CVE-2025-55000 to CVE-2025-55999
113 CVEs with public proof-of-concept exploits.
- CVE-2025-550041 PoCImageMagick: heap-buffer overflow read in MNG magnification with alpha
- CVE-2025-550051 PoCImageMagick: heap-buffer overflow in log colorspace handling
- CVE-2025-550101 PoCKanboard Authenticated Admin Remote Code Execution via Unsafe Deserialization of Events
- CVE-2025-550111 PoCKanboard Path Traversal in File Write via Task File Upload Api
- CVE-2025-551301 PoCA flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted…
- CVE-2025-551491 PoCPath Traversal Vulnerability in PDF Review Function (CWE-22)
- CVE-2025-551501 PoCStirling-PDF SSRF vulnerability on /api/v1/convert/html/pdf
- CVE-2025-551521 PoCoak: ReDoS in x-forwarded-proto and x-forwarded-for headers
- CVE-2025-551561 PoCPyLoad vulnerable to SQL Injection via API /json/add_package in add_links parameter
- CVE-2025-551601 PoCImageMagick Undefined Behavior (function-type-mismatch) in CloneSplayTree
- CVE-2025-551612 PoCsStirling-PDF SSRF vulnerability on /api/v1/convert/markdown/pdf
- CVE-2025-551621 PoCEnvoy: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag
- CVE-2025-551661 PoCsvg-sanitizer By-Passing Attribute Sanitization
- CVE-2025-551671 PoCWeGIA SQL Injection via id_fichamedica at endpoint `GET/html/funcionario/dependente_remover.php`
- CVE-2025-551681 PoCWeGIA SQL Injection via id_fichamedica at endpoint `GET /html/saude/aplicar_medicamento.php`
- CVE-2025-551692 PoCsWeGIA Path Traversal at endpoint 'html/socio/sistema/download_remessa.php' via parameter 'file'
- CVE-2025-551701 PoCWeGIA reflected XSS via `verificacao` and `redir_config` param at endpoint `/html/alterar_senha.php`
- CVE-2025-55182326 PoCsKEVA pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0…
- CVE-2025-551835 PoCsAn information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1,…
- CVE-2025-5518410 PoCsA pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2,…
- CVE-2025-551883 PoCs7-Zip before 25.01 does not always properly handle symbolic links during extraction.
- CVE-2025-551902 PoCsArgo CD: Project API Token Exposes Repository Credentials
- CVE-2025-551941 PoCPart-DB Persistent Denial of Service via Uncaught Exception from Misleading File Extension in Avatar Upload
- CVE-2025-552051 PoCCapsule tenant owners with "patch namespace" permission can hijack system namespaces label
- CVE-2025-552071 PoC@astrojs/node's trailing slash handling causes open redirect issue
- CVE-2025-552122 PoCsImageMagick affected by divide-by-zero in ThumbnailImage via montage -geometry ":" leads to crash
- CVE-2025-552341 PoCWindows SMB Elevation of Privilege Vulnerability
- CVE-2025-552871 PoCGenealogy has a stored XSS vulnerability
- CVE-2025-552962 PoCsLibreNMS allows stored XSS in Alert Template name field
- CVE-2025-552982 PoCsImageMagick Format String Bug in InterpretImageFilename leads to arbitrary code execution
- CVE-2025-553033 PoCsUnauthorized third-party images in Astro’s _image endpoint
- CVE-2025-553041 PoCExiv2 has quadratic performance in ICC profile parsing in JpegBase::readMetadata
- CVE-2025-553155 PoCsASP.NET Security Feature Bypass Vulnerability
- CVE-2025-553191 PoCAgentic AI and Visual Studio Code Remote Code Execution Vulnerability
- CVE-2025-553201 PoCConfiguration Manager Elevation of Privilege Vulnerability
- CVE-2025-553461 PoCUnintended dynamic code execution leads to remote code execution by network attackers
- CVE-2025-554441 PoCA SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0.…
- CVE-2025-554492 PoCsAstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
- CVE-2025-554721 PoCSQL Injection vulnerability exists in Tirreno v0.9.5, specifically in the /admin/loadUsers API endpoint. The vulnerability arises due to…
- CVE-2025-554741 PoCMany Notes 0.10.1 is vulnerable to Cross Site Scripting (XSS), which allows malicious Markdown files to execute JavaScript when viewed.
- CVE-2025-554761 PoCFireShare FileShare 1.2.25 contains a time-based blind SQL injection vulnerability in the sort parameter of the endpoint: GET…
- CVE-2025-554821 PoCTenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the formSetCfm function.
- CVE-2025-554831 PoCTenda AC6 V15.03.06.23_multi is vulnerable to Buffer Overflow in the function formSetMacFilterCfg via the parameters macFilterType and…
- CVE-2025-554951 PoCTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
- CVE-2025-554981 PoCTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.
- CVE-2025-554991 PoCTenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the ntpServer parameter in the fromSetSysTime function.
- CVE-2025-555031 PoCTenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.
- CVE-2025-555211 PoCAn issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial of Service (DoS)…
- CVE-2025-555221 PoCCross-site scripting (XSS) vulnerability in the component /common/reports of Akaunting v3.1.18 allows attackers to execute arbitrary web…
- CVE-2025-555232 PoCsAn issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
- CVE-2025-555241 PoCInsecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.
- CVE-2025-555261 PoCn8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
- CVE-2025-555751 PoCSQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with…
- CVE-2025-555791 PoCSolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is…
- CVE-2025-555801 PoCSolidInvoice version 2.3.7 is vulnerable to a stored cross-site scripting (XSS) issue in the Clients module. An authenticated attacker can…
- CVE-2025-555811 PoCD-Link DCS-825L firmware version 1.08.01 and possibly prior versions contain an insecure implementation in the mydlink-watch-dog.sh…
- CVE-2025-555821 PoCD-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries…
- CVE-2025-555831 PoCD-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the…
- CVE-2025-555841 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the telnet service and root account.
- CVE-2025-555851 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an eval injection vulnerability via the eval() function.
- CVE-2025-555861 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the url parameter at /boafrm/formFilter. This…
- CVE-2025-555871 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the hostname parameter at /boafrm/formMapDelDevice.…
- CVE-2025-555881 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow in the fw_ip parameter at /boafrm/formPortFw. This…
- CVE-2025-555891 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain multiple OS command injection vulnerabilities via the macstr, bandstr, and…
- CVE-2025-555901 PoCTOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain an command injection vulnerability via the component bupload.html.
- CVE-2025-555911 PoCTOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the…
- CVE-2025-555991 PoCD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formWlanSetup function via the parameter f_wds_wepKey.
- CVE-2025-556021 PoCD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formSysCmd function via the submit-url parameter.
- CVE-2025-556031 PoCTenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter.
- CVE-2025-556051 PoCTenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName parameter.
- CVE-2025-556061 PoCTenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parameter.
- CVE-2025-556111 PoCD-Link DIR-619L 2.06B01 is vulnerable to Buffer Overflow in the formLanguageChange function via the nextPage parameter.
- CVE-2025-556131 PoCTenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.
- CVE-2025-556191 PoCReolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this…
- CVE-2025-556201 PoCA cross-site scripting (XSS) vulnerability in the valuateJavascript() function of Reolink v4.54.0.4.20250526 allows attackers to execute…
- CVE-2025-556221 PoCReolink v4.54.0.4.20250526 was discovered to contain a task hijacking vulnerability due to inappropriate taskAffinity settings. NOTE: this…
- CVE-2025-556231 PoCAn issue in the lock screen component of Reolink v4.54.0.4.20250526 allows attackers to bypass authentication via using an ADB (Android…
- CVE-2025-556241 PoCAn intent redirection vulnerability in Reolink v4.54.0.4.20250526 allows unauthorized attackers to access internal functions or access…
- CVE-2025-556251 PoCAn open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL.…
- CVE-2025-556301 PoCA discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware…
- CVE-2025-556341 PoCIncorrect access control in the RTMP server settings of Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware…
- CVE-2025-556681 PoCApache Tomcat: session fixation via rewrite valve
- CVE-2025-557271 PoCXWiki Remote Macros vulnerable to remote code execution from width parameter in the column macro
- CVE-2025-557331 PoCDeepChat One-click Remote Code Execution through Custom URL Handling
- CVE-2025-557341 PoCflaskBlo Authorization Bypass
- CVE-2025-557351 PoCflaskBlog Stored XSS Vulnerability
- CVE-2025-557361 PoCflaskBlog allows arbitrary privilege escalation
- CVE-2025-557371 PoCflaskBlog arbitrary comment delete
- CVE-2025-557411 PoCunopim/unopim allows unauthorized product deletion via mass-delete endpoint
- CVE-2025-557422 PoCsUnoPim Stored XSS via SVG MIME/Sanitizer Bypass
- CVE-2025-557431 PoCUnoPim vulnerable to remote code execution through Arbitrary File upload
- CVE-2025-557442 PoCsUnoPim vulnerable to CSRF on Product edit feature and creation of other types
- CVE-2025-557452 PoCsUnoPim Quick Export feature is vulnerable to CSV injection
- CVE-2025-557461 PoCDirectus allows unauthenticated file upload and file modification due to lacking input sanitization
- CVE-2025-557471 PoCXWiki Platform's configuration files can be accessed through the webjars API
- CVE-2025-557481 PoCXWiki Platform's configuration files can be accessed through jsx and sx endpoints
- CVE-2025-557491 PoCThe XWiki Jetty package (XJetty) allows accessing any application file through URL
- CVE-2025-557524 PoCsApache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
- CVE-2025-557631 PoCBuffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a…
- CVE-2025-557801 PoCA null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document.…
- CVE-2025-558161 PoCHotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.
- CVE-2025-558341 PoCA Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information via the…
- CVE-2025-558521 PoCTenda AC8 v16.03.34.06 is vulnerable to Buffer Overflow in the formWifiBasicSet function via the parameter security or security_5g.
- CVE-2025-558531 PoCSoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal…
- CVE-2025-558851 PoCSQL Injection vulnerability in Alpes Recherche et Developpement ARD GEC en Lign before v.2025-04-23 allows a remote attacker to escalate…
- CVE-2025-558861 PoCAn Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment…
- CVE-2025-558871 PoCCross-Site Scripting (XSS) vulnerability was discovered in the meal reservation service ARD. The vulnerability exists in the transactionID…
- CVE-2025-558881 PoCCross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD. An attacker can intercept the…
- CVE-2025-559041 PoCOpen5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference when a…
- CVE-2025-559112 PoCsAn issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php and the file parameter
- CVE-2025-559122 PoCsAn issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in photo_uploader.php…
- CVE-2025-559441 PoCSlink v1.4.9 allows stored cross-site scripting (XSS) via crafted SVG uploads. When a user views the shared image in a new browser tab,…
- CVE-2025-559761 PoCIntelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local…