CVE-2025-3000 to CVE-2025-3999
447 CVEs with public proof-of-concept exploits.
- CVE-2025-30001 PoCPyTorch torch.jit.script memory corruption
- CVE-2025-30011 PoCPyTorch torch.lstm_cell memory corruption
- CVE-2025-30021 PoCDigital China DCME-520 mon_merge_stat_hist.php os command injection
- CVE-2025-30031 PoCESAFENET CDG UserAjax sql injection
- CVE-2025-30041 PoCSayski ForestBlog search cross site scripting
- CVE-2025-30051 PoCSayski ForestBlog Friend Link cross site scripting
- CVE-2025-30061 PoCPHPGurukul e-Diary Management System edit-category.php sql injection
- CVE-2025-30091 PoCJinher Network OA NetDiskProperty.aspx sql injection
- CVE-2025-30101 PoCKhronos Group glslang Intermediate.cpp isConversionAllowed null pointer dereference
- CVE-2025-30151 PoCOpen Asset Import Library Assimp ASE File ASELoader.cpp BuildUniqueRepresentation out-of-bounds
- CVE-2025-30161 PoCOpen Asset Import Library Assimp MDL File MDLMaterialLoader.cpp ParseTextureColorData resource consumption
- CVE-2025-30171 PoCTA-Lib ta_regtest test_minmax.c setInputBuffer out-of-bounds write
- CVE-2025-30181 PoCSourceCodester Online Eyewear Shop Users.php sql injection
- CVE-2025-30361 PoCyzk2356911358 StudentServlet-JSP Student Management cross site scripting
- CVE-2025-30371 PoCyzk2356911358 StudentServlet-JSP cross-site request forgery
- CVE-2025-30381 PoCcode-projects Payroll Management System view_account.php sql injection
- CVE-2025-30391 PoCcode-projects Payroll Management System add_employee.php sql injection
- CVE-2025-30401 PoCProject Worlds Online Time Table Generator add_student.php unrestricted upload
- CVE-2025-30411 PoCProject Worlds Online Time Table Generator updatestudent.php unrestricted upload
- CVE-2025-30421 PoCProject Worlds Online Time Table Generator updateprofile.php unrestricted upload
- CVE-2025-30431 PoCGuoMinJim PersonManage login preHandle path traversal
- CVE-2025-30451 PoCoretnom23/SourceCodester Apartment Visitor Management System remove-apartment.php sql injection
- CVE-2025-30522 PoCsAn arbitrary write vulnerability in Microsoft signed UEFI firmware from DT Research Inc.
- CVE-2025-30541 PoCWP User Frontend Pro <= 4.1.3 - Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2025-30961 PoCClinics Patient Management System SQL Injection
- CVE-2025-310211 PoCsSureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
- CVE-2025-31081 PoCUnsafe Deserialization in JsonPickleSerializer Enables Remote Code Execution in run-llama/llama_index
- CVE-2025-31111 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-31181 PoCSourceCodester Online Tutor Portal view_course.php sql injection
- CVE-2025-31191 PoCSourceCodester Online Tutor Portal manage_course.php sql injection
- CVE-2025-31201 PoCSourceCodester Apartment Visitors Management System add-apartment.php sql injection
- CVE-2025-31211 PoCPyTorch torch.jit.jit_module_from_flatbuffer memory corruption
- CVE-2025-31221 PoCWebAssembly wabt binary-reader-interp.cc BeginFunctionBody null pointer dereference
- CVE-2025-31231 PoCWonderCMS Theme Installation/Plugin Installation installUpdateModuleAction unrestricted upload
- CVE-2025-31341 PoCcode-projects Payroll Management System add_overtime.php sql injection
- CVE-2025-31351 PoCfcba_zzm ics-park Smart Park Management System update sql injection
- CVE-2025-31361 PoCPyTorch CUDACachingAllocator.cpp torch.cuda.memory.caching_allocator_delete memory corruption
- CVE-2025-31371 PoCPHPGurukul Online Security Guards Hiring System changeimage.php sql injection
- CVE-2025-31381 PoCPHPGurukul Online Security Guards Hiring System edit-guard-detail.php sql injection
- CVE-2025-31391 PoCcode-projects Bus Reservation System Login Form login buffer overflow
- CVE-2025-31401 PoCSourceCodester Online Medicine Ordering System view_category.php sql injection
- CVE-2025-31411 PoCSourceCodester Online Medicine Ordering System manage_category.php sql injection
- CVE-2025-31421 PoCSourceCodester Apartment Visitor Management System add-apartment.php sql injection
- CVE-2025-31431 PoCSourceCodester Apartment Visitor Management System visitor-entry.php sql injection
- CVE-2025-31441 PoCMindSpore mindspore.numpy.fft.hfftn memory corruption
- CVE-2025-31451 PoCMindSpore mindspore.numpy.fft.rfft2 memory corruption
- CVE-2025-31462 PoCsPHPGurukul Bus Pass Management System view-pass-detail.php sql injection
- CVE-2025-31471 PoCPHPGurukul Boat Booking System add-subadmin.php sql injection
- CVE-2025-31481 PoCcodeprojects Product Management System Login buffer overflow
- CVE-2025-31491 PoCitning Student Homework Management System Edit Job Page fileupload cross site scripting
- CVE-2025-31501 PoCitning Student Homework Management System cross-site request forgery
- CVE-2025-31511 PoCSourceCodester Gym Management System signup.php sql injection
- CVE-2025-31521 PoCcaipeichao ThinkOX Search search.html cross site scripting
- CVE-2025-31551 PoCYelp: arbitrary file read
- CVE-2025-31581 PoCOpen Asset Import Library Assimp LWO File LWOAnimation.cpp UpdateAnimRangeSetup heap-based overflow
- CVE-2025-31591 PoCOpen Asset Import Library Assimp ASE File ASEParser.cpp ParseLV4MeshBonesVertices heap-based overflow
- CVE-2025-31601 PoCOpen Asset Import Library Assimp File SceneCombiner.cpp AddNodeHashes out-of-bounds
- CVE-2025-31611 PoCTenda AC10 ShutdownSetAdd stack-based overflow
- CVE-2025-31621 PoCInternLM LMDeploy PT File utils.py load_weight_ckpt deserialization
- CVE-2025-31631 PoCInternLM LMDeploy conf.py open code injection
- CVE-2025-31641 PoCTencent Music Entertainment SuperSonic H2 Database Connection testConnect code injection
- CVE-2025-31661 PoCcode-projects Product Management System Search Product Menu search_item stack-based overflow
- CVE-2025-31671 PoCTenda AC23 API Interface VerAPIMant denial of service
- CVE-2025-31681 PoCPHPGurukul Time Table Generator System edit-class.php sql injection
- CVE-2025-31691 PoCProjeqtor saveAttachment.php unrestricted upload
- CVE-2025-31701 PoCProject Worlds Online Lawyer Management System admin_user.php sql injection
- CVE-2025-31711 PoCProject Worlds Online Lawyer Management System approve_lawyer.php sql injection
- CVE-2025-31721 PoCProject Worlds Online Lawyer Management System lawyer_booking.php sql injection
- CVE-2025-31731 PoCProject Worlds Online Lawyer Management System save_booking.php sql injection
- CVE-2025-31741 PoCProject Worlds Online Lawyer Management System searchLawyer.php sql injection
- CVE-2025-31751 PoCProject Worlds Online Lawyer Management System save_user_edit_profile.php sql injection
- CVE-2025-31761 PoCProject Worlds Online Lawyer Management System single_lawyer.php sql injection
- CVE-2025-31771 PoCFastCMS JWT hard-coded key
- CVE-2025-31781 PoCprojectworlds Online Doctor Appointment Booking System deleteappointment.php sql injection
- CVE-2025-31791 PoCprojectworlds Online Doctor Appointment Booking System deletepatient.php sql injection
- CVE-2025-31801 PoCprojectworlds Online Doctor Appointment Booking System deleteschedule.php sql injection
- CVE-2025-31811 PoCprojectworlds Online Doctor Appointment Booking System appointment.php sql injection
- CVE-2025-31821 PoCprojectworlds Online Doctor Appointment Booking System getschedule.php sql injection
- CVE-2025-31831 PoCprojectworlds Online Doctor Appointment Booking System patientupdateprofile.php sql injection
- CVE-2025-31841 PoCprojectworlds Online Doctor Appointment Booking System profile.php sql injection
- CVE-2025-31851 PoCprojectworlds Online Doctor Appointment Booking System patientupdateprofile.php sql injection
- CVE-2025-31861 PoCprojectworlds Online Doctor Appointment Booking System invoice.php sql injection
- CVE-2025-31871 PoCPHPGurukul e-Diary Management System login.php sql injection
- CVE-2025-31881 PoCPHPGurukul e-Diary Management System add-notes.php sql injection
- CVE-2025-31931 PoCVersions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in the _merge()…
- CVE-2025-31951 PoCitsourcecode Online Blood Bank Management System bbms.php sql injection
- CVE-2025-31961 PoCOpen Asset Import Library Assimp Malformed File MD2Loader.cpp InternReadFile stack-based overflow
- CVE-2025-31981 PoCGNU Binutils objdump bucomm.c display_info memory leak
- CVE-2025-31992 PoCsageerle ruoyi-ai API Interface SysModelController.java improper authorization
- CVE-2025-32011 PoCKali Forms < 2.4.3 - Contributor+ Stored XSS
- CVE-2025-32022 PoCsageerle ruoyi-ai SysNoticeController.java improper authorization
- CVE-2025-32031 PoCTenda W18E setModules formSetAccountList stack-based overflow
- CVE-2025-32041 PoCCodeAstro Car Rental System returncar.php sql injection
- CVE-2025-32051 PoCCodeAstro Student Grading System studentsubject.php sql injection
- CVE-2025-32061 PoCcode-projects Hospital Management System doctor-specilization.php sql injection
- CVE-2025-32071 PoCcode-projects Patient Record Management System birthing_form.php sql injection
- CVE-2025-32081 PoCcode-projects Patient Record Management System xray_print.php sql injection
- CVE-2025-32091 PoCcode-projects Patient Record Management System add_patient.php sql injection
- CVE-2025-32101 PoCcode-projects Patient Record Management System birthing_pending.php sql injection
- CVE-2025-32111 PoCcode-projects Patient Record Management System birthing_print.php sql injection
- CVE-2025-32131 PoCPHPGurukul e-Diary Management System view-note.php sql injection
- CVE-2025-32141 PoCJFinal CMS readTemplate engine.getTemplate path traversal
- CVE-2025-32151 PoCPHPGurukul Restaurant Table Booking System add-subadmin.php sql injection
- CVE-2025-32161 PoCPHPGurukul e-Diary Management System password-recovery.php sql injection
- CVE-2025-32171 PoCPHPGurukul e-Diary Management System registration.php sql injection
- CVE-2025-32191 PoCCodeCanyon Perfex CRM Project Discussions Module 2 cross site scripting
- CVE-2025-32201 PoCPHPGurukul e-Diary Management System dashboard.php sql injection
- CVE-2025-32291 PoCPHPGurukul Restaurant Table Booking System edit-subadmin.php sql injection
- CVE-2025-32311 PoCPHPGurukul Zoo Management System aboutus.php sql injection
- CVE-2025-32351 PoCPHPGurukul Old Age Home Management System profile.php sql injection
- CVE-2025-32361 PoCTenda FH1202 Web Management Interface VirSerDMZ access control
- CVE-2025-32371 PoCTenda FH1202 wrlwpsset access control
- CVE-2025-32381 PoCPHPGurukul Online Fire Reporting System search-request.php sql injection
- CVE-2025-32391 PoCPHPGurukul Online Fire Reporting System edit-guard-detail.php sql injection
- CVE-2025-32401 PoCPHPGurukul Online Fire Reporting System search.php sql injection
- CVE-2025-32411 PoCzhangyanbo2007 youkefu XML Document CallCenterRouterController.java xml external entity reference
- CVE-2025-32421 PoCPHPGurukul e-Diary Management System search-result.php sql injection
- CVE-2025-32433 PoCscode-projects Patient Record Management System dental_form.php sql injection
- CVE-2025-32441 PoCSourceCodester Web-based Pharmacy Product Management System Create User Page add-admin.php unrestricted upload
- CVE-2025-32451 PoCitsourcecode Library Management System Forgot.java search sql injection
- CVE-2025-324837 PoCsKEVLangflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/code
- CVE-2025-32491 PoCTOTOLINK A6000R mtkwifi.lua apcli_cancel_wps command injection
- CVE-2025-32501 PoCelunez eladmin Maintenance Management Module testConnect deserialization
- CVE-2025-32511 PoCxujiangfei admintwo updateSet cross site scripting
- CVE-2025-32521 PoCxujiangfei admintwo add cross site scripting
- CVE-2025-32531 PoCxujiangfei admintwo insertTree cross site scripting
- CVE-2025-32541 PoCxujiangfei admintwo add server-side request forgery
- CVE-2025-32551 PoCxujiangfei admintwo home access control
- CVE-2025-32561 PoCxujiangfei admintwo updateSet access control
- CVE-2025-32571 PoCxujiangfei admintwo updateSet cross-site request forgery
- CVE-2025-32581 PoCPHPGurukul Old Age Home Management System search.php sql injection
- CVE-2025-32592 PoCsTenda RX3 SetOnlineDevName formSetDeviceName stack-based overflow
- CVE-2025-32651 PoCPHPGurukul e-Diary Management System add-category.php sql injection
- CVE-2025-32661 PoCqinguoyi TinyWebServer http_conn.cpp stack-based overflow
- CVE-2025-32671 PoCqinguoyi TinyWebServer http_conn.cpp sql injection
- CVE-2025-32681 PoCqinguoyi TinyWebServer http_conn.cpp improper authentication
- CVE-2025-32791 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-32961 PoCSourceCodester Online Eyewear Shop Users.php sql injection
- CVE-2025-32971 PoCSourceCodester Online Eyewear Shop Master.php cross site scripting
- CVE-2025-32981 PoCSourceCodester Online Eyewear Shop Registration Master.php access control
- CVE-2025-32991 PoCPHPGurukul Men Salon Management System appointment.php sql injection
- CVE-2025-33031 PoCcode-projects Patient Record Management System birthing_record.php sql injection
- CVE-2025-33041 PoCcode-projects Patient Record Management System dental_not.php sql injection
- CVE-2025-33051 PoC1902756969/code-projects IKUN_Library Borrow MvcConfig.java addInterceptors access control
- CVE-2025-33061 PoCcode-projects Blood Bank Management System don.php sql injection
- CVE-2025-33071 PoCcode-projects Blood Bank Management System reset.php sql injection
- CVE-2025-33081 PoCcode-projects Blood Bank Management System viewrequest.php sql injection
- CVE-2025-33091 PoCcode-projects Blood Bank Management System campsdetails.php sql injection
- CVE-2025-33101 PoCcode-projects Blood Bank Management System delete.php sql injection
- CVE-2025-33111 PoCPHPGurukul Men Salon Management System about-us.php sql injection
- CVE-2025-33121 PoCPHPGurukul Men Salon Management System add-customer-services.php sql injection
- CVE-2025-33131 PoCPHPGurukul Men Salon Management System add-customer.php sql injection
- CVE-2025-33141 PoCSourceCodester Apartment Visitor Management System forgotpw.php sql injection
- CVE-2025-33151 PoCSourceCodester Apartment Visitor Management System view-report.php sql injection
- CVE-2025-33161 PoCPHPGurukul Men Salon Management System search-invoices.php sql injection
- CVE-2025-33171 PoCfumiao opencms dataPage.jsp path traversal
- CVE-2025-33181 PoCKenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 ShangpinleixingController.java page sql injection
- CVE-2025-33231 PoCgodcheese/code-projects Nimrod ViewMenuCategoryRestController.java searchAllByName sql injection
- CVE-2025-33241 PoCgodcheese/code-projects Nimrod FileRestController.java unrestricted upload
- CVE-2025-33251 PoCiteaj iboot 物联网网关 Admin Password pwd access control
- CVE-2025-33261 PoCiteaj iboot 物联网网关 File Upload upload cross site scripting
- CVE-2025-33271 PoCiteaj iboot 物联网网关 File Upload batch cross site scripting
- CVE-2025-33281 PoCTenda AC1206 fast_setting_wifi_set form_fast_setting_wifi_set buffer overflow
- CVE-2025-33291 PoCConsumer Comanda Mobile Restaurant Order cleartext transmission
- CVE-2025-33301 PoCcodeprojects Online Restaurant Management System reservation_save.php sql injection
- CVE-2025-33311 PoCcodeprojects Online Restaurant Management System payment_save.php sql injection
- CVE-2025-33321 PoCcodeprojects Online Restaurant Management System menu_save.php sql injection
- CVE-2025-33331 PoCcodeprojects Online Restaurant Management System menu_update.php sql injection
- CVE-2025-33341 PoCcodeprojects Online Restaurant Management System category_save.php sql injection
- CVE-2025-33351 PoCcodeprojects Online Restaurant Management System category_update.php sql injection
- CVE-2025-33361 PoCcodeprojects Online Restaurant Management System member_save.php sql injection
- CVE-2025-33371 PoCcodeprojects Online Restaurant Management System member_update.php sql injection
- CVE-2025-33381 PoCcodeprojects Online Restaurant Management System user_save.php sql injection
- CVE-2025-33391 PoCcodeprojects Online Restaurant Management System user_update.php sql injection
- CVE-2025-33401 PoCcodeprojects Online Restaurant Management System combo_update.php sql injection
- CVE-2025-33411 PoCcodeprojects Online Restaurant Management System reservation_view.php sql injection
- CVE-2025-33421 PoCcodeprojects Online Restaurant Management System payment_save.php sql injection
- CVE-2025-33431 PoCcodeprojects Online Restaurant Management System reservation_update.php sql injection
- CVE-2025-33441 PoCcodeprojects Online Restaurant Management System assign_save.php sql injection
- CVE-2025-33451 PoCcodeprojects Online Restaurant Management System combo.php sql injection
- CVE-2025-33461 PoCTenda AC7 SetPptpServerCfg formSetPPTPServer buffer overflow
- CVE-2025-33471 PoCcode-projects Patient Record Management System dental_pending.php sql injection
- CVE-2025-33481 PoCcode-projects Patient Record Management System edit_dpatient.php sql injection
- CVE-2025-33491 PoCPCMan FTP Server SYST Command buffer overflow
- CVE-2025-33501 PoCPHPGurukul Old Age Home Management System view-enquiry.php sql injection
- CVE-2025-33511 PoCPHPGurukul Old Age Home Management System login.php sql injection
- CVE-2025-33521 PoCPHPGurukul Old Age Home Management System edit-scdetails.php sql injection
- CVE-2025-33531 PoCPHPGurukul Men Salon Management System add-services.php sql injection
- CVE-2025-33691 PoCxxyopen Novel-Plus list sql injection
- CVE-2025-33701 PoCPHPGurukul Men Salon Management System admin-profile.php sql injection
- CVE-2025-33711 PoCPCMan FTP Server DELETE Command buffer overflow
- CVE-2025-33721 PoCPCMan FTP Server MKDIR Command buffer overflow
- CVE-2025-33731 PoCPCMan FTP Server SITE CHMOD Command buffer overflow
- CVE-2025-33741 PoCPCMan FTP Server CCC Command buffer overflow
- CVE-2025-33751 PoCPCMan FTP Server CDUP Command buffer overflow
- CVE-2025-33761 PoCPCMan FTP Server CONF Command buffer overflow
- CVE-2025-33771 PoCPCMan FTP Server ENC Command buffer overflow
- CVE-2025-33781 PoCPCMan FTP Server EPRT Command buffer overflow
- CVE-2025-33791 PoCPCMan FTP Server EPSV Command buffer overflow
- CVE-2025-33801 PoCPCMan FTP Server FEAT Command buffer overflow
- CVE-2025-33811 PoCzhangyanbo2007 youkefu File Upload WebIMController.java path traversal
- CVE-2025-33821 PoCjoey-zhou xiaozhi-esp32-server-java update sql injection
- CVE-2025-33831 PoCSourceCodester Web-based Pharmacy Product Management System search_sales.php sql injection
- CVE-2025-33841 PoC1000 Projects Human Resource Management System employee.php sql injection
- CVE-2025-33851 PoCLinZhaoguan pb-cms Classification Management Page cross site scripting
- CVE-2025-33861 PoCLinZhaoguan pb-cms Friendship Link admin#links cross site scripting
- CVE-2025-33871 PoCrenrenio renren-security JSON cross site scripting
- CVE-2025-33881 PoChailey888 oa_system Frontend LoginsController.java loginCheck cross site scripting
- CVE-2025-33891 PoChailey888 oa_system Backend InformManageController.java testMess cross site scripting
- CVE-2025-33901 PoChailey888 oa_system Backend DaymanageController.java addandchangeday cross site scripting
- CVE-2025-33911 PoChailey888 oa_system Backend AddrController. java outAddress cross site scripting
- CVE-2025-33921 PoChailey888 oa_system Backend MailController.java save cross site scripting
- CVE-2025-33931 PoCmrcen springboot-ucan-admin Personal Settings Interface index cross site scripting
- CVE-2025-33961 PoCIncorrect Authorization in GitLab
- CVE-2025-33971 PoCYzmCMS message.tpl cross site scripting
- CVE-2025-33981 PoClenve VBlog WebSecurityConfig.java configure access control
- CVE-2025-33991 PoCESAFENET CDG updateNotice.jsp sql injection
- CVE-2025-34001 PoCESAFENET CDG UnChkMailApplication.jsp sql injection
- CVE-2025-34011 PoCESAFENET CDG getLimitIPList.jsp sql injection
- CVE-2025-34021 PoCSeeyon Zhiyuan Interconnect FE Collaborative Office Platform check.js%70 sql injection
- CVE-2025-34031 PoCVivotek NVR ND8422P/NVR ND9525P/NVR ND9541P HTML Form sensitive information in source
- CVE-2025-34051 PoCFCJ Venture Builder appclientefiel HTTP GET Request ObterPedido resource injection
- CVE-2025-34101 PoCmymagicpower AIAS LocalStorageController.java unrestricted upload
- CVE-2025-34111 PoCmymagicpower AIAS AsrController.java server-side request forgery
- CVE-2025-34121 PoCmymagicpower AIAS InferController.java server-side request forgery
- CVE-2025-34131 PoCopplus springboot-admin SysGeneratorController.java code deserialization
- CVE-2025-34141 PoCStructured Content < 1.7.0 - Contributor Stored XSS
- CVE-2025-34151 PoCGrafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected…
- CVE-2025-34191 PoCEvent Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.26 - Unauthenticated Arbitrary File Read
- CVE-2025-34641 PoCA race condition vulnerability exists in Armoury Crate. This vulnerability arises from a Time-of-check Time-of-use issue, potentially…
- CVE-2025-34711 PoCSureForms < 1.4.4 - Contributor+ Settings Update
- CVE-2025-34721 PoCOcean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution
- CVE-2025-34891 PoCNababur Simple-User-Management-System register.php cross site scripting
- CVE-2025-35001 PoCInteger Overflow in Avast Antiviurs 25.1.981.6 on Windows may result in privilege escalation
- CVE-2025-35021 PoCWP Maps < 4.7.2 - Admin+ Stored XSS
- CVE-2025-35031 PoCWP Maps < 4.7.2 - Admin+ Stored XSS
- CVE-2025-35041 PoCWP Maps < 4.7.2 - Admin+ Stored XSS
- CVE-2025-35131 PoCSureForms < 1.4.4 - Admin+ Stored XSS
- CVE-2025-35141 PoCSureForms < 1.4.4 - Admin+ Stored XSS
- CVE-2025-35154 PoCsDrag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.9 - Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks
- CVE-2025-35161 PoCSimple Lightbox < 2.9.4 - Contributor+ Stored XSS
- CVE-2025-35251 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-35311 PoCYouDianCMS index.html cross site scripting
- CVE-2025-35321 PoCYouDianCMS index.html.Attackers cross site scripting
- CVE-2025-35331 PoCYouDianCMS index.html.Attackers cross site scripting
- CVE-2025-35341 PoCPowerCreator CMS OpenPublicCourse.aspx sql injection
- CVE-2025-35351 PoCshuanx BurpAPIFinder BurpApiFinder.db denial of service
- CVE-2025-35361 PoCTutorials-Website Employee Management System delete-user.php improper authorization
- CVE-2025-35371 PoCTutorials-Website Employee Management System update-user.php improper authorization
- CVE-2025-35381 PoCD-Link DI-8100 jhttpd auth.asp auth_asp stack-based overflow
- CVE-2025-35391 PoCH3C Magic BE18000 HTTP POST Request getBasicInfo FCGI_CheckStringIfContainsSemicolon command injection
- CVE-2025-35401 PoCH3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request getCapability FCGI_WizardProtoProcess command injection
- CVE-2025-35411 PoCH3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request getSpecs FCGI_WizardProtoProcess command injection
- CVE-2025-35421 PoCH3C Magic NX15/Magic NX400/Magic R3010 HTTP POST Request getsyncpppoecfg FCGI_WizardProtoProcess command injection
- CVE-2025-35431 PoCH3C Magic NX15/Magic NX30 Pro/Magic NX400/Magic R3010 HTTP POST Request setsyncpppoecfg FCGI_WizardProtoProcess command injection
- CVE-2025-35441 PoCH3C Magic BE18000 HTTP POST Request getCapabilityWeb FCGI_CheckStringIfContainsSemicolon command injection
- CVE-2025-35451 PoCH3C Magic BE18000 HTTP POST Request setLanguage FCGI_CheckStringIfContainsSemicolon command injection
- CVE-2025-35461 PoCH3C Magic BE18000 HTTP POST Request getLanguage FCGI_CheckStringIfContainsSemicolon command injection
- CVE-2025-35482 PoCsOpen Asset Import Library Assimp File types.h Set heap-based overflow
- CVE-2025-35492 PoCsOpen Asset Import Library Assimp File MD3Loader.cpp ValidateSurfaceHeaderOffsets heap-based overflow
- CVE-2025-35501 PoCwowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System detail improper authorization
- CVE-2025-35531 PoCphpshe admin.php pe_delete sql injection
- CVE-2025-35541 PoCphpshe api.php cross site scripting
- CVE-2025-35551 PoCScriptAndTools eCommerce-website-in-PHP login.php excessive authentication
- CVE-2025-35561 PoCScriptAndTools eCommerce-website-in-PHP login.php excessive authentication
- CVE-2025-35571 PoCScriptAndTools eCommerce-website-in-PHP cross-site request forgery
- CVE-2025-35581 PoCghostxbh uzy-ssm-mall uploadUserHeadImage unrestricted upload
- CVE-2025-35591 PoCghostxbh uzy-ssm-mall 20 ForeProductListController sql injection
- CVE-2025-35601 PoCghostxbh uzy-ssm-mall product cross site scripting
- CVE-2025-35611 PoCghostxbh uzy-ssm-mall cross-site request forgery
- CVE-2025-35621 PoCYonyou YonBIP userfile FileInputStream path traversal
- CVE-2025-35631 PoCWuzhiCMS Setting index.php set code injection
- CVE-2025-35641 PoChuanfenz/code-projects StudentManager Teacher String improper authorization
