CVE-2025-56000 to CVE-2025-56999
30 CVEs with public proof-of-concept exploits.
- CVE-2025-560051 PoCAn undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile`…
- CVE-2025-560151 PoCIn GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.
- CVE-2025-561322 PoCsLiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns…
- CVE-2025-562361 PoCFormCms v0.5.5 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload feature. Authenticated users can upload…
- CVE-2025-562412 PoCsAztech DSL5005EN firmware 1.00.AZ_2013-05-10 and possibly other versions allows unauthenticated attackers to change the administrator…
- CVE-2025-562661 PoCA Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.
- CVE-2025-563111 PoCIn Shenzhen C-Data Technology Co. FD602GW-DX-R410 (firmware v2.2.14), the web management interface contains an authenticated CSRF…
- CVE-2025-563811 PoCERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint…
- CVE-2025-563831 PoCNotepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code.
- CVE-2025-563991 PoCalexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted…
- CVE-2025-564471 PoCTM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
- CVE-2025-564481 PoCThe Positron PX360BT SW REV 8 car alarm system is vulnerable to a replay attack due to a failure in implementing rolling code security.…
- CVE-2025-564981 PoCAn OS command injection vulnerability exists in PLDT WiFi Router's Prolink PGN6401V Firmware 8.1.2 web management interface. The ping6.asp…
- CVE-2025-565201 PoCDify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component…
- CVE-2025-565341 PoCA cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute…
- CVE-2025-565351 PoCA cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting…
- CVE-2025-565361 PoCA stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via…
- CVE-2025-565371 PoCA stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web…
- CVE-2025-566051 PoCA reflected Cross-Site Scripting (XSS) vulnerability exists in the register.php backend script of PuneethReddyHC Event Management System…
- CVE-2025-566891 PoCOne Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor…
- CVE-2025-567101 PoCA Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul…
- CVE-2025-567621 PoCParacrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.
- CVE-2025-567991 PoCReolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted…
- CVE-2025-568001 PoCReolink desktop application 8.18.12 contains a vulnerability in its local authentication mechanism. The application implements lock screen…
- CVE-2025-568011 PoCThe Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption…
- CVE-2025-568022 PoCsThe Reolink desktop application uses a hard-coded and predictable AES encryption key to encrypt user configuration files allowing…
- CVE-2025-568033 PoCsFigma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute…
- CVE-2025-568071 PoCA cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a…
- CVE-2025-568151 PoCDatart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses…
- CVE-2025-568192 PoCsAn issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.