CVE-2025-43000 to CVE-2025-43999
22 CVEs with public proof-of-concept exploits.
- CVE-2025-433009 PoCsKEVAn out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12…
- CVE-2025-433561 PoCThe issue was addressed with improved handling of caches. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS…
- CVE-2025-435104 PoCsKEVA memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1…
- CVE-2025-435204 PoCsKEVA memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and…
- CVE-2025-435294 PoCsKEVA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3,…
- CVE-2025-435411 PoCA type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS…
- CVE-2025-435641 PoCColdFusion | Incorrect Authorization (CWE-863)
- CVE-2025-437081 PoCVisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap…
- CVE-2025-438531 PoCiwasm vulnerable to filesystem sandbox escape with symlink when using uvwasi feature
- CVE-2025-438551 PoCtRPC 11 WebSocket DoS Vulnerability
- CVE-2025-438581 PoCYoutubeDLSharp allows command injection on windows system due to non sanitized arguments
- CVE-2025-438601 PoCOpemEMR Vulnerable to Stored XSS Attack in the Additional Address Section of Patient Demographics
- CVE-2025-438621 PoCDify Allows Unauthorized Access and Modification of APP Orchestration
- CVE-2025-438642 PoCsReact Router allows a DoS via cache poisoning by forcing SPA mode
- CVE-2025-438651 PoCReact Router allows pre-render data spoofing on React-Router framework mode
- CVE-2025-439192 PoCsGNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal…
- CVE-2025-439201 PoCGNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to…
- CVE-2025-439211 PoCGNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint.…
- CVE-2025-439291 PoCopen_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked…
- CVE-2025-439461 PoCTCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).
- CVE-2025-439471 PoCCodemers KLIMS 1.6.DEV lacks a proper access control mechanism, allowing a normal KLIMS user to perform all the actions that an admin can…
- CVE-2025-439601 PoCAdminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized payload (e.g.,…