CVE-2025-30000 to CVE-2025-30999
45 CVEs with public proof-of-concept exploits.
- CVE-2025-300041 PoCXorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection
- CVE-2025-300051 PoCXorcom CompletePBX <= 5.2.35 Authenticated Path Traversal & File Deletion
- CVE-2025-300656 PoCsApache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
- CVE-2025-300661 PoCKEVtj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were…
- CVE-2025-301431 PoCRule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript…
- CVE-2025-301442 PoCsFast-JWT Improperly Validates iss Claims
- CVE-2025-301491 PoCOpenEMR Reflected XSS in AJAX Script
- CVE-2025-301531 PoCImproper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter
- CVE-2025-301541 PoCKEVMultiple Reviewdog actions were compromised during a specific time period
- CVE-2025-301581 PoCNamelessMC Forum iframe width/height abuse causing UI-based Denial of Service
- CVE-2025-302061 PoCDpanel's hard-coded JWT secret leads to remote code execution
- CVE-2025-3020827 PoCsVite bypasses server.fs.deny when using `?raw??`
- CVE-2025-302131 PoCFrappe has Possibility of Remote Code Execution due to improper validation
- CVE-2025-302162 PoCsCryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length
- CVE-2025-302203 PoCsGeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
- CVE-2025-302232 PoCsBeego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
- CVE-2025-302252 PoCsDirectus's S3 assets become unavailable after a burst of malformed transformations
- CVE-2025-303421 PoCAn XSS issue was discovered in OpenSlides before 4.2.5. When submitting descriptions such as Moderator Notes or Agenda Topics, an editor…
- CVE-2025-303431 PoCA directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and organized in…
- CVE-2025-303441 PoCAn issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/ endpoint, the system's response times differ…
- CVE-2025-303451 PoCAn issue was discovered in OpenSlides before 4.2.5. When creating new chats via the chat_group.create action, the user is able to specify…
- CVE-2025-303491 PoCHorde IMP through 6.2.27, as used with Horde Application Framework through 5.2.23, allows XSS that leads to account takeover via a crafted…
- CVE-2025-303502 PoCsDirectus's S3 assets become unavailable after a burst of HEAD requests
- CVE-2025-303511 PoCSuspended Directus user can continue to use session token to access API
- CVE-2025-303531 PoCDirectus's webhook trigger flows can leak sensitive data
- CVE-2025-303561 PoCHeap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity`
- CVE-2025-303592 PoCswebpack-dev-server users' source code may be stolen when they access a malicious web site
- CVE-2025-303602 PoCswebpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
- CVE-2025-303611 PoCWeGIA Vulnerable to Broken Authentication - Old Password Validation
- CVE-2025-303621 PoCWeGIA vulnerable to Stored XSS in documentos_funcionario.php parameter id
- CVE-2025-303631 PoCWeGIA vulnerable to Stored XSS in documentos_funcionario.php parameter dados_addInfo
- CVE-2025-303641 PoCWeGIA vulnerable to SQL Injection (Blind Time-Based) in remuneracao.php parameter id_funcionario
- CVE-2025-303651 PoCSQL Injection in query_geracao_auto.php
- CVE-2025-303661 PoCWeGIA vulnerable to Stored XSS in personalizacao.php
- CVE-2025-303671 PoCWeGIA SQL Injection Vulnerability in nextPage Parameter on control.php Endpoint
- CVE-2025-303701 PoCjupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
- CVE-2025-303973 PoCsKEVScripting Engine Memory Corruption Vulnerability
- CVE-2025-304002 PoCsKEVMicrosoft DWM Core Library Elevation of Privilege Vulnerability
- CVE-2025-304065 PoCsKEVGladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack…
- CVE-2025-305672 PoCsWordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability
- CVE-2025-307122 PoCsVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is…
- CVE-2025-307721 PoCWordPress WPC Smart Upsell Funnel for WooCommerce plugin <= 3.0.4 - Arbitrary Option Update to Privilege Escalation vulnerability
- CVE-2025-309111 PoCWordPress RomethemeKit For Elementor plugin <= 1.5.4 - Arbitrary Plugin Installation/Activation to RCE vulnerability
- CVE-2025-309211 PoCWordPress Newsletters plugin <= 4.9.9.7 - SQL Injection vulnerability
- CVE-2025-309671 PoCWordPress WPJobBoard plugin < 5.11.1 - CSRF to Remote Code Execution (RCE) vulnerability