CVE-2025-32000 to CVE-2025-32999
81 CVEs with public proof-of-concept exploits.
- CVE-2025-320132 PoCsServer-Side Request Forgery via LNURL Authentication Callback in LNbits Lightning Network Payment System
- CVE-2025-320151 PoCFreshRSS vulnerable to Cross-site Scripting by embedding <script> tag inside <iframe srcdoc>
- CVE-2025-320234 PoCsRedis allows out of bounds writes in hyperloglog commands leading to RCE
- CVE-2025-320281 PoCHAX CMS PHP allows Insecure File Upload to Lead to Remote Code Execution
- CVE-2025-320441 PoCMoodle: unauthenticated rest api user data exposure
- CVE-2025-320561 PoCAnti-Theft Bypass for Infotainment ECU
- CVE-2025-320571 PoCMisconfigured SSL/TLS communication of Redbend service for Infotainment ECU
- CVE-2025-320581 PoCStack Overflow in processing requests over INC interface on RH850 side of Infotainment ECU
- CVE-2025-320591 PoCStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECU
- CVE-2025-320601 PoCAbsence of Kernel Module Signature Verification on Linux System of Infotainment ECU
- CVE-2025-320611 PoCStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECU
- CVE-2025-320621 PoCStack Buffer Overflow leading to RCE in Bluetooth stack of Infotainment ECU
- CVE-2025-320631 PoCEnabling SSH server on Infotainment ECU
- CVE-2025-321031 PoCCrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/ URI to read files…
- CVE-2025-321181 PoCWordPress CMP – Coming Soon & Maintenance plugin <= 4.1.14 - Remote Code Execution (RCE) vulnerability
- CVE-2025-321401 PoCWordPress WP Remote Thumbnail Plugin <= 1.3.2 - Arbitrary File Upload vulnerability
- CVE-2025-322061 PoCWordPress Processing Projects Plugin <= 1.0.2 - Arbitrary File Upload vulnerability
- CVE-2025-322571 PoCWordPress 1 Click WordPress Migration plugin <= 2.5.7 - Sensitive Data Exposure vulnerability
- CVE-2025-322591 PoCWordPress WP ULike plugin <= 4.7.9.1 - Content Spoofing Vulnerability
- CVE-2025-323551 PoCRocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a…
- CVE-2025-323641 PoCA floating-point exception in the PSStack::roll function of Poppler before 25.04.0 can cause an application to crash when handling…
- CVE-2025-323651 PoCPoppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc…
- CVE-2025-323671 PoCThe Oz Forensics face recognition application before 4.0.8 late 2023 allows PII retrieval via /statistic/list Insecure Direct Object…
- CVE-2025-323691 PoCKentico Xperience before 13.0.181 allows authenticated users to distribute malicious content (for stored XSS) via certain interactions…
- CVE-2025-323702 PoCsKentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however,…
- CVE-2025-323755 PoCsInsecure Deserialization leads to RCE in BentoML's runner server
- CVE-2025-323881 PoCSvelteKit allows XSS via tracked search_params
- CVE-2025-323901 PoCEspoCRM vulnerable to HTML Injection into phishing, which may lead to account takeover
- CVE-2025-323955 PoCsVite has an `server.fs.deny` bypass with an invalid `request-target`
- CVE-2025-324071 PoCSamsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates,…
- CVE-2025-324211 PoCNext.js Race Condition to Cache Poisoning
- CVE-2025-324294 PoCsXWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
- CVE-2025-324302 PoCsXWiki Platform contains Reflected XSS vulnerability in two templates
- CVE-2025-3243219 PoCsKEVCraft CMS Allows Remote Code Execution
- CVE-2025-3243341 PoCsKEVErlang/OTP SSH Vulnerable to Pre-Authentication RCE
- CVE-2025-324343 PoCsPyTorch: `torch.load` with `weights_only=True` leads to remote code execution
- CVE-2025-324511 PoCA memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted…
- CVE-2025-3246216 PoCsSudo before 1.9.17p1, when used with a sudoers file that specifies a host that is neither the current host nor ALL, allows listed users to…
- CVE-2025-3246377 PoCsKEVSudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the…
- CVE-2025-324681 PoCA memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading…
- CVE-2025-325791 PoCWordPress Sync Posts Plugin <= 1.0 - Arbitrary File Upload vulnerability
