CVE-2025-45000 to CVE-2025-45999
55 CVEs with public proof-of-concept exploits.
- CVE-2025-450011 PoCreact-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as…
- CVE-2025-450551 PoCSilverpeas 6.4.2 contains a stored cross-site scripting (XSS) vulnerability in the event management module. An authenticated user can…
- CVE-2025-452502 PoCsMrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.
- CVE-2025-453131 PoCA cross-site scripting (XSS) vulnerability in the /tasks endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary JavaScript…
- CVE-2025-453141 PoCA cross-site scripting (XSS) vulnerability in the /Calendar endpoint of hortusfox-web v4.4 allows attackers to execute arbitrary…
- CVE-2025-453151 PoCA cross-site scripting (XSS) vulnerability in the /controller/admin.php endpoint of hortusfox-web v4.4 allows attackers to execute…
- CVE-2025-453171 PoCA zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a…
- CVE-2025-453431 PoCAn issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of the account module…
- CVE-2025-453461 PoCSQL Injection vulnerability in Bacula-web before v.9.7.1 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request.
- CVE-2025-454061 PoCA stored cross-site scripting (XSS) vulnerability in CodeIgniter4 v4.6.0 allows attackers to execute arbitrary web scripts or HTML via a…
- CVE-2025-454221 PoCIncorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary…
- CVE-2025-454241 PoCIncorrect access control in Xinference before v1.4.0 allows attackers to access the Web GUI without authentication.
- CVE-2025-454271 PoCIn Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow vulnerability,…
- CVE-2025-454281 PoCIn Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack overflow…
- CVE-2025-454291 PoCIn the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWpsStart, which may…
- CVE-2025-454661 PoCUnitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.
- CVE-2025-454671 PoCUnitree Go1 <= Go1_2022_05_11 is vulnerable to Insecure Permissions as the firmware update functionality (via Wi-Fi/Ethernet) implements…
- CVE-2025-455123 PoCsA lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install…
- CVE-2025-455422 PoCsSQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to…
- CVE-2025-455821 PoCGNU Tar through 1.35 allows file overwrite via directory traversal in crafted TAR archives, with a certain two-step process. First, the…
- CVE-2025-456191 PoCAn issue in Aver PTC310UV2 firmware v.0.1.0000.59 allows a remote attacker to execute arbitrary code via the SendAction function
- CVE-2025-456201 PoCAn issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request
- CVE-2025-456631 PoCAn issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure.
- CVE-2025-457311 PoCA group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is deleted while other…
- CVE-2025-457541 PoCA stored cross-site scripting (XSS) vulnerability exists in SeedDMS 6.0.32. This vulnerability allows an attacker to inject malicious…
- CVE-2025-457771 PoCAn issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via…
- CVE-2025-457781 PoCA stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary web…
- CVE-2025-457791 PoCTenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.
- CVE-2025-457861 PoCReal Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php.
- CVE-2025-458001 PoCTOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a command execution vulnerability in the setDeviceName interface of the…
- CVE-2025-458051 PoCIn phpgurukul Doctor Appointment Management System 1.0, an authenticated doctor user can inject arbitrary JavaScript code into their…
- CVE-2025-458092 PoCsBerriAI litellm v1.65.4 was discovered to contain a SQL injection vulnerability via the /key/block endpoint.
- CVE-2025-458131 PoCENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
- CVE-2025-458141 PoCMissing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows…
- CVE-2025-458351 PoCA null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function…
- CVE-2025-458461 PoCALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the…
- CVE-2025-458541 PoC/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
- CVE-2025-458571 PoCEDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.
- CVE-2025-458581 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc function.
- CVE-2025-458591 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice…
- CVE-2025-458621 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the interfacenameds parameter in the formDhcpv6s…
- CVE-2025-458631 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMapDelDevice…
- CVE-2025-458641 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s…
- CVE-2025-458661 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s…
- CVE-2025-458671 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup…
- CVE-2025-458851 PoCPHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject…
- CVE-2025-459311 PoCAn issue D-Link DIR-816-A2 DIR-816A2_FWv1.10CNB05_R1B011D88210 allows a remote attacker to execute arbitrary code via system() function in…
- CVE-2025-459471 PoCAn issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary code via the /obbs/change-password.php…
- CVE-2025-459491 PoCA critical vulnerability was found in PHPGurukul User Registration & Login and User Management System V3.3 in the…
- CVE-2025-459531 PoCA vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change-password.php file of the user panel - Change…
- CVE-2025-459561 PoCA SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated…
- CVE-2025-459601 PoCCross Site Scripting vulnerability in tawk.to Live Chat v.1.6.1 allows a remote attacker to execute arbitrary code via the web application…
- CVE-2025-459681 PoCAn issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application…
- CVE-2025-459851 PoCBlink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8,…
- CVE-2025-459971 PoCSourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file…