CVE-2025-50000 to CVE-2025-50999
69 CVEs with public proof-of-concept exploits.
- CVE-2025-501291 PoCA memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When decoding…
- CVE-2025-501545 PoCsMicrosoft Windows File Explorer Spoofing Vulnerability
- CVE-2025-501651 PoCWindows Graphics Component Remote Code Execution Vulnerability
- CVE-2025-501681 PoCWin32k Elevation of Privilege Vulnerability
- CVE-2025-501801 PoCesm.sh is vulnerable to full-response SSRF
- CVE-2025-501831 PoCOpenList (frontend) allows XSS Attacks in the built-in Markdown Viewer
- CVE-2025-502001 PoCRabbitMQ Node can log Basic Auth header from an HTTP request
- CVE-2025-502011 PoCWeGIA OS Command Injection in debug_info.php parameter 'branch'
- CVE-2025-502331 PoCA vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insufficient validation of…
- CVE-2025-502341 PoCMCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter…
- CVE-2025-502511 PoCServer side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
- CVE-2025-502865 PoCsA Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plugin via the…
- CVE-2025-503401 PoCAn Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send…
- CVE-2025-503411 PoCA Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can manipulate the SQL…
- CVE-2025-503431 PoCAn issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not…
- CVE-2025-503631 PoCPhpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name field.
- CVE-2025-503831 PoCalextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by parameter.
- CVE-2025-504282 PoCsIn RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability…
- CVE-2025-504331 PoCAn issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to…
- CVE-2025-504552 PoCsSQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <=…
- CVE-2025-504601 PoCA remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py…
- CVE-2025-504611 PoCA deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script when using the…
- CVE-2025-504641 PoCA buffer overflow vulnerability exists in the upload.cgi module of the iptime NAS firmware v1.5.04. The vulnerability arises due to the…
- CVE-2025-504661 PoCOpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the…
- CVE-2025-504681 PoCOpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the…
- CVE-2025-504721 PoCThe modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the…
- CVE-2025-504812 PoCsA cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute…
- CVE-2025-504841 PoCImproper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session…
- CVE-2025-504851 PoCImproper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 allows attackers to…
- CVE-2025-504861 PoCImproper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allows attackers to…
- CVE-2025-504871 PoCImproper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management System v2.4 allows…
- CVE-2025-504881 PoCImproper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management System v3.0 allows…
- CVE-2025-504891 PoCImproper session invalidation in the component /srms/change-password.php of PHPGurukul Student Result Management System v2.0 allows…
- CVE-2025-504901 PoCImproper session invalidation in the component /elms/emp-changepassword.php of PHPGurukul Student Result Management System v2.0 allows…
- CVE-2025-504941 PoCImproper session invalidation in the component /doctor/change-password.php of PHPGurukul Car Washing Management System v1.0 allows…
- CVE-2025-505281 PoCA buffer overflow vulnerability exists in the fromNatStaticSetting function of Tenda AC6 <=V15.03.05.19 via the page parameter.
- CVE-2025-505381 PoCFlowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
- CVE-2025-505651 PoCDoubo ERP 1.0 has an SQL injection vulnerability due to a lack of filtering of user input, which can be remotely initiated by an attacker.
- CVE-2025-505783 PoCsLinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host`…
- CVE-2025-505811 PoCMRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.
- CVE-2025-505821 PoCStudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Course module.
- CVE-2025-505831 PoCStudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.
- CVE-2025-505841 PoCStudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module.
- CVE-2025-505861 PoCStudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).
- CVE-2025-505921 PoCCross site scripting vulnerability in seacms before 13.2 via the vid parameter to Upload/js/player/dmplayer/player.
- CVE-2025-506081 PoCA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgitest.cgi file.…
- CVE-2025-506091 PoCA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the Function_00465620 of the cgitest.cgi file. Attackers…
- CVE-2025-506101 PoCA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00476598 function of the cgitest.cgi file.…
- CVE-2025-506111 PoCA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00473154 function of the cgitest.cgi file.…
- CVE-2025-506121 PoCA buffer overflow vulnerability has been discovered in the Netis WF2880 v2.1.40207 in the FUN_004743f8 function of the cgitest.cgi file.…
- CVE-2025-506131 PoCA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00475e1c function of the cgitest.cgi file.…
- CVE-2025-506141 PoCA buffer overflow vulnerability has been discovered in the Netis WF2880 v2.1.40207 in the FUN_0047151c function of the cgitest.cgi file.…
- CVE-2025-506151 PoCA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00470c50 function of the cgitest.cgi file.…
- CVE-2025-506161 PoCA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046f984 function of the cgitest.cgi file.…
- CVE-2025-506171 PoCA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_0046ed68 function of the cgitest.cgi file.…
- CVE-2025-506351 PoCA null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function…
- CVE-2025-506751 PoCGPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The…
- CVE-2025-506881 PoCA command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload…
- CVE-2025-507061 PoCAn issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function
- CVE-2025-507071 PoCAn issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component
- CVE-2025-507382 PoCsThe Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo…
- CVE-2025-507541 PoCUnisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script…
- CVE-2025-507561 PoCWavlink WN535K3 20191010 was found to contain a command injection vulnerability in the set_sys_adm function via the newpass parameter.…
- CVE-2025-507771 PoCThe firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1.00.02) contains an Incorrect Access Control…
- CVE-2025-508661 PoCCloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic…
- CVE-2025-508671 PoCA SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST…
- CVE-2025-508971 PoCA vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address…
- CVE-2025-509442 PoCsAn issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom…
- CVE-2025-509461 PoCOS Command Injection in Olivetin 2025.4.22 Custom Themes via the ParseRequestURI function in service/internal/executor/arguments.go.