CVE-2025-39000 to CVE-2025-39999
13 CVEs with public proof-of-concept exploits.
- CVE-2025-392471 PoCThere is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain theā¦
- CVE-2025-394012 PoCsWordPress WPAMS plugin <= 44.0 (17-08-2023) - Arbitrary File Upload vulnerability
- CVE-2025-394361 PoCWordPress I Draw <= 1.0 - Arbitrary File Upload Vulnerability
- CVE-2025-394592 PoCsWordPress Real Estate 7 theme <= 3.5.2 - Privilege Escalation vulnerability
- CVE-2025-395381 PoCWordPress WP-Advanced-Search plugin <= 3.3.9.4 - Arbitrary File Upload Vulnerability
- CVE-2025-395961 PoCWordPress Quentn WP plugin <= 1.2.8 - Privilege Escalation Vulnerability
- CVE-2025-396011 PoCWordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability
- CVE-2025-396821 PoCtls: fix handling of zero-length records on the rx_list
- CVE-2025-398661 PoCfs: writeback: fix use-after-free in __mark_inode_dirty()
- CVE-2025-399131 PoCtcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork.
- CVE-2025-399461 PoCtls: make sure to abort the stream if headers are bogus
- CVE-2025-399642 PoCscrypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
- CVE-2025-399651 PoCxfrm: xfrm_alloc_spi shouldn't use 0 as SPI