CVE-2025-34000 to CVE-2025-34999
195 CVEs with public proof-of-concept exploits.
- CVE-2025-340214 PoCsSelea Targa IP OCR-ANPR Camera Server-Side Request Forgery
- CVE-2025-340224 PoCsSelea Targa IP OCR-ANPR Camera Path Traversal
- CVE-2025-340233 PoCsKarel IP Phone IP1211 Path Traversal
- CVE-2025-340241 PoCEdimax EW-7438RPn Mini OS Command Injection via mp.asp
- CVE-2025-340251 PoCVersa Concerto Insecure Docker Mount Container Escape
- CVE-2025-340262 PoCsKEVVersa Concerto Actuator Authentication Bypass Information Leak
- CVE-2025-340272 PoCsVersa Concerto Authentication Bypass File Write Remote Code Execution
- CVE-2025-340285 PoCsKEVCommvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
- CVE-2025-340291 PoCEdimax EW-7438RPn Mini OS Command Injection via syscmd.asp
- CVE-2025-340303 PoCssar2html OS Command Injection
- CVE-2025-340313 PoCsMoodle LMS Jmol Plugin Path Traversal
- CVE-2025-340323 PoCsMoodle LMS Jmol Plugin Cross-site Scripting (XSS)
- CVE-2025-340332 PoCs5VTechnologies Blue Angel Software Suite OS Command Injection
- CVE-2025-340341 PoC5VTechnologies Blue Angel Software Suite Hardcoded Credentials
- CVE-2025-340355 PoCsEnGenius EnShare IoT Gigabit Cloud Service Command Injection
- CVE-2025-340362 PoCsShenzhen TVT CCTV-DVR Command Injection
- CVE-2025-340373 PoCsLinksys Routers E/WAG/WAP/WES/WET/WRT-Series
- CVE-2025-340382 PoCsWeaver E-cology SQL Injection
- CVE-2025-340391 PoCYonyou NC BeanShell Command Injection
- CVE-2025-340405 PoCsSeeyon Zhiyuan OA System Path Traversal File Upload
- CVE-2025-340423 PoCsBeward N100 IP Camera Remote Command Execution
- CVE-2025-340431 PoCVacron NVR Remote Command Execution
- CVE-2025-340451 PoCWeiPHP Path Traversal Arbitrary File Read
- CVE-2025-340462 PoCsFanwei E-Office Unauthenticated File Upload
- CVE-2025-340471 PoCLeadsec VPN Path Traversal Arbitrary File Read
- CVE-2025-340482 PoCsD-Link DSL-2730U/2750U/2750E Path Traversal Arbitrary File Read
- CVE-2025-340492 PoCsOptiLink ONT1GEW GPON Remote Code Execution
- CVE-2025-340502 PoCsAVTECH IP Camera, DVR, and NVR Devices Cross-Site Request Forgery
- CVE-2025-340512 PoCsAVTECH DVR Devices Server-Side Request Forgery
- CVE-2025-340532 PoCsAVTECH IP camera, DVR, and NVR Devices Authentication Bypass via .cab Path Manipulation
- CVE-2025-340542 PoCsAVTECH IP camera, DVR, and NVR Devices Unauthenticated Command Injection
- CVE-2025-340552 PoCsAVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution
- CVE-2025-340562 PoCsAVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution
- CVE-2025-340572 PoCsRuijie NBR Router Administrative Credential Disclosure
- CVE-2025-340581 PoCHikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File Read
- CVE-2025-340591 PoCDahua Smart Cloud Gateway Registration Management Platform SQL Injection
- CVE-2025-340612 PoCsPHPStudy 2016-2018 Backdoor Remote Code Execution Vulnerability
- CVE-2025-340652 PoCsAVTECH IP camera, DVR, and NVR Devices Authentication Bypass via /nobody URL Path
- CVE-2025-340662 PoCsAVTECH IP camera, DVR, and NVR Devices Unauthenticated Information Disclosure
- CVE-2025-340671 PoCHikvision Integrated Security Management Platform Remote Command Execution via applyCT Fastjson
- CVE-2025-340681 PoCSamsung WLAN AP WEA453e < 5.2.4.T1 Unauthenticated RCE via command1 and command2 Parameters
- CVE-2025-340691 PoCGFI Kerio Control GFIAgent Authentication Bypass via Proxy Forwarding
- CVE-2025-340701 PoCGFI Kerio Control GFIAgent Missing Authentication on Administrative Interfaces
- CVE-2025-340711 PoCGFI Kerio Control Unsigned System Image Upload Root Code Execution
- CVE-2025-340721 PoCAnthropic Slack MCP Server Data Exfiltration via Link Unfurling
- CVE-2025-340735 PoCsstamparm/maltrail <=0.54 Remote Command Execution
- CVE-2025-340742 PoCsLucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File Write
- CVE-2025-340763 PoCsMicroweber CMS Authenticated Local File Inclusion via Backup API
- CVE-2025-340778 PoCsWordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
- CVE-2025-340784 PoCsNSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web Interface
- CVE-2025-340793 PoCsNSClient++ Authenticated Remote Code Execution via ExternalScripts API
- CVE-2025-340822 PoCsIGEL OS Secure Terminal and Secure Shadow Remote Code Execution
- CVE-2025-340864 PoCsBolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename
- CVE-2025-340873 PoCsPi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
- CVE-2025-340884 PoCsPandora FMS Authenticated Remote Code Execution via Ping Module
- CVE-2025-340894 PoCsRemote for Mac Unauthenticated Remote Code Execution via AppleScript Injection
- CVE-2025-340934 PoCsPolycom HDX Series Telnet Command Injection via lan traceroute
- CVE-2025-340953 PoCsMako Server v2.5 and v2.6 OS Command Injection via examples/save.lsp
- CVE-2025-340964 PoCsEasy File Sharing HTTP Server 7.2 Buffer Overflow via POST to /sendemail.ghp
- CVE-2025-340973 PoCsProcessMaker < 3.5.4 Authenticated Plugin Upload RCE
- CVE-2025-340983 PoCsRiverbed SteelHead VCX Authenticated Arbitrary File Read via Log Filter Injection
- CVE-2025-340993 PoCsVICIdial vicidial_sales_viewer.php Unauthenticated Command Injection via Basic Auth Password
- CVE-2025-341006 PoCsBuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
- CVE-2025-341015 PoCsServiio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
- CVE-2025-341024 PoCsCryptoLog Unauthenticated RCE via SQL Injection and Command Injection
- CVE-2025-341033 PoCsWePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
- CVE-2025-341042 PoCsPiwik Authenticated RCE via Custom Plugin Upload
- CVE-2025-341054 PoCsDiskBoss Enterprise Stack-Based Buffer Overflow RCE
- CVE-2025-341063 PoCsPDF Shaper v3.5/3.6 Buffer Overflow via Convert to Image Feature
- CVE-2025-341074 PoCsWinaXe 7.7 FTP Client Remote Buffer Overflow
- CVE-2025-341084 PoCsDisk Pulse Enterprise 9.0.34 Login Stack Buffer Overflow
- CVE-2025-341093 PoCsPanda Security PSEvents.exe Insecure DLL Loading Privilege Escalation
- CVE-2025-341103 PoCsColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure
- CVE-2025-341113 PoCsTiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCE
- CVE-2025-341123 PoCsRiverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE
- CVE-2025-341133 PoCsTiki Wiki CMS Authenticated Command Injection in Calendar Module
- CVE-2025-341141 PoCOpenBlow Missing Critical Security Headers
- CVE-2025-341153 PoCsOP5 Monitor <= 7.1.9 Authenticated Command Execution via command_test.php
- CVE-2025-341164 PoCsIPFire < 2.19 Core Update 101 proxy.cgi RCE
- CVE-2025-341174 PoCsNetcore / Netis Routers RCE via UDP Port 53413 Backdoor
- CVE-2025-341182 PoCsLinknat VOS Manager Path Traversal File Disclosure
- CVE-2025-341193 PoCsEasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43
- CVE-2025-341203 PoCsLimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup Payload
- CVE-2025-341214 PoCsIdera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
- CVE-2025-341233 PoCsVideoCharge Studio 2.12.3.685 SEH Buffer Overflow via .VSC File
- CVE-2025-341243 PoCsHeroes of Might and Magic III .h3m Map File Buffer Overflow
- CVE-2025-341254 PoCsD-Link DSP-W110A1 Cookie Command Injection
- CVE-2025-341264 PoCsRIPS Scanner v0.54 Path Traversal
- CVE-2025-341273 PoCsAchat v0.150 SEH Buffer Overflow via UDP
- CVE-2025-341284 PoCsX360 VideoPlayer ActiveX Control Buffer Overflow via ConvertFile()
- CVE-2025-341411 PoCETQ Reliance CG < SE.2025.1 Reflected XSS in `SQLConverterServlet`
- CVE-2025-341431 PoCETQ Reliance CG Authentication Bypass via Trailing Space RCE
- CVE-2025-341461 PoCnyariv sandboxjs 0.8.23 Prototype Pollution Sandbox Escape DoS
- CVE-2025-341471 PoCShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via SSID
- CVE-2025-341481 PoCShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via WISP SSID
- CVE-2025-341491 PoCShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via WPA2 Key
- CVE-2025-341501 PoCShenzhen Aitemi M300 Wi-Fi Repeater PPPoE Username Command Injection
- CVE-2025-341511 PoCShenzhen Aitemi M300 Wi-Fi Repeater PPPoE Password Command Injection
- CVE-2025-341525 PoCsShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
- CVE-2025-341531 PoCHyland OnBase < 17.0.2.87 .NET Remoting TCP Channel Unauthenticated RCE
- CVE-2025-341541 PoCUnForm Server Manager < 10.1.12 Unauthenticated Arbitrary File Read
- CVE-2025-341571 PoCCoolify Stored Cross-Site Scripting (XSS) in Project Name Field
- CVE-2025-341591 PoCCoolify Docker Compose Directive Injection in Application Deployment Workflow
- CVE-2025-341601 PoCAnyShare ServiceAgent API Unauthenticated RCE
- CVE-2025-341611 PoCCoolify Git Repository Field Command Injection in Project Deployment Workflow
- CVE-2025-341621 PoCBian Que Feijiu Intelligent Emergency and Quality Control System SQL Injection via GetLyfsByParams
- CVE-2025-341631 PoCDongsheng Logistics Software Unauthenticated Arbitrary File Upload
- CVE-2025-341791 PoCNetSupport Manager < 14.12.0001 Unauthenticated SQLi Local File Disclosure
- CVE-2025-341801 PoCNetSupport Manager < 14.12.0001 Gateway Key Reversible Encoding Credential Recovery
- CVE-2025-341811 PoCNetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE
- CVE-2025-341832 PoCsIlevia EVE X1 Server 4.7.18.0.eden Credentials Leak Through Log Disclosure
- CVE-2025-341842 PoCsIlevia EVE X1 Server 4.7.18.0.eden Neuro-Core Unauthenticated Code Injection
- CVE-2025-341852 PoCsIlevia EVE X1 Server 4.7.18.0.eden Unauthenticated File Disclosure
- CVE-2025-341862 PoCsIlevia EVE X1/X5 Server 4.7.18.0.eden Authentication Bypass
- CVE-2025-341872 PoCsIlevia EVE X1/X5 Server 4.7.18.0.eden Reverse Rootshell
- CVE-2025-341881 PoCVasion Print (formerly PrinterLogic) Local Log Disclosure of Cleartext Sessions
- CVE-2025-341891 PoCVasion Print (formerly PrinterLogic) Insecure Inter-Process Communication Allows Local Session Hijacking
- CVE-2025-341901 PoCVasion Print (formerly PrinterLogic) PrinterInstallerClientService Authentication Bypass via LD_PRELOAD Hooking
- CVE-2025-341911 PoCVasion Print (formerly PrinterLogic) Arbitrary File Write as Root via Response Path Symlink Follow
- CVE-2025-341921 PoCVasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL Version
- CVE-2025-341931 PoCVasion Print (formerly PrinterLogic) Insecure Windows Components Lack Modern Memory Protections and Use Outdated Runtimes
- CVE-2025-341941 PoCVasion Print (formerly PrinterLogic) Local Privilege Escalation via Insecure Temporary File Handling
- CVE-2025-341951 PoCVasion Print (formerly PrinterLogic) Unquoted Path During Driver Installation Leads to Execution of C:\Program.exe
- CVE-2025-341971 PoCVasion Print (formerly PrinterLogic) Undocumented Local Account with Hardcoded Password and Passwordless sudo
- CVE-2025-341981 PoCVasion Print (formerly PrinterLogic) Shared / Hardcoded SSH Host Private Keys in Appliance Image
- CVE-2025-341991 PoCVasion Print (formerly PrinterLogic) Insecure SSL Verification Allows Man-in-the-Middle Attacks
- CVE-2025-342001 PoCVasion Print (formerly PrinterLogic) Network Account Password Stored in Cleartext
- CVE-2025-342011 PoCVasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instances
- CVE-2025-342021 PoCVasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
- CVE-2025-342031 PoCVasion Print (formerly PrinterLogic) Use of Outdated, End-Of-Life, and Vulnerable Third-Party Components
- CVE-2025-342041 PoCVasion Print (formerly PrinterLogic) Processes Running as Root Inside Docker Instances
- CVE-2025-342051 PoCVasion Print (formerly PrinterLogic) Dangerous PHP Dead Code Enables RCE
- CVE-2025-342061 PoCVasion Print (formerly PrinterLogic) Insecure Shared Storage Permissions
- CVE-2025-342272 PoCsNagios XI < 2026R1 Configuration Wizard Authenticated Command Injection
- CVE-2025-342511 PoCTesla Telematics Control Unit (TCU) < v2025.14 Authentication Bypass
- CVE-2025-342561 PoCAdvantech WISE-DeviceOn Server < 5.4 Hard-coded JWT Key Authentication Bypass
- CVE-2025-342822 PoCsThingsBoard < v4.2.1 SVG Image SSRF
- CVE-2025-342912 PoCsKEVLangflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
- CVE-2025-342921 PoCBeWelcome/Rox PHP Object Injection RCE
- CVE-2025-342994 PoCsMonsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
- CVE-2025-343003 PoCsSawtooth Software Lighthouse Studio < 9.16.14 Pre-Authentication RCE
- CVE-2025-343222 PoCsNagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries
- CVE-2025-343232 PoCsNagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules
- CVE-2025-343243 PoCsGoSign Desktop < 2.4.1 Insecure Update Mechanism RCE
- CVE-2025-343282 PoCsAudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Upload RCE via ajaxScript.php
- CVE-2025-343292 PoCsAudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated Backup Upload RCE via ajaxBackupUploadFile.php
- CVE-2025-343302 PoCsAudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated Prompt File Upload via ajaxPromptUploadFile.php
- CVE-2025-343312 PoCsAudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Read via download.php
- CVE-2025-343322 PoCsAudioCodes Fax/IVR Appliance <= 2.6.23 Insecure Service Control Scripts LPE
- CVE-2025-343332 PoCsAudioCodes Fax/IVR Appliance <= 2.6.23 World-Writable Webroot LPE
- CVE-2025-343342 PoCsAudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via TestFax.php & LPE
- CVE-2025-343352 PoCsAudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via ActivateLicense.php
- CVE-2025-343362 PoCseGovFramework <= 4.3.1 Unauthenticated File Upload via Web Editor Image Upload Endpoints
- CVE-2025-343372 PoCseGovFramework <= 4.3.1 Unauthenticated Encryption Oracle via Web Editor Image Upload Endpoints
- CVE-2025-343921 PoCBarracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE
- CVE-2025-344131 PoCLegality WHISTLEBLOWING Missing Critical HTTP Security Headers
- CVE-2025-344332 PoCsAVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt
- CVE-2025-344341 PoCAVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and Deletion
- CVE-2025-344351 PoCAVideo < 20.1 IDOR Arbitrary File Deletion
- CVE-2025-344361 PoCAVideo < 20.1 IDOR Arbitrary File Upload
- CVE-2025-344371 PoCAVideo < 20.1 IDOR Arbitrary Comment Image Upload
- CVE-2025-344381 PoCAVideo < 20.1 IDOR Arbitrary Video Rotation
- CVE-2025-344391 PoCAVideo < 20.1 Open Redirect via cancelUri Parameter
- CVE-2025-344401 PoCAVideo < 20.1 Open Redirect via siteRedirectUri Parameter
- CVE-2025-344412 PoCsAVideo < 20.1 User Information Disclosure via Public API
- CVE-2025-344422 PoCsAVideo < 20.1 System Path Disclosure via Public API
- CVE-2025-344491 PoCGenymobile/scrcpy <= 3.3.3 Global Buffer Overflow
- CVE-2025-344501 PoCmerbanan/rtl_433 <= 25.02 Stack-based Buffer Overflow
- CVE-2025-344511 PoCrofl0r/proxychains-ng <= 4.17 Stack-based Buffer Overflow
- CVE-2025-344521 PoCStreama Subtitle Download Path Traversal and SSRF Leading to Arbitrary File Write
- CVE-2025-344571 PoCwb2osz/direwolf <= 1.8.1 Stack-based Buffer Overflow DoS
- CVE-2025-344581 PoCwb2osz/direwolf <= 1.8.1 Reachable Assertion DoS
- CVE-2025-344691 PoCCowrie < 2.9.0 Unrestricted wget/curl Emulation Enables SSRF-Based DDoS Amplification
- CVE-2025-344891 PoCGFI MailEssentials < 21.8 Local Privilege Escalation
- CVE-2025-344901 PoCGFI MailEssentials < 21.8 XXE Arbitrary File Read
- CVE-2025-344911 PoCGFI MailEssentials < 21.8 MultiNode Insecure Deserialization
- CVE-2025-344992 PoCsAnyDesk 9.0.1 Unquoted Service Path Privilege Escalation Vulnerability
- CVE-2025-345001 PoCShuffle Master Deck Mate 2 Insecure Update Chain
- CVE-2025-345011 PoCShuffle Master Deck Mate 2 Hard-coded Credentials & Exposed Services
- CVE-2025-345021 PoCShuffle Master Deck Mate 2 Missing Secure Boot
- CVE-2025-345031 PoCShuffle Master Deck Mate 1 Unauthenticated EEPROM Firmware Execution
- CVE-2025-345041 PoCKodExplorer 4.52 Open Redirect Vulnerability via User Login Endpoint
- CVE-2025-345061 PoCWBCE CMS 1.6.3 Authenticated Remote Code Execution via Module Upload
- CVE-2025-345081 PoCZendTo < 6.15-8 Path Traversal
- CVE-2025-345092 PoCsSitecore XM and XP Hardcoded Credentials
- CVE-2025-345102 PoCsSitecore XM, XC, and XP Post-Auth RCE via Zip Slip
- CVE-2025-345112 PoCsSitecore PowerShell Extension RCE via Unrestricted Upload
- CVE-2025-345121 PoCIlevia EVE X1 Server 4.7.18.0.eden Reflected XSS
- CVE-2025-345131 PoCIlevia EVE X1 Server 4.7.18.0.eden Unauthenticated Command Injection
- CVE-2025-345141 PoCIlevia EVE X1 Server 4.7.18.0.eden Authenticated Command Injection
- CVE-2025-345151 PoCIlevia EVE X1 Server 4.7.18.0.eden Root Privilege Escalation
- CVE-2025-345161 PoCIlevia EVE X1 Server 4.7.18.0.eden Use of Default Credentials
- CVE-2025-345171 PoCIlevia EVE X1 Server 4.7.18.0.eden Absolute Path Traversal
- CVE-2025-345181 PoCIlevia EVE X1 Server 4.7.18.0.eden Relative Path Traversal
- CVE-2025-345191 PoCIlevia EVE X1 Server 4.7.18.0.eden Insecure Hashing Algorithm