- CVE-2025-23011 PoCIDOR in Akbim Software's Online Exam Registration
- CVE-2025-230418 PoCsCamaleon CMS Privilege Escalation
- CVE-2025-23081 PoCHDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow
- CVE-2025-23091 PoCHDF5 Type Conversion Logic H5T__bit_copy heap-based overflow
- CVE-2025-23101 PoCHDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow
- CVE-2025-23201 PoC274056675 springboot-openai-chatgpt User submit improper authorization
- CVE-2025-23211 PoC274056675 springboot-openai-chatgpt addData logic error
- CVE-2025-23221 PoC274056675 springboot-openai-chatgpt OpenController.java hard-coded credentials
- CVE-2025-23231 PoC274056675 springboot-openai-chatgpt Number of Question questionCou updateQuestionCou behavioral workflow
- CVE-2025-23341 PoC274056675 springboot-openai-chatgpt Chat History chat deleteChat access control
- CVE-2025-23361 PoCAngularJS improper sanitization in SVG '<image>' element with 'ngSanitize'
- CVE-2025-23371 PoCtbeu matio mat.c Mat_VarPrint heap-based overflow
- CVE-2025-23381 PoCtbeu matio io.c strdup_vprintf heap-based overflow
- CVE-2025-23391 PoCotale Tale Blog logs improper authentication
- CVE-2025-23401 PoCotale Tale Blog Site Settings save saveOptions cross site scripting
- CVE-2025-23411 PoCIROAD Dash Cam X5 SSID default credentials
- CVE-2025-23421 PoCIROAD X5 Mobile App API Endpoint hard-coded credentials
- CVE-2025-23471 PoCIROAD Dash Cam FX2 Device Registration default password
- CVE-2025-23481 PoCIROAD Dash Cam FX2 HTTP/RTSP event information disclosure
- CVE-2025-23491 PoCIROAD Dash Cam FX2 Password Hash passwd weak password hash
- CVE-2025-23501 PoCIROAD Dash Cam FX2 upload_file unrestricted upload
- CVE-2025-23521 PoCStarSea99 starsea-mall Backend save cross site scripting
- CVE-2025-23551 PoCBlackVue App API Endpoint credentials storage
- CVE-2025-23561 PoCBlackVue App API deviceDelete get request method with sensitive query strings
- CVE-2025-23571 PoCDCMTK dcmjpls JPEG-LS Decoder memory corruption
- CVE-2025-23581 PoCShenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System HTTP Header Service.asmx sql injection
- CVE-2025-23591 PoCD-Link DIR-823G DDNS Service HNAP1 SetDDNSSettings improper authorization
- CVE-2025-23601 PoCD-Link DIR-823G UPnP Service HNAP1 SetUpnpSettings improper authorization
- CVE-2025-23621 PoCPHPGurukul Pre-School Enrollment System contact-us.php sql injection
- CVE-2025-23631 PoClenve VBlog ArticleController.java uploadImg path traversal
- CVE-2025-23641 PoClenve VBlog ArticleService.java addNewArticle cross site scripting
- CVE-2025-23651 PoCcrmeb_java WeChatMessageController.java webHook xml external entity reference
- CVE-2025-23661 PoCgougucms Add Department Page add cross site scripting
- CVE-2025-23681 PoCWebAssembly wabt Malformed File binary-reader-interp.cc OnExport heap-based overflow
- CVE-2025-23691 PoCTOTOLINK EX1800T cstecgi.cgi setPasswordCfg stack-based overflow
- CVE-2025-23701 PoCTOTOLINK EX1800T cstecgi.cgi setWiFiExtenderConfig stack-based overflow
- CVE-2025-23711 PoCPHPGurukul Human Metapneumovirus Testing Management System Registered Mobile Number Search registered-user-testing.php cross site scripting
- CVE-2025-23721 PoCPHPGurukul Human Metapneumovirus Testing Management System Password Recovery Page password-recovery.php sql injection