- CVE-2025-325831 PoCWordPress PDF 2 Post Plugin <= 2.4.0 - Remote Code Execution (RCE) vulnerability
- CVE-2025-326141 PoCWordPress EventON plugin <= 2.4 - Local File Inclusion vulnerability
- CVE-2025-326411 PoCWordPress Anant Addons for Elementor plugin <= 1.1.8 - CSRF to Arbitrary Plugin Installation vulnerability
- CVE-2025-326821 PoCWordPress MapSVG Lite plugin <= 8.6.4 - Arbitrary File Upload Vulnerability
- CVE-2025-327062 PoCsKEVWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2025-327101 PoCWindows Remote Desktop Services Remote Code Execution Vulnerability
- CVE-2025-327112 PoCsM365 Copilot Information Disclosure Vulnerability
- CVE-2025-327565 PoCsKEVA stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10,…
- CVE-2025-327783 PoCsWeb-Check allows command Injection via Unvalidated URL in Screenshot API
- CVE-2025-327891 PoCEspoCRM Allows Potential Disclosure of Sensitive Information in the User Sorting Function
- CVE-2025-327901 PoCDify Allows Insecure User Role Access Control for APP DSL Exporting
- CVE-2025-327941 PoCOpenEMR Stored XSS via Patient Name Field in Procedure Orders
- CVE-2025-327951 PoCDify Allows Insecure User Role Access Control for APP Editing
- CVE-2025-327961 PoCDify Allows Unauthorized APP Enable/Disable via API
- CVE-2025-327981 PoCConda-build Allows Arbitrary Code Execution via Malicious Recipe Selectors
- CVE-2025-327991 PoCConda-build Vulnerable to Path Traversal via Malicious Tar File
- CVE-2025-328081 PoCW. W. Norton InQuizitive through 2025-04-08 allows students to insert arbitrary records of their quiz performance into the backend,…
- CVE-2025-328091 PoCW. W. Norton InQuizitive through 2025-04-08 allows students to conduct stored XSS attacks against educators via a bonus description,…
- CVE-2025-328132 PoCsAn issue was discovered in Infoblox NETMRI before 7.6.1. Remote Unauthenticated Command Injection can occur.
- CVE-2025-328142 PoCsAn issue was discovered in Infoblox NETMRI before 7.6.1. Unauthenticated SQL Injection can occur.
- CVE-2025-328152 PoCsAn issue was discovered in Infoblox NETMRI before 7.6.1. Authentication Bypass via a Hardcoded credential can occur.
- CVE-2025-328731 PoCAn issue was discovered in Django 4.2 before 4.2.21, 5.1 before 5.1.9, and 5.2 before 5.2.1. The django.utils.html.strip_tags() function…
- CVE-2025-328761 PoCAn issue was discovered on COROS PACE 3 devices through 3.0808.0. The BLE implementation of the COROS smartwatch does not support LE…
- CVE-2025-328771 PoCAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It identifies itself as a device without input or output capabilities,…
- CVE-2025-328781 PoCAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. This function…
- CVE-2025-328791 PoCAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It starts advertising if no device is connected via Bluetooth. This…
- CVE-2025-328801 PoCAn issue was discovered on COROS PACE 3 devices through 3.0808.0. It implements a function to connect the watch to a WLAN. With WLAN…
- CVE-2025-329431 PoCPeerTube HLS Video Files Path Traversal
- CVE-2025-329441 PoCPeerTube User Import Authenticated Persistent Denial of Service
- CVE-2025-329451 PoCPeerTube Arbitrary Playlist Creation via REST API
- CVE-2025-329461 PoCPeerTube Arbitrary Playlist Creation via ActivityPub Protocol
- CVE-2025-329471 PoCPeerTube ActivityPub Crawl Infinite Loop DoS
- CVE-2025-329481 PoCPeerTube ActivityPub Playlist Creation Blind SSRF and DoS
- CVE-2025-329491 PoCPeerTube User Import Authenticated Resource Exhaustion
- CVE-2025-329562 PoCsManageWiki has SQL injection vulnerability in NamespaceMigrationJob
- CVE-2025-329651 PoCCompromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2
- CVE-2025-329663 PoCsDataease H2 JDBC Connection Remote Code Execution
- CVE-2025-329671 PoCOpenEMR doesn't log password administration properly
- CVE-2025-329691 PoCorg.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API
- CVE-2025-329701 PoCorg.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability