CVE-2025-49000 to CVE-2025-49999
44 CVEs with public proof-of-concept exploits.
- CVE-2025-490014 PoCsDataease Authentication Bypass Vulnerability
- CVE-2025-490025 PoCsDataease H2 Database Remote Code Execution (RCE) Bypass Vulnerability
- CVE-2025-490031 PoCDataease H2 JDBC Connection Remote Code Execution
- CVE-2025-490292 PoCsWordPress Custom Login And Signup Widget plugin <= 1.0 - Arbitrary Code Execution vulnerability
- CVE-2025-490711 PoCWordPress Flozen < 1.5.1 - Arbitrary File Upload Vulnerability
- CVE-2025-490911 PoCKDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a…
- CVE-2025-4911328 PoCsKEVRoundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in…
- CVE-2025-491251 PoCApache Tomcat: Security constraint bypass for pre/post-resources
- CVE-2025-491281 PoCJackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
- CVE-2025-491311 PoCFastGPT Sandbox Vulnerable to Sandbox Bypass
- CVE-2025-4913232 PoCsPterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
- CVE-2025-491363 PoCslistmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
- CVE-2025-491381 PoCHAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
- CVE-2025-491391 PoC@haxtheweb/haxcms-nodejs Iframe Phishing vulnerability
- CVE-2025-491412 PoCsHaxCMS-PHP Command Injection Vulnerability
- CVE-2025-491448 PoCsNotepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path
- CVE-2025-491491 PoCDify has XSS vulnerability
- CVE-2025-492231 PoCbillboard.js before 3.15.1 was discovered to contain a prototype pollution via the function generate, which could allow attackers to…
- CVE-2025-493881 PoCWordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
- CVE-2025-494841 PoCExtension - joomsky.com - SQL injection in JS jobs component version 1.1.5 - 1.4.1 for Joomla
- CVE-2025-494932 PoCsAkamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
- CVE-2025-495331 PoCAdobe Experience Manager (MS) | Deserialization of Untrusted Data (CWE-502)
- CVE-2025-495751 PoCCitizen allows stored XSS in Command Palette tip messages
- CVE-2025-495761 PoCCitizen allows stored XSS in search no result messages
- CVE-2025-495771 PoCCitizen allows stored XSS in preference menu headings
- CVE-2025-495781 PoCCitizen allows stored XSS in user registration date message
- CVE-2025-495791 PoCCitizen allows stored XSS in menu heading message
- CVE-2025-495901 PoCCryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability
- CVE-2025-495911 PoCCryptPad 2FA Bypass Vulnerability
- CVE-2025-495964 PoCsMCP Inspector proxy server lacks authentication between the Inspector client and proxy
- CVE-2025-496193 PoCsSkyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the…
- CVE-2025-496771 PoCMicrosoft Brokering File System Elevation of Privilege Vulnerability
- CVE-2025-496831 PoCMicrosoft Virtual Hard Disk Remote Code Execution Vulnerability
- CVE-2025-497046 PoCsKEVMicrosoft SharePoint Remote Code Execution Vulnerability
- CVE-2025-497068 PoCsKEVMicrosoft SharePoint Server Spoofing Vulnerability
- CVE-2025-497211 PoCWindows Fast FAT File System Driver Elevation of Privilege Vulnerability
- CVE-2025-497301 PoCMicrosoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability
- CVE-2025-497411 PoCMicrosoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2025-497441 PoCWindows Graphics Component Elevation of Privilege Vulnerability
- CVE-2025-498251 PoCTeleport allows remote authentication bypass
- CVE-2025-498321 PoCAsterisk is Vulnerable to Remote DoS and possible RCE Attacks During Memory Allocation
- CVE-2025-4984417 PoCsRedis Lua Use-After-Free may lead to remote code execution
- CVE-2025-499011 PoCWordPress Simple Link Directory plugin < 14.8.1 - Broken Authentication vulnerability
- CVE-2025-499401 PoCWordPress Fusion Builder plugin <= 3.13.2 - Cross Site Scripting (XSS) vulnerability