- CVE-2025-23731 PoCPHPGurukul Human Metapneumovirus Testing Management System check_availability.php sql injection
- CVE-2025-23741 PoCPHPGurukul Human Metapneumovirus Testing Management System profile.php sql injection
- CVE-2025-23751 PoCPHPGurukul Human Metapneumovirus Testing Management System Admin Profile Page profile.php cross site scripting
- CVE-2025-23761 PoCviames Pair Framework PHP Object UserRemember.php getCookieContent deserialization
- CVE-2025-23771 PoCSourceCodester Vehicle Management System confirmbooking.php cross site scripting
- CVE-2025-23781 PoCPHPGurukul Medical Card Generation System download-medical-cards.php sql injection
- CVE-2025-23791 PoCPHPGurukul Apartment Visitors Management System create-pass.php sql injection
- CVE-2025-23801 PoCPHPGurukul Apartment Visitors Management System admin-profile.php sql injection
- CVE-2025-23811 PoCPHPGurukul Curfew e-Pass Management System search-pass.php sql injection
- CVE-2025-23821 PoCPHPGurukul Online Banquet Booking System booking-search.php sql injection
- CVE-2025-23831 PoCPHPGurukul Doctor Appointment Management System search.php sql injection
- CVE-2025-23841 PoCcode-projects Real Estate Property Management System Parameter InsertCustomer.php sql injection
- CVE-2025-23851 PoCcode-projects Modern Bag login.php sql injection
- CVE-2025-23861 PoCPHPGurukul Local Services Search Engine Management System serviceman-search.php sql injection
- CVE-2025-23871 PoCSourceCodester Online Food Ordering System ajax.php sql injection
- CVE-2025-23881 PoCKeytop 路内停车收费系统 API getParks improper authentication
- CVE-2025-23891 PoCcode-projects Blood Bank Management System add_city.php sql injection
- CVE-2025-23901 PoCcode-projects Blood Bank Management System add_donor.php sql injection
- CVE-2025-23911 PoCcode-projects Blood Bank Management System Admin Login Page admin_login.php sql injection
- CVE-2025-23921 PoCcode-projects Online Class and Exam Scheduling System activate.php sql injection
- CVE-2025-23931 PoCcode-projects Online Class and Exam Scheduling System salut_del.php sql injection
- CVE-2025-23971 PoCChina Mobile P22g-CIac Telnet Service improper authorization
- CVE-2025-23981 PoCChina Mobile P22g-CIac CLI su Command default credentials
- CVE-2025-24041 PoCXSS in Ubit Information Technologies' STOYS
- CVE-2025-24081 PoCInsufficient Granularity of Access Control in GitLab
- CVE-2025-24191 PoCcode-projects Real Estate Property Management System InsertFeedback.php sql injection
- CVE-2025-24201 PoC猫宁i Morning cross-site request forgery
- CVE-2025-24431 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-24691 PoCDebug Messages Revealing Unnecessary Information in GitLab
- CVE-2025-24711 PoCPHPGurukul Boat Booking System boat-details.php sql injection
- CVE-2025-24721 PoCPHPGurukul Apartment Visitors Management System Sign In index.php sql injection
- CVE-2025-24732 PoCsPHPGurukul Company Visitor Management System Sign In index.php sql injection
- CVE-2025-24901 PoCDromara ujcms File Upload WebFileUploadController.java upload cross site scripting
- CVE-2025-24911 PoCDromara ujcms Edit Template File Page WebFileTemplateController.java update cross site scripting
- CVE-2025-24981 PoCInsufficient Granularity of Access Control in GitLab
- CVE-2025-25021 PoCAn improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.
- CVE-2025-25051 PoCAge Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang'
- CVE-2025-25121 PoCFile Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated File Upload via upload Function
- CVE-2025-25241 PoCNinja Forms < 3.10.1 - Admin+ Stored XSS
- CVE-2025-25396 PoCsFile Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
- CVE-2025-25461 PoCD-Link DIR-618/DIR-605L Firewall Service formAdvFirewall access control
- CVE-2025-25471 PoCD-Link DIR-618/DIR-605L formAdvNetwork access control
- CVE-2025-25481 PoCD-Link DIR-618/DIR-605L formSetDomainFilter access control
- CVE-2025-25491 PoCD-Link DIR-618/DIR-605L formSetPassword access control
- CVE-2025-25501 PoCD-Link DIR-618/DIR-605L DDNS Service formSetDDNS access control
- CVE-2025-25511 PoCD-Link DIR-618/DIR-605L formSetPortTr access control
- CVE-2025-25521 PoCD-Link DIR-618/DIR-605L formTcpipSetup access control
- CVE-2025-25531 PoCD-Link DIR-618/DIR-605L formVirtualServ access control
- CVE-2025-25551 PoCAudi Universal Traffic Recorder App FTP Credentials hard-coded password
- CVE-2025-25561 PoCAudi UTR Dashcam Video Stream hard-coded credentials
- CVE-2025-25571 PoCAudi UTR Dashcam Command API access control
- CVE-2025-25582 PoCsThe Wound <= 0.0.1 - Unauthenticated LFI
- CVE-2025-25601 PoCNinja Forms < 3.10.1 - Admin+ Stored XSS
- CVE-2025-25611 PoCNinja Forms < 3.10.1 - Admin+ Stored XSS
- CVE-2025-25636 PoCsUser Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
- CVE-2025-25681 PoCVayu Blocks – Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary…
- CVE-2025-25821 PoCSimpleMachines SMF ManageAttachments.php cross site scripting
- CVE-2025-25831 PoCSimpleMachines SMF ManageNews.php cross site scripting
- CVE-2025-25841 PoCWebAssembly wabt binary-reader-interp.cc GetReturnCallDropKeepCount heap-based overflow
- CVE-2025-25871 PoCJinher OA C6 IncentivePlanFulfillAppprove.aspx sql injection
- CVE-2025-25881 PoCHercules Augeas fa.c re_case_expand null pointer dereference
- CVE-2025-25891 PoCcode-projects Human Resource Management System Account.go Index improper authorization
- CVE-2025-25901 PoCcode-projects Human Resource Management System recruitment.go UpdateRecruitmentById cross site scripting
- CVE-2025-25911 PoCOpen Asset Import Library Assimp MDLLoader.cpp InternReadFile_Quake1 divide by zero
- CVE-2025-25921 PoCOpen Asset Import Library Assimp CSMLoader.cpp InternReadFile heap-based overflow
- CVE-2025-25931 PoCFastCMS list sql injection
- CVE-2025-25943 PoCsUser Registration & Membership < 4.1.3 - Authentication Bypass
- CVE-2025-25983 PoCsAWS CDK CLI prints AWS credentials retrieved by custom credential plugins
- CVE-2025-26011 PoCSourceCodester Kortex Lite Advocate Office Management System activate_reg.php sql injection
- CVE-2025-26021 PoCSourceCodester Kortex Lite Advocate Office Management System deactivate_reg.php sql injection
- CVE-2025-26031 PoCSourceCodester Kortex Lite Advocate Office Management System deactivate.php sql injection
- CVE-2025-26041 PoCSourceCodester Kortex Lite Advocate Office Management System edit_act.php sql injection
- CVE-2025-26061 PoCSourceCodester Best Church Management Software soulwinning_crud.php unrestricted upload
- CVE-2025-26071 PoCphplaozhang LzCMS-LaoZhangBoKeXiTong HTTP POST Request upimage.html unrestricted upload
- CVE-2025-26081 PoCPHPGurukul Banquet Booking System view-user-queries.php sql injection
- CVE-2025-26092 PoCsMagnusBilling Stored Cross-Site Scripting in Login Logs
- CVE-2025-26102 PoCsMagnusBilling Stored Cross-Site Scripting in Alarm Module
- CVE-2025-26113 PoCsICTBroadcast <= 7.4 Unauthenticated Session Cookie RCE
- CVE-2025-26141 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-26151 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2025-26161 PoCyangyouwang 杨有旺 crud 简约后台管理系统 Role Management Page cross site scripting
- CVE-2025-26171 PoCyangyouwang 杨有旺 crud 简约后台管理系统 Department Page cross site scripting
- CVE-2025-26181 PoCD-Link DAP-1620 Path api set_ws_action heap-based overflow
- CVE-2025-26191 PoCD-Link DAP-1620 Cookie storage check_dws_cookie stack-based overflow
- CVE-2025-26202 PoCsD-Link DAP-1620 Authentication storage mod_graph_auth_uri_handler stack-based overflow
- CVE-2025-26211 PoCD-Link DAP-1620 storage check_dws_cookie stack-based overflow
- CVE-2025-26221 PoCaizuda snail-job Workflow-Task Management Module check-node-expression getRuntime deserialization
- CVE-2025-26231 PoCwestboy CicadasCMS save cross site scripting
- CVE-2025-26241 PoCwestboy CicadasCMS save sql injection
- CVE-2025-26251 PoCwestboy CicadasCMS page sql injection
- CVE-2025-26261 PoCSourceCodester Kortex Lite Advocate Office Management System edit_case.php sql injection
- CVE-2025-26271 PoCPHPGurukul Art Gallery Management System contactus.php sql injection
- CVE-2025-26281 PoCPHPGurukul Art Gallery Management System art-enquiry.php sql injection
- CVE-2025-26361 PoCInstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion
- CVE-2025-26371 PoCJIZHICMS Account Profile Page userinfo.html improper authorization
- CVE-2025-26381 PoCJIZHICMS Article release.html improper authorization
- CVE-2025-26391 PoCJIZHICMS Article release.html improper authorization
- CVE-2025-26401 PoCPHPGurukul Doctor Appointment Management System appointment-bwdates-reports-details.php sql injection
- CVE-2025-26411 PoCPHPGurukul Art Gallery Management System edit-artist-detail.php sql injection
- CVE-2025-26421 PoCPHPGurukul Art Gallery Management System edit-art-product-detail.php sql injection
- CVE-2025-26431 PoCPHPGurukul Art Gallery Management System edit-art-type-detail.php sql injection
- CVE-2025-26441 PoCPHPGurukul Art Gallery Management System add-art-product.php sql injection
- CVE-2025-26451 PoCPHPGurukul Art Gallery Management System product.php cross site scripting
- CVE-2025-26461 PoCPHPGurukul Art Gallery Management System admin-profile.php sql injection
- CVE-2025-26471 PoCPHPGurukul Art Gallery Management System search.php sql injection
- CVE-2025-26481 PoCPHPGurukul Art Gallery Management System view-enquiry-detail.php sql injection
- CVE-2025-26491 PoCPHPGurukul Doctor Appointment Management System check-appointment.php sql injection
- CVE-2025-26501 PoCPHPGurukul Medical Card Generation System download-medical-cards.php cross site scripting
- CVE-2025-26511 PoCSourceCodester Online Eyewear Shop admin exposure of information through directory listing
- CVE-2025-26521 PoCSourceCodester Employee and Visitor Gate Pass Logging System exposure of information through directory listing
- CVE-2025-26531 PoCFoxCMS improper authorization
- CVE-2025-26541 PoCSourceCodester AC Repair and Services System manage_service.php sql injection
- CVE-2025-26551 PoCSourceCodester AC Repair and Services System Users.php delete_users sql injection
- CVE-2025-26561 PoCPHPGurukul Zoo Management System login.php sql injection
- CVE-2025-26571 PoCprojectworlds Apartment Visitors Management System front.php sql injection
- CVE-2025-26581 PoCPHPGurukul Online Security Guards Hiring System search-request.php sql injection
- CVE-2025-26591 PoCProject Worlds Online Time Table Generator index.php sql injection
- CVE-2025-26601 PoCProject Worlds Online Time Table Generator index.php sql injection
- CVE-2025-26611 PoCProject Worlds Online Time Table Generator index.php sql injection
- CVE-2025-26621 PoCProject Worlds Online Time Table Generator studentdashboard.php sql injection
- CVE-2025-26631 PoCPHPGurukul Bank Locker Management System search-locker-details.php sql injection
- CVE-2025-26641 PoCCodeZips Hospital Management System suadpeted.php sql injection
- CVE-2025-26651 PoCPHPGurukul Online Security Guards Hiring System bwdates-reports-details.php sql injection
- CVE-2025-26711 PoCYue Lao Blind Box 月老盲盒 Upload.php base64image unrestricted upload
- CVE-2025-26721 PoCcode-projects Payroll Management System add_deductions.php sql injection
- CVE-2025-26731 PoCcode-projects Payroll Management System home_employee.php cross site scripting
- CVE-2025-26741 PoCPHPGurukul Bank Locker Management System aboutus.php sql injection
- CVE-2025-26751 PoCPHPGurukul Bank Locker Management System add-lockertype.php sql injection
- CVE-2025-26761 PoCPHPGurukul Bank Locker Management System add-subadmin.php sql injection
- CVE-2025-26771 PoCPHPGurukul Bank Locker Management System changeidproof.php sql injection
- CVE-2025-26781 PoCPHPGurukul Bank Locker Management System changeimage1.php sql injection
- CVE-2025-26791 PoCPHPGurukul Bank Locker Management System contact-us.php sql injection
- CVE-2025-26801 PoCPHPGurukul Bank Locker Management System edit-assign-locker.php sql injection
- CVE-2025-26811 PoCPHPGurukul Bank Locker Management System edit-locker.php sql injection
- CVE-2025-26821 PoCPHPGurukul Bank Locker Management System edit-subadmin.php sql injection
- CVE-2025-26831 PoCPHPGurukul Bank Locker Management System profile.php sql injection
- CVE-2025-26841 PoCPHPGurukul Bank Locker Management System search-report-details.php sql injection
- CVE-2025-26861 PoCmingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 Backend admin doFilter access control
- CVE-2025-26871 PoCPHPGurukul eLearning System Image index.php unrestricted upload
- CVE-2025-26881 PoCTOTOLINK A3000RU Syslog Configuration File ExportSyslog.sh access control
- CVE-2025-26891 PoCyiisoft Yii2 SortableIterator.php getIterator deserialization
- CVE-2025-26901 PoCyiisoft Yii2 MockClass.php generate deserialization
- CVE-2025-26911 PoCVersions of the package nossrf before 1.0.4 are vulnerable to Server-Side Request Forgery (SSRF) where an attacker can provide a hostname…
- CVE-2025-26991 PoCGetmeUK ContentTools Image cross site scripting
- CVE-2025-27001 PoCmichelson Dante Editor Insert Link cross site scripting
- CVE-2025-27011 PoCAMTT Hotel Broadband Operation System port_setup.php popen os command injection
- CVE-2025-27021 PoCSoftwin WMX3 ImageAdd.ashx ImageAdd unrestricted upload
- CVE-2025-27051 PoCDigiwin ERP FileUploadApi.ashx DoWebUpload unrestricted upload
- CVE-2025-27061 PoCDigiwin ERP UploadAjaxAPI.ashx unrestricted upload
- CVE-2025-27071 PoCzhijiantianya ruoyi-vue-pro Front-End Store Interface upload path traversal
- CVE-2025-27081 PoCzhijiantianya ruoyi-vue-pro Backend File Upload Interface upload path traversal
- CVE-2025-27092 PoCsYonyou UFIDA ERP-NC login.jsp cross site scripting
- CVE-2025-27102 PoCsYonyou UFIDA ERP-NC menu.jsp cross site scripting
- CVE-2025-27112 PoCsYonyou UFIDA ERP-NC systop.jsp cross site scripting
- CVE-2025-27122 PoCsYonyou UFIDA ERP-NC top.jsp cross site scripting
- CVE-2025-27151 PoCtimschofield webERP Confirm Dispatch and Invoice Page ConfirmDispatch_Invoice.php cross site scripting
- CVE-2025-27161 PoCChina Mobile P22g-CIac Samba Path path traversal
- CVE-2025-27171 PoCD-Link DIR-823X HTTP POST Request diag_nslookup sub_41710C os command injection
- CVE-2025-27251 PoCH3C Magic BE18000 HTTP POST Request auth command injection
- CVE-2025-27261 PoCH3C Magic BE18000 HTTP POST Request esps command injection
- CVE-2025-27271 PoCH3C Magic NX30 Pro HTTP POST Request getNetworkStatus command injection
- CVE-2025-27291 PoCH3C Magic BE18000 HTTP POST Request networkSetup command injection
- CVE-2025-27301 PoCH3C Magic BE18000 HTTP POST Request getssidname command injection
- CVE-2025-27311 PoCH3C Magic BE18000 HTTP POST Request getDualbandSync command injection
- CVE-2025-27321 PoCH3C Magic BE18000 HTTP POST Request getWifiNeighbour command injection
- CVE-2025-27331 PoCmannaandpoem OpenManus Prompt python_execute.py os command injection
- CVE-2025-27341 PoCPHPGurukul Old Age Home Management System aboutus.php sql injection
- CVE-2025-27351 PoCPHPGurukul Old Age Home Management System add-services.php sql injection
- CVE-2025-27361 PoCPHPGurukul Old Age Home Management System bwdates-report-details.php sql injection
- CVE-2025-27371 PoCPHPGurukul Old Age Home Management System contactus.php sql injection
- CVE-2025-27381 PoCPHPGurukul Old Age Home Management System manage-scdetails.php sql injection
- CVE-2025-27391 PoCPHPGurukul Old Age Home Management System manage-services.php sql injection
- CVE-2025-27401 PoCPHPGurukul Old Age Home Management System eligibility.php sql injection
- CVE-2025-27421 PoCzhijiantianya ruoyi-vue-pro Material Upload Interface upload-permanent path traversal
- CVE-2025-27431 PoCzhijiantianya ruoyi-vue-pro Material Upload Interface upload-temporary path traversal
- CVE-2025-27441 PoCzhijiantianya ruoyi-vue-pro Material Upload Interface upload-news-image path traversal
- CVE-2025-27463 PoCsKEVKentico Xperience <= 13.0.172 Staging Sync Server Digest Password Authentication Bypass
- CVE-2025-27473 PoCsKEVKentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
- CVE-2025-27482 PoCsKentico Xperience stored cross-site scripting in multiple-file upload functionality
- CVE-2025-27491 PoCKEVKentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE
- CVE-2025-27501 PoCOpen Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds write
- CVE-2025-27511 PoCOpen Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile out-of-bounds
- CVE-2025-27521 PoCOpen Asset Import Library Assimp CSM File fast_atof.h fast_atoreal_move out-of-bounds
- CVE-2025-27531 PoCOpen Asset Import Library Assimp LWS File LWSLoader.cpp MergeScenes out-of-bounds
- CVE-2025-27541 PoCOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflow
- CVE-2025-27551 PoCOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection out-of-bounds
- CVE-2025-27561 PoCOpen Asset Import Library Assimp AC3D File ACLoader.cpp ConvertObjectSection heap-based overflow
- CVE-2025-27571 PoCOpen Asset Import Library Assimp MD5 File MD5Parser.cpp AI_MD5_PARSE_STRING_IN_QUOTATION heap-based overflow
- CVE-2025-27754 PoCsKEVSysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
- CVE-2025-27765 PoCsKEVSysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
- CVE-2025-27774 PoCsSysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
- CVE-2025-27836 PoCsKEVIncorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote…
- CVE-2025-28071 PoCMotors – Car Dealership & Classified Listings Plugin <= 1.4.64 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin…
- CVE-2025-28311 PoCmingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 bookList getBookList sql injection
- CVE-2025-28321 PoCmingyuefusu 明月复苏 tushuguanlixitong 图书管理系统 cross-site request forgery
- CVE-2025-28331 PoCzhangyd-c OneBlog HTTP Header redos
- CVE-2025-28351 PoCzhangyd-c OneBlog RestApiController.java autoLink server-side request forgery
- CVE-2025-28461 PoCSourceCodester Online Eyewear Shop Registration Users.php registration sql injection
- CVE-2025-28471 PoCCodezips Gym Management System over_month.php sql injection
- CVE-2025-28491 PoCUPX p_lx_elf.cpp un_DT_INIT heap-based overflow
- CVE-2025-28521 PoCSourceCodester Food Ordering Management System view_menu.php sql injection
- CVE-2025-28531 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-28541 PoCcode-projects Payroll Management System update_employee.php sql injection
- CVE-2025-28861 PoCTerminating targets role delegations are not respected in tough
- CVE-2025-29073 PoCsOrder Delivery Date Pro for WooCommerce < 12.3.1 - Unauthenticated Arbitrary Option Update
- CVE-2025-29121 PoCHDF5 H5Omessage.c H5O_msg_flush heap-based overflow
- CVE-2025-29131 PoCHDF5 H5FL.c H5FL__blk_gc_list use after free
- CVE-2025-29141 PoCHDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflow
- CVE-2025-29151 PoCHDF5 H5Faccum.c H5F__accum_free heap-based overflow
- CVE-2025-29161 PoCAishida Call Center System amr2mp3 command injection
- CVE-2025-29171 PoCChestnutCMS read readFile path traversal
- CVE-2025-29191 PoCNetis WF-2404 UART hardware allows activation of test or debug logic at runtime
- CVE-2025-29201 PoCNetis WF-2404 passwd weak hash
- CVE-2025-29211 PoCNetis WF-2404 passwd default password
- CVE-2025-29221 PoCNetis WF-2404 BusyBox Shell cleartext storage
- CVE-2025-29231 PoCHDF5 H5Fint.c H5F_addr_encode_len heap-based overflow
- CVE-2025-29241 PoCHDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflow
- CVE-2025-29251 PoCHDF5 H5MM.c H5MM_realloc double free
- CVE-2025-29261 PoCHDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference
- CVE-2025-29271 PoCESAFENET CDG getFileTypeList.jsp sql injection
- CVE-2025-29291 PoCOrder Delivery Date Pro for WooCommerce < 12.4.0 - Reflected XSS
- CVE-2025-29341 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-29371 PoCInefficient Regular Expression Complexity in GitLab
- CVE-2025-29381 PoCBusiness Logic Errors in GitLab
- CVE-2025-29421 PoCOrder Delivery Date Pro for WooCommerce < 12.6.0 - Unauthenticated Arbitrary Post Title Disclosure
- CVE-2025-294511 PoCspgAdmin 4: Remote Code Execution in Query Tool and Cloud Deployment
- CVE-2025-29511 PoCBluestar Micro Mall data.php sql injection
- CVE-2025-29521 PoCBluestar Micro Mall api.php unrestricted upload
- CVE-2025-29531 PoCPyTorch torch.mkldnn_max_pool2d denial of service
- CVE-2025-29541 PoCmannaandpoem OpenManus File file_saver.py execute access control
- CVE-2025-29551 PoCTOTOLINK A3000RU IBMS Configuration File ExportIbmsConfig.sh access control
- CVE-2025-29561 PoCTRENDnet TI-G102i HTTP Request lighttpd plugins_call_handle_uri_raw null pointer dereference
- CVE-2025-29571 PoCTRENDnet TEW-411BRP+ HTTP Request httpd sub_401DB0 null pointer dereference
- CVE-2025-29582 PoCsTRENDnet TEW-818DRU HTTP Request httpd denial of service
- CVE-2025-29591 PoCTRENDnet TEW-410APB HTTP Request httpd sub_4019A0 null pointer dereference
- CVE-2025-29601 PoCTRENDnet TEW-637AP/TEW-638APB HTTP Request goahead sub_41DED0 null pointer dereference
- CVE-2025-29611 PoCopensolon org.noear.solon.core.handle.RenderManager aa render_mav path traversal
- CVE-2025-29731 PoCcode-projects College Management System student.php unrestricted upload
- CVE-2025-29741 PoCCodeCanyon Perfex CRM Contracts contract cross site scripting
- CVE-2025-29751 PoCGFI KerioConnect Signature EditHtmlSource cross site scripting
- CVE-2025-29761 PoCGFI KerioConnect File Upload cross site scripting
- CVE-2025-29771 PoCGFI KerioConnect PDF File cross site scripting
- CVE-2025-29781 PoCWCMS Article Publishing Page CKEditor unrestricted upload
- CVE-2025-29791 PoCWCMS Registration setregister cross site scripting
- CVE-2025-29841 PoCcode-projects Payroll Management System delete.php sql injection
- CVE-2025-29851 PoCcode-projects Payroll Management System update_account.php sql injection
- CVE-2025-29891 PoCTenda FH1202 Web Management Interface AdvSetWrl access control
- CVE-2025-29901 PoCTenda FH1202 Web Management Interface AdvSetWrlGstset access control
- CVE-2025-29911 PoCTenda FH1202 Web Management Interface AdvSetWrlmacfilter access control
- CVE-2025-29921 PoCTenda FH1202 Web Management Interface AdvSetWrlsafeset access control
- CVE-2025-29931 PoCTenda FH1202 default.cfg access control
- CVE-2025-29941 PoCTenda FH1202 Web Management Interface qossetting access control
- CVE-2025-29952 PoCsTenda FH1202 Web Management Interface SysToolChangePwd access control
- CVE-2025-29961 PoCTenda FH1202 Web Management Interface SysToolDDNS access control
- CVE-2025-29971 PoCzhangyanbo2007 youkefu url server-side request forgery
- CVE-2025-29981 PoCPyTorch torch.nn.utils.rnn.pad_packed_sequence memory corruption
- CVE-2025-29991 PoCPyTorch torch.nn.utils.rnn.unpack_sequence memory corruption