CVE-2025-46000 to CVE-2025-46999
87 CVEs with public proof-of-concept exploits.
- CVE-2025-460001 PoCAn arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows…
- CVE-2025-460012 PoCsAn arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary…
- CVE-2025-460022 PoCsAn issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the…
- CVE-2025-460141 PoCSeveral services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe…
- CVE-2025-460181 PoCCSC Pay Mobile App 2.19.4 (fixed in version 2.20.0) contains a vulnerability allowing users to bypass payment authorization by disabling…
- CVE-2025-460351 PoCBuffer Overflow vulnerability in Tenda AC6 v.15.03.05.16 allows a remote attacker to cause a denial of service via the oversized…
- CVE-2025-460412 PoCsA stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page…
- CVE-2025-460472 PoCsA User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers…
- CVE-2025-460601 PoCBuffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the…
- CVE-2025-460781 PoCHuoCMS V3.5.1 and before is vulnerable to file upload, which allows attackers to take control of the target server
- CVE-2025-460801 PoCHuoCMS V3.5.1 has a File Upload Vulnerability. An attacker can exploit this flaw to bypass whitelist restrictions and craft malicious…
- CVE-2025-460931 PoCLiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code…
- CVE-2025-460941 PoCLiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.
- CVE-2025-460961 PoCDirectory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component
- CVE-2025-461091 PoCSQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET…
- CVE-2025-461161 PoCAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to…
- CVE-2025-461171 PoCAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to…
- CVE-2025-461181 PoCAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139 and in Ruckus ZoneDirector prior to…
- CVE-2025-461191 PoCAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to…
- CVE-2025-461201 PoCAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to…
- CVE-2025-461211 PoCAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions…
- CVE-2025-461221 PoCAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API…
- CVE-2025-461231 PoCAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to…
- CVE-2025-461571 PoCAn issue in EfroTech Time Trax v.1.0 allows a remote attacker to execute arbitrary code via the file attachment function in the leave…
- CVE-2025-461711 PoCvBulletin 3.8.7 is vulnerable to a denial-of-service condition via the misc.php?do=buddylist endpoint. If an authenticated user has a…
- CVE-2025-461731 PoCcode-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) via the name field in the feedback form.
- CVE-2025-461781 PoCCross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows…
- CVE-2025-461791 PoCA SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts…
- CVE-2025-461881 PoCSourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
- CVE-2025-461891 PoCSourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id…
- CVE-2025-462031 PoCAn issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /students/edit/{id} endpoint.
- CVE-2025-462041 PoCAn issue in Unifiedtransform v2.0 allows a remote attacker to escalate privileges via the /course/edit/{id} endpoint.
- CVE-2025-462711 PoCPlanet Technology Network Products OS Command Injection
- CVE-2025-463352 PoCsMobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload
- CVE-2025-463381 PoCAudiobookshelf Vulnerable to Cross-Site-Scripting Reflected via POST Request in /api/upload
- CVE-2025-463411 PoCPrivilege escalation via SSRF when using HTTP auth
- CVE-2025-463421 PoCKyverno vulnerable to bypass of policy rules that use namespace selectors in match statements
- CVE-2025-463461 PoCYesWiki Vulnerable to Stored XSS in Comments
- CVE-2025-463472 PoCsYesWiki Remote Code Execution via Arbitrary PHP File Write and Execution
- CVE-2025-463482 PoCsYesWiki Vulnerable to Unauthenticated Site Backup Creation and Download
- CVE-2025-463493 PoCsYesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
- CVE-2025-463501 PoCYeswiki Vulnerable to Authenticated Reflected Cross-site Scripting
- CVE-2025-463541 PoCA denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomberg Comdb2 8.1. A…
- CVE-2025-463591 PoCA path traversal issue exists in backup and restore feature of multiple versions of PowerCMS. A product administrator may execute…
- CVE-2025-464071 PoCA memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library v0.9.8. When…
- CVE-2025-464081 PoCAn issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and…
- CVE-2025-464111 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-464171 PoCThe unsafe globals in Picklescan before 0.0.25 do not include ssl. Consequently, ssl.get_server_certificate can exfiltrate data via DNS…
- CVE-2025-465492 PoCsYeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
- CVE-2025-465502 PoCsYeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
- CVE-2025-465512 PoCsJRuby-OpenSSL has hostname verification disabled by default
- CVE-2025-465541 PoCXWiki missing authorization when accessing the wiki level attachments list and metadata via REST API
- CVE-2025-465591 PoCMisskey Directory Traversal Vulnerability in AiScript via `Mk:api`
- CVE-2025-465602 PoCsvLLM phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
- CVE-2025-465654 PoCsVite's server.fs.deny bypassed with /. for files under project root
- CVE-2025-465672 PoCsLLaMA-Factory Allows Arbitrary Code Execution via Unsafe Deserialization in Ilamafy_baichuan2.py
- CVE-2025-465712 PoCsOpen WebUI vulnerable to limited stored XSS vila uploaded html file
- CVE-2025-466121 PoCThe Panel Designer dashboard in Airleader Master and Easy before 6.36 allows remote attackers to execute arbitrary commands via a…
- CVE-2025-466531 PoCFormidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable…
- CVE-2025-466542 PoCsCodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by…
- CVE-2025-466571 PoCKaraz Karazal through 2025-04-14 allows reflected XSS via the lang parameter to the default URI.
- CVE-2025-466731 PoCNASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space…
- CVE-2025-466891 PoCVerverica Platform 2.14.0 contain an Reflected XSS vulnerability via a namespaces/default/formats URI.
- CVE-2025-466901 PoCVerverica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.
- CVE-2025-467012 PoCsApache Tomcat: Security constraint bypass for CGI scripts
- CVE-2025-467131 PoCSandboxie has Pool Buffer Overflow in SbieDrv.sys API (API_SET_SECURE_PARAM)
- CVE-2025-467141 PoCSandboxie has Pool Buffer Overflow in SbieDrv.sys API (API_GET_SECURE_PARAM)
- CVE-2025-467151 PoCSandboxie Arbitrary Kernel Write in SbieDrv.sys API (API_GET_SECURE_PARAM)
- CVE-2025-467161 PoCSandboxie Arbitrary Kernel Read in SbieDrv.sys API (API_SET_SECURE_PARAM)
- CVE-2025-467172 PoCssudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible Folders
- CVE-2025-467182 PoCssudo-rs Allows Low Privilege Users to Enumerate Privileges of Others
- CVE-2025-467191 PoCOpen WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via…
- CVE-2025-467211 PoCnosurf vulnerable to CSRF due to non-functional same-origin request checks
- CVE-2025-467241 PoCLangroid has a Code Injection vulnerability in TableChatAgent
- CVE-2025-467262 PoCsLangroid Vulnerable to XXE Injection via XMLToolMessage
- CVE-2025-467281 PoCcpp-httplib has Unbounded Memory Allocation in Chunked/No-Length Requests
- CVE-2025-467301 PoCMobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
- CVE-2025-467311 PoCCraft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
- CVE-2025-468112 PoCsSUSE Multi Linux Manager allows code execution via unprotected websocket endpoint
- CVE-2025-468141 PoCFastAPI Guard Remote Header Injection via X-Forwarded-For Manipulation
- CVE-2025-468162 PoCsgoshs route not protected, allows command execution
- CVE-2025-468173 PoCsLua library commands may lead to integer overflow and potential RCE
- CVE-2025-468182 PoCsRedis: Authenticated users can execute LUA scripts as a different user
- CVE-2025-468192 PoCsRedis is vulnerable to DoS via specially crafted LUA scripts
- CVE-2025-468226 PoCsUnauthenticated Arbitrary File Read via Absolute Path
- CVE-2025-468251 PoCKanboard has stored Cross-site Scripting vulnerability in project name
- CVE-2025-468281 PoCUnauthenticated SQL Injection on get_socios.php endpoint