- CVE-2025-35651 PoChuanfenz/code-projects StudentManager Announcement Management Section uploadArticle.do unrestricted upload
- CVE-2025-35661 PoCveal98 小牛肉 Echo 开源社区系统 uploadMdPic unrestricted upload
- CVE-2025-35671 PoCveal98 小牛肉 Echo 开源社区系统 Ticket LoginTicketInterceptor.java preHandle improper authorization
- CVE-2025-35683 PoCsWebkul Krayin CRM SVG File edit cross site scripting
- CVE-2025-35691 PoCJamesZBL/code-projects db-hospital-drug ShiroConfig.java improper authorization
- CVE-2025-35701 PoCJamesZBL/code-projects db-hospital-drug ContentController.java save cross site scripting
- CVE-2025-35711 PoCFannuo Enterprise Content Management System 凡诺企业网站管理系统 cms_chip.php sql injection
- CVE-2025-35771 PoC**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version…
- CVE-2025-35811 PoCNewsletter < 8.8.5 - Admin+ Stored XSS via Widget
- CVE-2025-35821 PoCNewsletter < 8.8.5 - Admin+ Stored XSS via Form
- CVE-2025-35831 PoCNewsletter < 8.7.1 - Admin+ Stored XSS
- CVE-2025-35841 PoCNewsletter < 8.8.2 - Admin+ Stored XSS via Subscription
- CVE-2025-35851 PoCwestboy CicadasCMS JSP Parser upload unrestricted upload
- CVE-2025-35871 PoCZeroWdd/code-projects studentmanager getTeacherList improper authorization
- CVE-2025-35881 PoCjoelittlejohn jsonschema2pojo JSON File SchemaRule.java apply stack-based overflow
- CVE-2025-35891 PoCSourceCodester Music Class Enrollment System manage_class.php sql injection
- CVE-2025-35901 PoCAdianti Framework deserialization
- CVE-2025-35911 PoCZHENFENG13/code-projects My-Blog-layui edit cross site scripting
- CVE-2025-35921 PoCZHENFENG13/code-projects My-Blog-layui edit cross site scripting
- CVE-2025-35931 PoCZHENFENG13/code-projects My-Blog-layui authorImg upload unrestricted upload
- CVE-2025-35971 PoCFirelight Lightbox < 2.3.15 - Contributor+ Stored XSS
- CVE-2025-36011 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-36041 PoCFlynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover
- CVE-2025-36053 PoCsFrontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
- CVE-2025-36121 PoCDemtec Graphytics HTTP GET Parameter visualization cross site scripting
- CVE-2025-36131 PoCDemtec Graphytics visualization cross site scripting
- CVE-2025-36161 PoCGreenshift 11.4 - 11.4.5 - Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2025-36391 PoCLiferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through…
- CVE-2025-36491 PoCLightPress Lightbox < 2.3.4 - Contributor+ Stored XSS
- CVE-2025-36501 PoCjQuery Colorbox <= 4.6.3 - Contributor+ Stored XSS
- CVE-2025-36621 PoCFancyBox for WordPress < 3.3.6 - Unauthenticated Stored XSS
- CVE-2025-36631 PoCTOTOLINK A3700R Password cstecgi.cgi setWiFiEasyGuestCfg access control
- CVE-2025-36641 PoCTOTOLINK A3700R cstecgi.cgi setWiFiEasyGuestCfg access control
- CVE-2025-36651 PoCTOTOLINK A3700R cstecgi.cgi setSmartQosCfg access control
- CVE-2025-36661 PoCTOTOLINK A3700R cstecgi.cgi setDdnsCfg access control
- CVE-2025-36671 PoCTOTOLINK A3700R cstecgi.cgi setUPnPCfg access control
- CVE-2025-36681 PoCTOTOLINK A3700R cstecgi.cgi setScheduleCfg access control
- CVE-2025-36741 PoCTOTOLINK A3700R cstecgi.cgi setUrlFilterRules access control
- CVE-2025-36751 PoCTOTOLINK A3700R cstecgi.cgi setL2tpServerCfg access control
- CVE-2025-36761 PoCxxyopen Novel-Plus books sql injection
- CVE-2025-36781 PoCPCMan FTP Server HELP Command buffer overflow
- CVE-2025-36791 PoCPCMan FTP Server HOST Command buffer overflow
- CVE-2025-36801 PoCPCMan FTP Server LANG Command buffer overflow
- CVE-2025-36811 PoCPCMan FTP Server MODE Command buffer overflow
- CVE-2025-36821 PoCPCMan FTP Server PASV Command buffer overflow
- CVE-2025-36831 PoCPCMan FTP Server SIZE Command buffer overflow
- CVE-2025-36841 PoCXianqi Kindergarten Management System Child Management stu_list.php sql injection
- CVE-2025-36851 PoCcode-projects Patient Record Management System edit_fpatient.php sql injection
- CVE-2025-36861 PoCmisstt123 oasys show image path traversal
- CVE-2025-36871 PoCmisstt123 oasys Sticky Notes cross-site request forgery
- CVE-2025-36881 PoCmirweiye Seven Bears Library CMS Background Management Page cross site scripting
- CVE-2025-36891 PoCPHPGurukul Men Salon Management System edit-customer-detailed.php sql injection
- CVE-2025-36901 PoCPHPGurukul Men Salon Management System edit-services.php sql injection
- CVE-2025-36911 PoCmirweiye Seven Bears Library CMS Add Link server-side request forgery
- CVE-2025-36921 PoCSourceCodester Online Eyewear Shop Master.php cross site scripting
- CVE-2025-36931 PoCTenda W12 httpd cgiWifiRadioSet stack-based overflow
- CVE-2025-36941 PoCSourceCodester Web-based Pharmacy Product Management System Login sql injection
- CVE-2025-36961 PoCSourceCodester Web-based Pharmacy Product Management System search_stock. php sql injection
- CVE-2025-36971 PoCSourceCodester Web-based Pharmacy Product Management System edit-product.php sql injection
- CVE-2025-37231 PoCPCMan FTP Server MDTM Command buffer overflow
- CVE-2025-37241 PoCPCMan FTP Server DIR Command buffer overflow
- CVE-2025-37251 PoCPCMan FTP Server MIC Command buffer overflow
- CVE-2025-37261 PoCPCMan FTP Server CD Command buffer overflow
- CVE-2025-37271 PoCPCMan FTP Server STATUS Command buffer overflow
- CVE-2025-37281 PoCSourceCodester Simple Hotel Booking System login buffer overflow
- CVE-2025-37291 PoCSourceCodester Web-based Pharmacy Product Management System Database Backup backup.php os command injection
- CVE-2025-37301 PoCPyTorch LossCTC.cpp torch.nn.functional.ctc_loss denial of service
- CVE-2025-37421 PoCResponsive Lightbox & Gallery < 2.5.1 - Contributor+ Stored XSS
- CVE-2025-37451 PoCWP Lightbox 2 < 3.0.6.8 - Unauthenticated Stored XSS
- CVE-2025-37621 PoCPCMan FTP Server MPUT Command buffer overflow
- CVE-2025-37631 PoCSourceCodester Phone Management System Password main buffer overflow
- CVE-2025-37641 PoCSourceCodester Web-based Pharmacy Product Management System edit-product.php unrestricted upload
- CVE-2025-37651 PoCSourceCodester Web-based Pharmacy Product Management System edit-photo.php unrestricted upload
- CVE-2025-37761 PoCVerification SMS with TargetSMS <= 1.5 - Unauthenticated Limited Remote Code Execution
- CVE-2025-37831 PoCSourceCodester Web-based Pharmacy Product Management System add-product.php unrestricted upload
- CVE-2025-37851 PoCD-Link DWR-M961 Authorization Interface formStaticDHCP stack-based overflow
- CVE-2025-37861 PoCTenda AC15 WifiExtraSet fromSetWirelessRepeat buffer overflow
- CVE-2025-37871 PoCPbootCMS Image server-side request forgery
- CVE-2025-37881 PoCbaseweb JSite save cross site scripting
- CVE-2025-37891 PoCbaseweb JSite save cross site scripting
- CVE-2025-37901 PoCbaseweb JSite Apache Druid Monitoring Console index.html access control
- CVE-2025-37911 PoCsymisc UnQLite unqlite.c jx9MemObjStore heap-based overflow
- CVE-2025-37921 PoCSeaCMS admin_link.php sql injection
- CVE-2025-37951 PoCDaiCuo SEO Optimization Settings Section cross site scripting
- CVE-2025-37961 PoCPHPGurukul Men Salon Management System contact-us.php sql injection
- CVE-2025-37971 PoCSeaCMS admin_topic.php sql injection
- CVE-2025-37981 PoCWCMS Advertisement Image AdvadminController.php sub unrestricted upload
- CVE-2025-37991 PoCWCMS AnonymousController.php sql injection
- CVE-2025-38001 PoCWCMS AnonymousController.php sql injection
- CVE-2025-38011 PoCsongquanpeng one-api System Setting cross site scripting
- CVE-2025-38021 PoCTenda W12/i24 httpd cgiPingSet stack-based overflow
- CVE-2025-38031 PoCTenda W12/i24 httpd cgiSysScheduleRebootSet stack-based overflow
- CVE-2025-38041 PoCthautwarm vscode-diana Jinja2 Template Gen.py injection
- CVE-2025-38051 PoCsarrionandia tournatrack Jinja2 Template check_id.py injection
- CVE-2025-38061 PoCdazhouda lecms Edit Profile admin cross site scripting
- CVE-2025-38071 PoCzhenfeng13 My-BBS Endpoint UploadController.java upload unrestricted upload
- CVE-2025-38081 PoCzhenfeng13 My-BBS cross-site request forgery
- CVE-2025-38161 PoCwestboy CicadasCMS Scheduled Task save os command injection
- CVE-2025-38171 PoCSourceCodester Online Eyewear Shop Master.php sql injection
- CVE-2025-38181 PoCwebpy web.py db.py PostgresDB._process_insert_query sql injection
- CVE-2025-38191 PoCPHPGurukul Men Salon Management System search-appointment.php sql injection
- CVE-2025-38201 PoCTenda W12/i24 httpd cgiSysUplinkCheckSet stack-based overflow
- CVE-2025-38211 PoCSourceCodester Web-based Pharmacy Product Management System add-admin.php cross site scripting
- CVE-2025-38221 PoCSourceCodester Web-based Pharmacy Product Management System changepassword.php cross site scripting
- CVE-2025-38231 PoCSourceCodester Web-based Pharmacy Product Management System add-stock.php cross site scripting
- CVE-2025-38241 PoCSourceCodester Web-based Pharmacy Product Management System add-product.php cross site scripting
- CVE-2025-38251 PoCSourceCodester Web-based Pharmacy Product Management System add-category.php cross site scripting
- CVE-2025-38261 PoCSourceCodester Web-based Pharmacy Product Management System add-supplier.php cross site scripting
- CVE-2025-38271 PoCPHPGurukul Men Salon Management System forgot-password.php sql injection
- CVE-2025-38281 PoCPHPGurukul Men Salon Management System view-appointment.php sql injection
- CVE-2025-38291 PoCPHPGurukul Men Salon Management System sales-reports-detail.php sql injection
- CVE-2025-38301 PoCkuangstudy KuangSimpleBBS QuestionController.java fileUpload unrestricted upload
- CVE-2025-38411 PoCwix-incubator jam Jinja2 Template jam.py special elements used in a template engine
- CVE-2025-38421 PoCpanhainan DS-Java FileUpload.java uploadUserPic.action code injection
- CVE-2025-38431 PoCpanhainan DS-Java cross-site request forgery
- CVE-2025-38451 PoCmarkparticle WebServer buffer.cpp HasWritten buffer overflow
- CVE-2025-38461 PoCmarkparticle WebServer Registration httprequest.cpp sql injection
- CVE-2025-38471 PoCmarkparticle WebServer Login httprequest.cpp sql injection
- CVE-2025-38491 PoCYXJ2018 SpringBoot-Vue-OnlineExam studentPWD unverified password change
- CVE-2025-38501 PoCYXJ2018 SpringBoot-Vue-OnlineExam API improper authentication
- CVE-2025-38541 PoCH3C GR-3000AX HTTP POST Request aspForm Edit_List_SSID buffer overflow
- CVE-2025-38551 PoCCodeCanyon RISE Ultimate Project Manager Profile Picture save_profile_image resource injection
- CVE-2025-38561 PoCxxyopen Novel-Plus searchByPage sql injection
- CVE-2025-39141 PoCAeropage Sync for Airtable <= 3.2.0 - Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2025-39151 PoCAeropage Sync for Airtable <= 3.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion
- CVE-2025-39221 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-39501 PoCExposure of Private Personal Information to an Unauthorized Actor in GitLab
- CVE-2025-39511 PoCWP-Optimize < 4.2.0 - Admin+ SQLi
- CVE-2025-39541 PoCChurchCRM Referer server-side request forgery
- CVE-2025-39551 PoCcodeprojects Patient Record Management System edit_rpatient.php.php sql injection
- CVE-2025-39561 PoC201206030 novel-cloud BookInfoMapper.xml RestResp sql injection
- CVE-2025-39571 PoCopplus springboot-admin SysLogDao.xml sql injection
- CVE-2025-39581 PoCwithstars Books-Management-System Book Edit Page book_edit_do.html cross site scripting
- CVE-2025-39591 PoCwithstars Books-Management-System reader_delete.html cross-site request forgery
- CVE-2025-39601 PoCwithstars Books-Management-System Background Interface allreaders.html authorization
- CVE-2025-39611 PoCwithstars Books-Management-System do cross site scripting
- CVE-2025-39621 PoCwithstars Books-Management-System Comment add cross site scripting
- CVE-2025-39631 PoCwithstars Books-Management-System Background Interface list authorization
- CVE-2025-39641 PoCwithstars Books-Management-System Article del cross-site request forgery
- CVE-2025-39651 PoCitwanger paicoding post cross site scripting
- CVE-2025-39661 PoCitwanger paicoding Browsing History home information disclosure
- CVE-2025-39671 PoCitwanger paicoding Article post improper authorization
- CVE-2025-39681 PoCcodeprojects News Publishing Site Dashboard api.php sql injection
- CVE-2025-39692 PoCscodeprojects News Publishing Site Dashboard Edit Category Page edit-category.php unrestricted upload
- CVE-2025-39701 PoCbaseweb JSite save cross site scripting
- CVE-2025-39711 PoCPHPGurukul COVID19 Testing Management System add-phlebotomist.php sql injection
- CVE-2025-39721 PoCPHPGurukul COVID19 Testing Management System bwdates-report-result.php sql injection
- CVE-2025-39731 PoCPHPGurukul COVID19 Testing Management System check_availability.php sql injection
- CVE-2025-39741 PoCPHPGurukul COVID19 Testing Management System edit-phlebotomist.php sql injection
- CVE-2025-39751 PoCScriptAndTools eCommerce-website-in-PHP subscriber-csv.php information disclosure
- CVE-2025-39761 PoCPHPGurukul COVID19 Testing Management System new-user-testing.php sql injection
- CVE-2025-39771 PoCiteachyou Dreamer CMS Attachment download improper authorization
- CVE-2025-39781 PoCdazhouda lecms user_set.htm information disclosure
- CVE-2025-39791 PoCdazhouda lecms Password Change index.php cross-site request forgery
- CVE-2025-39801 PoCwowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System list improper authorization
- CVE-2025-39811 PoCwowjoy 浙江湖州华卓信息科技有限公司 Internet Doctor Workstation System details improper authorization
- CVE-2025-39821 PoCnortikin Sverchok Set Property Mk2 Node getsetprop_mk2.py SvSetPropNodeMK2 prototype pollution
- CVE-2025-39831 PoCAMTT Hotel Broadband Operation System nlog_down.php command injection
- CVE-2025-39841 PoCApereo CAS Groovy Code RegisteredServiceSimpleFormController.java saveService code injection
- CVE-2025-39851 PoCApereo CAS ResponseEntity redos
- CVE-2025-39861 PoCApereo CAS CasConfigurationMetadataServerController.java redos
- CVE-2025-39871 PoCTOTOLINK N150RT formWsc command injection
- CVE-2025-39881 PoCTOTOLINK N150RT formPortFw buffer overflow
- CVE-2025-39891 PoCTOTOLINK N150RT formStaticDHCP buffer overflow
- CVE-2025-39901 PoCTOTOLINK N150RT formVlan buffer overflow
- CVE-2025-39911 PoCTOTOLINK N150RT formWdsEncrypt buffer overflow
- CVE-2025-39921 PoCTOTOLINK N150RT formWlwds buffer overflow
- CVE-2025-39931 PoCTOTOLINK N150RT formWsc buffer overflow
- CVE-2025-39941 PoCTOTOLINK N150RT IP Port Filtering home.htm cross site scripting
- CVE-2025-39951 PoCTOTOLINK N150RT LAN Settings Page fromStaticDHCP cross site scripting
- CVE-2025-39961 PoCTOTOLINK N150RT MAC Filtering Page home.htm cross site scripting
- CVE-2025-39971 PoCdazhouda lecms Personal Information Page index.php cross-site request forgery
- CVE-2025-39981 PoCCodeAstro Membership Management System renew.php sql injection
- CVE-2025-39991 PoCSeeyon Zhiyuan OA Web Application System URL Parameter date.jsp cross site scripting