CVE-2025-53000 to CVE-2025-53999
99 CVEs with public proof-of-concept exploits.
- CVE-2025-530022 PoCsLLaMA-Factory Remote Code Execution (RCE) Vulnerability
- CVE-2025-530041 PoCDataease Redshift Data Source JDBC Connection Parameters Bypass Vulnerability
- CVE-2025-530051 PoCDataease PostgreSQL Data Source JDBC Connection Parameters Bypass Vulnerability
- CVE-2025-530092 PoCsMaterialX Stack Overflow via Lack of MTLX XML Parsing Recursion Limit
- CVE-2025-530102 PoCsMaterialX's unchecked nodeGraph->getOutput return is vulnerable to NULL Pointer Dereference
- CVE-2025-530112 PoCsMaterialX is Vulnerable to NULL Pointer Dereference due to Unchecked implGraphOutput
- CVE-2025-530122 PoCsMaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion
- CVE-2025-530141 PoCImageMagick has Heap Buffer Overflow in InterpretImageFilename
- CVE-2025-530151 PoCImageMagick has XMP profile write that triggers hang due to unbounded loop
- CVE-2025-530201 PoCApache HTTP Server: HTTP/2 DoS by Memory Increase
- CVE-2025-530851 PoCA memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8. When…
- CVE-2025-530911 PoCWeGIA has Unauthenticated Time-Based Blind SQL Injection in almox Parameter
- CVE-2025-530921 PoCStrapi core vulnerable to sensitive data exposure via CORS misconfiguration
- CVE-2025-530931 PoCTabberNeue vulnerable to Stored XSS through wikitext
- CVE-2025-531071 PoC@cyanheads/git-mcp-server vulnerable to command injection in several tools
- CVE-2025-531181 PoCSecurden Unified PAM Authentication Bypass
- CVE-2025-533541 PoCNiceGUI is vulnerable to Reflected XSS attack
- CVE-2025-533551 PoCmcp-server-kubernetes vulnerable to command injection in several tools
- CVE-2025-533631 PoCDpanel has an arbitrary file read vulnerability
- CVE-2025-533641 PoCParse Server exposes the data schema via GraphQL API
- CVE-2025-533672 PoCsDjVuLibre OOB-Write Vulnerability in MMRDecoder
- CVE-2025-533681 PoCCitizen is vulnerable to stored XSS attack in the legacy search bar
- CVE-2025-533691 PoCCitizen Short Description stored XSS vulnerability through wikitext
- CVE-2025-533701 PoCCitizen stored XSS vulnerability through short descriptions
- CVE-2025-533721 PoCnode-code-sandbox-mcp has a Sandbox Escape via Command Injection
- CVE-2025-533771 PoCWebGia allows Cross-Site Scripting (XSS) in cadastro_dependente_pessoa_nova.php via the id_funcionario parameter
- CVE-2025-533921 PoCIn Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath…
- CVE-2025-535101 PoCA memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9.8. When loading a…
- CVE-2025-535111 PoCA heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-535251 PoCWebGia allows Cross-Site Scripting (XSS) in profile_familiar.php via the id_dependente parameter
- CVE-2025-535261 PoCWeGIA allows Stored XSS attacks in novo_memorando.php
- CVE-2025-535271 PoCWeGIA allows Time-Based Blind SQL Injection in the relatorio_geracao.php endpoint
- CVE-2025-535291 PoCWeGIA allows SQL Injection in html/funcionario/profile_funcionario.php (id_funcionario parameter)
- CVE-2025-535301 PoCWeGIA allows Uncontrolled Resource Consumption via the errorstr parameter
- CVE-2025-535311 PoCWeGIA allows Uncontrolled Resource Consumption via the fid parameter
- CVE-2025-535332 PoCsPi-hole Admin Interface vulnerable to cross-site scripting via malformed URL path on 404 error page
- CVE-2025-535341 PoCRatPanel can perform remote command execution without authorization
- CVE-2025-535393 PoCsReDoS in fastapi-guard's penetration attempts detector
- CVE-2025-535471 PoCHelm Chart Dependency Updating With Malicious Chart.yaml Content And Symlink Can Lead To Code Execution
- CVE-2025-535571 PoCA heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-535582 PoCsZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all installations. With the knowledge of the credential,…
- CVE-2025-535801 PoCWordPress Simple Business Directory Pro Plugin < 15.6.9 - Privilege Escalation Vulnerability
- CVE-2025-536201 PoCCrashing any Qwik Server
- CVE-2025-536241 PoCdocusaurus-plugin-content-gists Exposes GitHub Personal Access Token
- CVE-2025-536261 PoCpdfme has Sandbox Escape and Prototype Pollution vulnerabilities in pdfme expression evaluation
- CVE-2025-536281 PoCcpp-httplib does not limit the length of a line
- CVE-2025-536291 PoCcpp-httplib Unbounded Memory Allocation in Chunked/No-Length Requests Vulnerability
- CVE-2025-536321 PoCChall-Manager's scenario decoding process does not check for zip slips
- CVE-2025-536403 PoCsIndico vulnerable to user enumeration via API endpoint
- CVE-2025-536441 PoCOpenCV contains a use after free buffer write due to an uninitialized pointer
- CVE-2025-536902 PoCsKEVSitecore Products ViewState Deserialization Vulnerability
