CVE-2025-52000 to CVE-2025-52999
64 CVEs with public proof-of-concept exploits.
- CVE-2025-520211 PoCA SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id…
- CVE-2025-520441 PoCIn Frappe ERPNext v15.57.5, the function get_stock_balance() at erpnext/stock/utils.py is vulnerable to SQL Injection, which allows an…
- CVE-2025-520461 PoCTotolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and…
- CVE-2025-520481 PoCIn Frappe 15.x.x before 15.72.0 and 14.x.x before 14.96.10, in the function add_tag() at `frappe/desk/doctype/tag/tag.py` is vulnerable to…
- CVE-2025-520531 PoCTOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the…
- CVE-2025-520781 PoCFile upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to gain escalated…
- CVE-2025-520801 PoCIn Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi…
- CVE-2025-520811 PoCIn Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow vulnerability exists in the HTTPD service through the usb_device.cgi…
- CVE-2025-520821 PoCIn Netgear XR300 V1.0.3.38_10.3.30, a stack-based buffer overflow exists in the HTTPD service through the usb_device.cgi endpoint. The…
- CVE-2025-520892 PoCsA hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to…
- CVE-2025-520941 PoCInsecure Permissions vulnerability in PDQ Smart Deploy V.3.0.2040 allows a local attacker to execute arbtirary code via the…
- CVE-2025-520951 PoCAn issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll
- CVE-2025-521222 PoCsFreeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in…
- CVE-2025-521871 PoCGetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php.
- CVE-2025-521941 PoCA buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio…
- CVE-2025-522041 PoCA Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter
- CVE-2025-522071 PoCPBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.
- CVE-2025-522771 PoCCross Site Scripting vulnerability in YesWiki v.4.54 allows a remote attacker to execute arbitrary code via a crafted payload to the meta…
- CVE-2025-522881 PoCAssertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build.c, the Access and Mobility Management Function…
- CVE-2025-522891 PoCA Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a…
- CVE-2025-523581 PoCA cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32…
- CVE-2025-523631 PoCTenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with…
- CVE-2025-523641 PoCInsecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the…
- CVE-2025-523673 PoCsCross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.
- CVE-2025-523721 PoCAn issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the…
- CVE-2025-523731 PoCUse of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in…
- CVE-2025-523741 PoCUse of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other…
- CVE-2025-523851 PoCAn issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process…
- CVE-2025-523861 PoCCycloneDX Sunshine v0.9 is vulnerable to CSV Formula Injection via a crafted JSON file
- CVE-2025-523891 PoCAn Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attackers to access…
- CVE-2025-523921 PoCSoosyze CMS 2.0 allows brute-force login attacks via the /user/login endpoint due to missing rate-limiting and lockout mechanisms. An…
- CVE-2025-524561 PoCA memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading…
- CVE-2025-524611 PoCAn out-of-bounds read vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch…
- CVE-2025-524641 PoCMeshtastic Repeated Public and Private Keypairs
- CVE-2025-524651 PoCGeoServer has an arbitrary file write vulnerability in its Master Password Dump Page
- CVE-2025-524721 PoCXWiki Platform vulnerable to HQL injection via wiki and space search REST API
- CVE-2025-524741 PoCWeGIA SQL Injection Vulnerability in id Parameter on control.php Endpoint
- CVE-2025-524883 PoCsDNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
- CVE-2025-525601 PoCKanboard Password Reset Poisoning via Host Header Injection
- CVE-2025-525661 PoCllama.cpp tokenizer signed vs. unsigned heap overflow
- CVE-2025-525751 PoCEspoCRM vulnerable to LDAP Injection through Improper Neutralization of Special Elements
- CVE-2025-526651 PoCA malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access application, UniFi Access,…
- CVE-2025-526881 PoCCommand Injection Vulnerability in the OmniAccess Stellar Web Management Interface
- CVE-2025-526891 PoCWeak Session ID Check in the OmniAccess Stellar Web Management Interface
- CVE-2025-5269110 PoCsKEVUpload Arbitrary Files
- CVE-2025-526942 PoCsExecution of arbitrary SQL commands
- CVE-2025-528861 PoCPoppler Use After Free Vulnerability
- CVE-2025-528881 PoCAllure 2's xunit-xml-plugin Vulnerable to Improper XXE Restriction
- CVE-2025-528891 PoCIncus vulnerable to DoS through antispoofing nftables firewall rule bypass on bridge networks with ACLs
- CVE-2025-528901 PoCIncus vulnerable to antispoofing nftables firewall rule bypass on bridge networks with ACLs
- CVE-2025-529002 PoCsFile Browser has Insecure File Permissions
- CVE-2025-529012 PoCsFile Browser allows sensitive data to be transferred in URL
- CVE-2025-529021 PoCFile Browser has Stored Cross-Site Scripting vulnerability
- CVE-2025-529031 PoCFile Browser Allows Execution of Shell Commands That Can Spawn Other Commands
- CVE-2025-529041 PoCFile Browser: Command Execution not Limited to Scope
- CVE-2025-529131 PoCA vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an…
- CVE-2025-529141 PoCA vulnerability in the Suite Applications Services component of Mitel MiCollab 10.0 through SP1 FP1 (10.0.1.101) could allow an…
- CVE-2025-529151 PoCK7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to…
- CVE-2025-529231 PoCSangfor aTrust through 2.4.10 allows users to modify the ExecStartPre command.
- CVE-2025-529301 PoCA memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When…
- CVE-2025-529705 PoCsA improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and…
- CVE-2025-529951 PoCFile Browser vulnerable to command execution allowlist bypass
- CVE-2025-529962 PoCsFile Browser's Password Protection of Links Vulnerable to Bypass
- CVE-2025-529972 PoCsFile Browser Insecurely Handles Passwords