CVE-2025-54000 to CVE-2025-54999
129 CVEs with public proof-of-concept exploits.
- CVE-2025-540581 PoCWeGIA SQL Injection (Blind Time-Based) Vulnerability in idatendido_familiares Parameter on dependente_editarEndereco.php Endpoint
- CVE-2025-540601 PoCWeGIA SQL Injection (Blind Time-Based) Vulnerability in idatendido_familiares Parameter on dependente_editarInfoPessoal.php Endpoint
- CVE-2025-540611 PoCWeGIASQL Injection (Blind Time-Based) Vulnerability in idatendido_familiares Parameter on dependente_editarDoc.php Endpoint
- CVE-2025-540621 PoCWeGIA SQL Injection (Blind Time-Based) Vulnerability in id_dependente Parameter on profile_dependente.php Endpoint
- CVE-2025-540631 PoCCherry Studio One-click Remote Code Execution Vulnerability through Custom URL Handling
- CVE-2025-540687 PoCsKEVLivewire vulnerable to remote command execution during property update hydration
- CVE-2025-540741 PoCCherry Studio is Vulnerable to OS Command Injection during Connection with a Malicious MCP Server
- CVE-2025-540751 PoCmdc vulnerable to XSS in markdown rendering bypassing HTML filter. (N°4)
- CVE-2025-540761 PoCWeGIA Reflected Cross-Site Scripting (XSS) vulnerability in endpoint 'pre_cadastro_atendido.php' parameter 'msg_e'
- CVE-2025-540771 PoCWeGIA Reflected Cross-Site Scripting (XSS) vulnerability in endpoint 'personalizacao.php' parameter 'err'
- CVE-2025-540781 PoCWeGIA Reflected Cross-Site Scripting (XSS) vulnerability in endpoint 'personalizacao_imagem.php' parameter 'err'
- CVE-2025-540791 PoCWeGIA vulnerable to SQL Injection (Blind Time-Based) in endpoint 'Profile_Atendido.php' parameter 'idatendido'
- CVE-2025-540811 PoCSunshineService Has Unquoted Service Path That Allows Local SYSTEM Code Execution
- CVE-2025-540841 PoCCalix Gigacenter ONT - Command Injection
- CVE-2025-541002 PoCsPowerShell Remote Code Execution Vulnerability
- CVE-2025-541101 PoCWindows Kernel Elevation of Privilege Vulnerability
- CVE-2025-541171 PoCNamelessMC allows Stored Cross-Site Scripting (XSS) in dashboard text editor
- CVE-2025-541181 PoCNamelessMC allows sensitive information disclosure in member list component
- CVE-2025-541239 PoCsHoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
- CVE-2025-541251 PoCXWiki Platform: Password and email exposure in xml.vm fields
- CVE-2025-541261 PoCWebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specified
- CVE-2025-541291 PoCHAXiam allows for User Enumeration
- CVE-2025-541352 PoCsCursor Agent is vulnerable to prompt injection via MCP Special Files
- CVE-2025-541361 PoCCursor's Modification of MCP Server Definitions Bypasses Manual Re-approvals
- CVE-2025-541391 PoCHAX CMS' application pages are vulnerable to clickjacking
- CVE-2025-541401 PoCpyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Write
- CVE-2025-542367 PoCsKEVAdobe Commerce | Improper Input Validation (CWE-20)
- CVE-2025-542491 PoCAdobe Experience Manager | Server-Side Request Forgery (SSRF) (CWE-918)
- CVE-2025-542511 PoCAdobe Experience Manager | XML Injection (aka Blind XPath Injection) (CWE-91)
- CVE-2025-542532 PoCsKEVAdobe Experience Manager | Incorrect Authorization (CWE-863)
- CVE-2025-542861 PoCCSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
- CVE-2025-542871 PoCArbitrary File Read via Template Injection in Snapshot Patterns
- CVE-2025-542881 PoCSource Container Identification Vulnerability via cmdline Spoofing in devLXD Server
- CVE-2025-542891 PoCPrivilege Escalation via WebSocket Connection Hijacking in LXD Operations API
- CVE-2025-542901 PoCProject Existence Disclosure via Error Handling in LXD Image Export
- CVE-2025-542911 PoCProject existence disclosure in LXD images API
- CVE-2025-542931 PoCPath Traversal in LXD Instance Log File Retrieval
- CVE-2025-543098 PoCsKEVCrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently…
- CVE-2025-543131 PoCKEVeslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected…
- CVE-2025-543221 PoCXspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py.…
- CVE-2025-543281 PoCAn issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200,…
- CVE-2025-543523 PoCsWordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE:…
- CVE-2025-543652 PoCsfastapi-guard patch contains bypassable RegEx
- CVE-2025-543762 PoCsHoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.
- CVE-2025-543771 PoCRoo Code Lacks Line Break Validation in its Command Execution Tool
- CVE-2025-543781 PoCHAX CMS Backend Lacks Comprehensive Authorization Checks
- CVE-2025-543792 PoCseKuiper API endpoints handling SQL queries with user-controlled table names.
- CVE-2025-543814 PoCsBentoML is Vulnerable to an SSRF Attack Through File Upload Processing
- CVE-2025-543821 PoCCherry Studio RCE Vulnerability Disclosure
- CVE-2025-543872 PoCsIPX is Vulnerable to Path Traversal via Prefix Matching Bypass
- CVE-2025-543891 PoCAIDE improper output neutralization vulnerability
- CVE-2025-544091 PoCAIDE null pointer dereference when reading incorrectly encoded xattr attributes from database (local DoS)
- CVE-2025-544131 PoCskops' MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time
- CVE-2025-544161 PoCtj-actions/branch-names Contains Command Injection Vulnerability
- CVE-2025-544211 PoCNamelessMC allows Stored Cross Site Scripting (XSS) in SEO component
- CVE-2025-544232 PoCscopyparty has a DOM-Based XSS vulnerability when displaying multimedia metadata
- CVE-2025-544244 PoCs1Panel Agent Bypasses Certificate Verification Leading to Arbitrary Command Execution
- CVE-2025-544621 PoCA heap-based buffer overflow vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch…
- CVE-2025-544801 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544811 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544821 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544831 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544841 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544851 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544861 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544871 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544881 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544891 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544901 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544911 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544921 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544931 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-544941 PoCA stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master…
- CVE-2025-545101 PoCA missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative…
- CVE-2025-545541 PoCtiaudit in Tera Insights tiCrypt before 2025-07-17 allows unauthenticated REST API requests that reveal sensitive information about the…
- CVE-2025-545711 PoCModSecurity's Insufficient Return Value Handling can Lead to XSS and Source Code Disclosure
- CVE-2025-545741 PoCSquid's URN Handling can lead to Buffer Overflow
- CVE-2025-545811 PoCvproxy is vulnerable to a divide by zero DoS attack
- CVE-2025-545832 PoCsGitProxy bypasses approvals when pushing multiple branches
- CVE-2025-545841 PoCGitProxy is vulnerable to a packfile parsing exploit
- CVE-2025-545852 PoCsGitProxy is vulnerable to a new branch approval exploit
- CVE-2025-545861 PoCGitProxy is susceptible to a hidden commits injection attack
- CVE-2025-545894 PoCscopyparty Reflected XSS via Filter Parameter
- CVE-2025-545901 PoCwebfinger.js is vulnerable to Blind SSRF attacks through localhost
- CVE-2025-545931 PoCFreshRSS is vulnerable to RCE attacks by authenticated admin
- CVE-2025-545971 PoCLinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.
- CVE-2025-545991 PoCThe Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows account takeover, if SSO is used,…
- CVE-2025-547262 PoCsWordPress JS Archive List Plugin < 6.1.6 - SQL Injection Vulnerability
- CVE-2025-547651 PoCKL-001-2025-013: Xorux XorMon-NG Web Application Privilege Escalation to Administrator
- CVE-2025-547661 PoCKL-001-2025-012: Xorux XorMon-NG Read Only User Export Device Configuration Exposing Sensitive Information
- CVE-2025-547671 PoCKL-001-2025-014: Xorux LPAR2RRD Read Only User Denial of Service
- CVE-2025-547681 PoCKL-001-2025-015: Xorux LPAR2RRD Read Only User Log Download Exposing Sensitive Information
- CVE-2025-547693 PoCsKL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
- CVE-2025-547826 PoCs@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
- CVE-2025-547921 PoCLocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception
- CVE-2025-547931 PoCAstro: Duplicate trailing slash feature can lead to Open Redirects
- CVE-2025-547941 PoCClaude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access
- CVE-2025-547961 PoCCopyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" page
- CVE-2025-547982 PoCstmp does not restrict arbitrary temporary file / directory write via symbolic link `dir` parameter
- CVE-2025-548011 PoCFiber Susceptible to Crash via `BodyParser` Due to Unvalidated Large Slice Index in Decoder
- CVE-2025-548022 PoCspyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE)
- CVE-2025-548041 PoCRussh is missing an overflow check during channel windows adjust
- CVE-2025-548651 PoCTilesheets MediaWiki Extension is Vulnerable to Potential SQL Injection
- CVE-2025-548681 PoCLibreChat exposes arbitrary chats through Meilisearch engine
- CVE-2025-548711 PoCElectron Capture is Vulnerable to TCC Bypass via Misconfigured Node Fuses (macOS)
- CVE-2025-548742 PoCsOpenJPEG allows OOB heap memory write in opj_jp2_read_header
- CVE-2025-548781 PoCHeap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup`
- CVE-2025-548802 PoCsMermaid does not properly sanitize architecture diagram iconText leading to XSS
- CVE-2025-548811 PoCMermaid improperly sanitizes of sequence diagram labels leading to XSS
- CVE-2025-548821 PoCHimmelblau's Kerberos credential cache collection is world readable
- CVE-2025-548861 PoCskops: Card.get_model does not block arbitrary code execution
- CVE-2025-548871 PoCjwe: Missing AES-GCM authentication tag validation in encrypted JWEs
- CVE-2025-548881 PoC@fedify/fedify: Improper Authentication and Incorrect Authorization
- CVE-2025-549142 PoCsAzure Networking Elevation of Privilege Vulnerability
- CVE-2025-549182 PoCsWindows NTLM Elevation of Privilege Vulnerability
- CVE-2025-549201 PoCApache Spark: Spark History Server Code Execution Vulnerability
- CVE-2025-549391 PoCLiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak.
- CVE-2025-549571 PoCAn issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+ bitstream is…
- CVE-2025-549621 PoC/edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg),…
- CVE-2025-549631 PoCAn issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may submit a…
- CVE-2025-549641 PoCAn issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject…
- CVE-2025-549651 PoCAn XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize the job ID…
- CVE-2025-549661 PoCAn issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return sensitive…
- CVE-2025-549671 PoCAn issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An attacker who is able…
- CVE-2025-549681 PoCAn issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In some…
- CVE-2025-549691 PoCAn issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker…
- CVE-2025-549701 PoCAn issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests. In some…
- CVE-2025-549882 PoCsApache Tika PDF parser module: XXE vulnerability in PDFParser's handling of XFA
- CVE-2025-549951 PoCAsterisk remotely exploitable leak of RTP UDP ports and internal resources