- CVE-2025-536915 PoCsSitecore Experience Remote Code Execution through Insecure Deserialization
- CVE-2025-536933 PoCsHTML Cache Poisoning through Unsafe Reflections
- CVE-2025-536945 PoCsInformation Disclosure in ItemServices API
- CVE-2025-537661 PoCGDI+ Remote Code Execution Vulnerability
- CVE-2025-5377042 PoCsKEVMicrosoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2025-537715 PoCsMicrosoft SharePoint Server Spoofing Vulnerability
- CVE-2025-537723 PoCsWeb Deploy Remote Code Execution Vulnerability
- CVE-2025-537733 PoCsGitHub Copilot and Visual Studio Remote Code Execution Vulnerability
- CVE-2025-537791 PoCWindows Kerberos Elevation of Privilege Vulnerability
- CVE-2025-537861 PoCMicrosoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability
- CVE-2025-538161 PoCGHSL-2025-058 - 7-Zip Multi-byte write heap buffer overflow in NCompress::NRar5::CDecoder
- CVE-2025-538171 PoCGHSL-2025-059 - 7-Zip - Null pointer array write attempt in NArchive::NCom::CHandler::GetStream
- CVE-2025-538201 PoCWeGIA vulnerable to Cross-Site Scripting (XSS) Reflected via endpoint 'index.php' parameter 'erro'
- CVE-2025-538211 PoCWeGIA vulnerable to Open Redirect in endpoint 'control.php' parameter 'nextPage'
- CVE-2025-538221 PoCWeGIA vulnerable to Reflected Cross-Site Scripting in endpoint 'relatorio_geracao.php' parameter 'tipo_relatorio'
- CVE-2025-538231 PoCWeGIA vulnerable to SQL Injection (Blind Time-Based) in `processa_deletar_socio.php` parameter `id_socio`
- CVE-2025-538241 PoCWeGIA ReflectedCross-Site Scripting (XSS) vulnerability in endpoint 'cadastro_pet.php' parameter 'msg'
- CVE-2025-538262 PoCsFileBrowser Has Insecure JWT Handling Which Allows Session Replay Attacks after Logout
- CVE-2025-538321 PoC@translated/lara-mcp vulnerable to command injection in import_tmx tool
- CVE-2025-538332 PoCsLaRecipe is vulnerable to Server-Side Template Injection attacks
- CVE-2025-538361 PoCXWiki Rendering is vulnerable to RCE attacks when processing nested macros
- CVE-2025-538381 PoCLinkAce has a Stored One Click XSS vulnerability
- CVE-2025-538531 PoCA heap-based buffer overflow vulnerability exists in the ISHNE parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-538871 PoCDirectus's exact version number is exposed by the OpenAPI Spec
- CVE-2025-538901 PoCpyLoad vulnerable to remote code execution through js2py onCaptchaResult
- CVE-2025-538921 PoCIntlify Vue I18n's escapeParameterHtml does not prevent DOM-based XSS via tag attributes like onerror
- CVE-2025-538932 PoCsFile Browser Vulnerable to Uncontrolled Memory Consumption Due to Oversized File Processing
- CVE-2025-539051 PoCVim has path traversial issue with tar.vim and special crafted tar files
- CVE-2025-539061 PoCVim has path traversal issue with zip.vim and special crafted zip archives
- CVE-2025-539231 PoCEmlog vulnerable to reflected Cross-site Scripting in admin panel
- CVE-2025-539241 PoCEmlog vulnerable to stored Cross-site Scripting in links functionality
- CVE-2025-539251 PoCEmlog has Stored Cross-site Scripting vulnerability in file upload functionality
- CVE-2025-539261 PoCEmlog has Stored Cross-site Scripting vulnerability due to error
- CVE-2025-539271 PoCMaxKB sandbox bypass
- CVE-2025-539281 PoCMaxKB has RCE in MCP call
- CVE-2025-539291 PoCWeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint `adicionar_cor.php` parameter `cor`
- CVE-2025-539301 PoCWeGIA vulnerable to Stored Cross-Site Scripting (XSS) via endpoint 'adicionar_especie.php' parameter 'especie'
- CVE-2025-539311 PoCWeGIA vulnerable to Stored Cross-Site Scripting via endpoint `adicionar_raca.php` parameter `raca`
- CVE-2025-539321 PoCWeGIA vulnerable to Reflected Cross-Site Scripting via endpoint 'cadastro_adotante.php' parameter 'cpf'
- CVE-2025-539331 PoCWeGIA vulnerable to Stored Cross-Site Scripting via endpoint 'adicionar_enfermidade.php' parameter 'nome'
- CVE-2025-539341 PoCWeGIA vulnerable to Stored Cross-Site Scripting via endpoint 'control.php' parameter 'descricao_emergencia'
- CVE-2025-539351 PoCWeGIA vulnerable to Reflected Cross-Site Scripting via endpoint `personalizacao_selecao.php` parameter `id`
- CVE-2025-539361 PoCWeGIA vulnerable to Reflected Cross-Site Scripting via endpoint `personalizacao_selecao.php` parameter `nome_car`
- CVE-2025-539371 PoCWeGIA has SQL Injection (Blind Time-Based) Vulnerability in `cargo` Parameter on `control.php` Endpoint
- CVE-2025-539381 PoCWeGIA vulnerable to Authentication Bypass due to Missing Session Validation in multiple endpoints
- CVE-2025-539441 PoCAutoGPT Platform Exposes Graph Execution Results via Authorization Gap
- CVE-2025-539461 PoCWeGIA vulnerable to SQL Injection in endpoint profile_paciente.php parameter id_fichamedica
- CVE-2025-539641 PoCGoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary…