CVE-2025-47000 to CVE-2025-47999
47 CVEs with public proof-of-concept exploits.
- CVE-2025-471611 PoCMicrosoft Defender for Endpoint Elevation of Privilege Vulnerability
- CVE-2025-471651 PoCMicrosoft Excel Remote Code Execution Vulnerability
- CVE-2025-471661 PoCMicrosoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2025-471711 PoCMicrosoft Outlook Remote Code Execution Vulnerability
- CVE-2025-471752 PoCsMicrosoft PowerPoint Remote Code Execution Vulnerability
- CVE-2025-471761 PoCMicrosoft Outlook Remote Code Execution Vulnerability
- CVE-2025-471781 PoCMicrosoft Configuration Manager Remote Code Execution Vulnerability
- CVE-2025-471811 PoCMicrosoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
- CVE-2025-471881 PoCA vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference…
- CVE-2025-472041 PoCAn issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes…
- CVE-2025-472262 PoCsGrokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.
- CVE-2025-472272 PoCsIn the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), the Administrator password reset mechanism is…
- CVE-2025-472281 PoCIn the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connection settings allows…
- CVE-2025-472291 PoClibpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and…
- CVE-2025-472561 PoCLibxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module…
- CVE-2025-472682 PoCsping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply…
- CVE-2025-472735 PoCssetuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
- CVE-2025-472812 PoCsKyverno's Improper JMESPath Variable Evaluation Leads to Denial of Service
- CVE-2025-474231 PoCPersonal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to read arbitrary files via ../ directory traversal in…
- CVE-2025-474452 PoCsWordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
- CVE-2025-475331 PoCWordPress Graphina plugin <= 3.0.4 - Cross Site Request Forgery (CSRF) to Local File Inclusion vulnerability
- CVE-2025-475392 PoCsWordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
- CVE-2025-475491 PoCWordPress BEAF plugin <= 4.6.10 - Arbitrary File Upload Vulnerability
- CVE-2025-475501 PoCWordPress Instantio plugin <= 3.3.16 - Arbitrary File Upload Vulnerability
- CVE-2025-475773 PoCsWordPress TI WooCommerce Wishlist plugin <= 2.9.2 - Arbitrary File Upload Vulnerability
- CVE-2025-476081 PoCWordPress Recover abandoned cart for WooCommerce plugin <= 2.5 - SQL Injection Vulnerability
- CVE-2025-476463 PoCsWordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
- CVE-2025-477371 PoClib.rs in the trailer crate through 0.1.2 for Rust mishandles allocating with a size of zero.
- CVE-2025-477752 PoCsBullfrog's DNS over TCP bypasses domain filtering
- CVE-2025-477791 PoCUsing malformed From header can forge identity with ";" or NULL in name portion
- CVE-2025-477801 PoCcli_permissions.conf: deny option does not work for disallowing shell commands
- CVE-2025-477811 PoCRallly Insufficient Password Login Token Entropy Leads to Account Takeover
- CVE-2025-477821 PoCmotionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
- CVE-2025-477833 PoCslabel-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
- CVE-2025-477861 PoCEmlog vulnerable to Stored Cross-site Scripting
- CVE-2025-478112 PoCsIn Wing FTP Server through 7.4.4, the administrative web interface (listening by default on port 5466) runs as root or SYSTEM by default.…
- CVE-2025-4781224 PoCsKEVIn Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua…
- CVE-2025-478134 PoCsKEVloginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the…
- CVE-2025-479061 PoCUnexpected paths returned from LookPath in os/exec
- CVE-2025-479164 PoCsInvision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within…
- CVE-2025-479172 PoCsMbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the…
- CVE-2025-479311 PoCLibreNMS stored Cross-site Scripting vulnerability in poller group name
- CVE-2025-479451 PoCDonetick Has Weak Default JWT Secret
- CVE-2025-479571 PoCMicrosoft Word Remote Code Execution Vulnerability
- CVE-2025-479621 PoCWindows SDK Elevation of Privilege Vulnerability
- CVE-2025-479812 PoCsSPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
- CVE-2025-479873 PoCsCredential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability