CVE-2025-31000 to CVE-2025-31999
33 CVEs with public proof-of-concept exploits.
- CVE-2025-310331 PoCWordPress Buddypress Humanity plugin <= 1.2 - CSRF to Privilege Escalation vulnerability
- CVE-2025-311162 PoCsMobile Security Framework (MobSF) has a SSRF Vulnerability fix bypass on assetlinks_check with DNS Rebinding
- CVE-2025-311171 PoCOpenEMR Out-of-Band Server-Side Request Forgery (OOB SSRF) Vulnerability
- CVE-2025-311181 PoCNamelessMC Has Forum Reply Submission Time Limit Bypass
- CVE-2025-311201 PoCNamelessMC Vulnerable to Cookie-Based View Count Manipulation
- CVE-2025-311259 PoCsKEVVite has a `server.fs.deny` bypassed for `inline` and `raw` with `?import` query
- CVE-2025-311291 PoCjooby-pac4j: deserialization of untrusted data
- CVE-2025-311301 PoCgitoxide does not detect SHA-1 collision attacks
- CVE-2025-311315 PoCsPath Traversal allowing arbitrary read of files in Yeswiki
- CVE-2025-311333 PoCsrunc container escape via "masked path" abuse due to mount race conditions
- CVE-2025-311341 PoCFreshRSS vulnerable to directory enumeration via ext.php
- CVE-2025-311361 PoCFreshRSS vulnerable to Cross-site Scripting by <iframe>'ing a vulnerable same-origin page in a feed entry
- CVE-2025-311371 PoCRemix and React Router allow URL manipulation via Host / X-Forwarded-Host headers
- CVE-2025-3116130 PoCsKEVCrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy…
- CVE-2025-311921 PoCThe issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website…
- CVE-2025-312008 PoCsKEVA memory corruption issue was addressed with improved bounds checking. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1…
- CVE-2025-312014 PoCsKEVThis issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 18.4.1, visionOS 2.4.1, iOS iOS 18.4.1 and iPadOS…
- CVE-2025-312581 PoCThis issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.5. An app may be able to break out of…
- CVE-2025-312772 PoCsKEVThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6,…
- CVE-2025-3132420 PoCsKEVMissing Authorization check in SAP NetWeaver (Visual Composer development server)
- CVE-2025-314771 PoCImproper Scope Validation in the open Endpoint of tauri-plugin-shell
- CVE-2025-314821 PoCFreshRSS vulnerable to DoS by malicious feed entry loading logout URL
- CVE-2025-314865 PoCsVite allows server.fs.deny to be bypassed with .svg or relative paths
- CVE-2025-314891 PoCMinIO performs incomplete signature validation for unsigned-trailer uploads
- CVE-2025-314901 PoCAutoGPT allows SSRF due to DNS Rebinding in requests wrapper
- CVE-2025-314911 PoCAutoGPT allows leakage of cross-domain cookies and protected headers in requests redirect
- CVE-2025-316441 PoCAppliance mode BIG-IP iControl REST and tmsh vulnerability
- CVE-2025-316507 PoCsApache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
- CVE-2025-316512 PoCsApache Tomcat: Bypass of rules in Rewrite Valve
- CVE-2025-317101 PoCIn engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of…
- CVE-2025-317222 PoCsIn Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing…
- CVE-2025-318641 PoCWordPress Beam me up Scotty – Back to Top Button plugin <= 1.0.23 - Cross Site Scripting (XSS) vulnerability
- CVE-2025-319311 PoCUncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User…