CVE-2025-57000 to CVE-2025-57999
79 CVEs with public proof-of-concept exploits.
- CVE-2025-570551 PoCWonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An authenticated…
- CVE-2025-570571 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the listStr parameter in the ipMacBindListStore function. This…
- CVE-2025-570581 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formSetDebugCfg function via the pEnable, pLevel,…
- CVE-2025-570591 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the dhcpIndex parameter in the addDhcpRule function. This…
- CVE-2025-570601 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the rules parameter in the dns_forward_rule_store function. This…
- CVE-2025-570611 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain multiple stack overflows in the formIPMacBindModify function via the ruleId, ip,…
- CVE-2025-570621 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the delDhcpIndex parameter in the formDelDhcpRule function. This…
- CVE-2025-570631 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the portMappingIndex parameter in the formDelPortMapping…
- CVE-2025-570641 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the bindDhcpIndex parameter in the modifyDhcpRule function. This…
- CVE-2025-570691 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pPppUser parameter in the getsinglepppuser function. This…
- CVE-2025-570701 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the gstUp parameter in the guestWifiRuleRefresh function. This…
- CVE-2025-570711 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the vpnUsers parameter in the formAddVpnUsers function. This…
- CVE-2025-570721 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the staticRouteGateway parameter in the formSetStaticRoute…
- CVE-2025-570781 PoCTenda G3 v3.0br_V15.11.0.17 was discovered to contain a stack overflow in the pppoeServerWhiteMacIndex parameter in the…
- CVE-2025-570851 PoCTenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function. This…
- CVE-2025-570861 PoCTenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the String parameter in the formDeleteMeshNode function. This…
- CVE-2025-570871 PoCTenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the countryCode parameter in the werlessAdvancedSet function.…
- CVE-2025-571051 PoCThe DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The…
- CVE-2025-571171 PoCA Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary…
- CVE-2025-571181 PoCAn issue in PHPGurukul Online-Library-Management-System v3.0 allows an attacker to escalate privileges via the index.php
- CVE-2025-571191 PoCAn issue in Online Library Management System v.3.0 allows an attacker to escalate privileges via the adminlogin.php component and the…
- CVE-2025-571401 PoCrsbi-pom 4.7 is vulnerable to SQL Injection in the /bi/service/model/DatasetService path.
- CVE-2025-571411 PoCrsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.
- CVE-2025-571641 PoCFlowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
- CVE-2025-571742 PoCsAn issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other…
- CVE-2025-571762 PoCsThe rfpiped service on TCP port 555 in Ceragon Networks / Siklu Communication EtherHaul series (8010TX and 1200FX tested) Firmware 7.4.0…
- CVE-2025-572181 PoCTenda AC10 v4.0 firmware v16.03.10.09_multi_TDE01 was discovered to contain a stack overflow via the security_5g parameter in the function…
- CVE-2025-572271 PoCAn unquoted service path in Kingosoft Technology Ltd Kingo ROOT v1.5.8.3353 allows attackers to escalate privileges via placing a crafted…
- CVE-2025-572481 PoCA null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file…
- CVE-2025-572781 PoCThe LB-Link BL-CPE300M AX300 4G LTE Router firmware version BL-R8800_B10_ALK_SL_V01.01.02P42U14_06 does not implement proper session…
- CVE-2025-572851 PoCcodeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly…
- CVE-2025-572931 PoCA command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function…
- CVE-2025-572961 PoCTenda AC6 router firmware 15.03.05.19 contains a command injection vulnerability in the formSetIptv function, which processes requests to…
- CVE-2025-573251 PoCrollbar is a package designed to effortlessly track and debug errors in JavaScript applications. This package includes advanced error…
- CVE-2025-573891 PoCA reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to…
- CVE-2025-573922 PoCsBenimPOS Masaustu 3.0.x is affected by insecure file permissions. The application installation directory grants Everyone and BUILTIN\Users…
- CVE-2025-574251 PoCA Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated attacker to inject…
- CVE-2025-574301 PoCCreacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint…
- CVE-2025-574311 PoCThe Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware…
- CVE-2025-574321 PoCBlackmagic Web Presenter version 3.3 exposes a Telnet service on port 9977 that accepts unauthenticated commands. This service allows…
- CVE-2025-574331 PoCThe 2wcom IP-4c 2.15.5 device's web interface includes an information disclosure vulnerability. By sending a crafted POST request to a…
- CVE-2025-574341 PoCCreacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants…
- CVE-2025-574371 PoCThe Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977.…
- CVE-2025-574381 PoCThe 2wcom IP-4c 2.15.5 device suffers from a Broken Access Control vulnerability. Certain sensitive endpoints are intended to be…
- CVE-2025-574391 PoCCreacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An…
- CVE-2025-574411 PoCThe Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on…
- CVE-2025-574571 PoCAn OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject arbitrary OS…
- CVE-2025-574601 PoCFile upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
- CVE-2025-574621 PoCStored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML via a crafted PDF…
- CVE-2025-574891 PoCIncorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to…
- CVE-2025-575201 PoCA Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not…
- CVE-2025-575381 PoCA stored cross-site scripting (XSS) vulnerability in the HTTP Proxy field within the Datacenter configuration panel of Proxmox Virtual…
- CVE-2025-575391 PoCA stored cross-site scripting (XSS) vulnerability in the U2F Origin field of the Datacenter configuration in Proxmox Virtual Environment…
- CVE-2025-575401 PoCA stored cross-site scripting (XSS) vulnerability exists in the WebAuthn Relying Party field within the Datacenter configuration of…
- CVE-2025-576232 PoCsA NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Service.
- CVE-2025-576361 PoCOS Command injection vulnerability in D-Link C1 2020-02-21. The sub_47F028 function in jhttpd contains a command injection vulnerability…
- CVE-2025-576421 PoCA Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP shell scripts on the…
- CVE-2025-576921 PoCPiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution…
- CVE-2025-577511 PoCDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
- CVE-2025-577531 PoCvite-plugin-static-copy files not included in `src` are accessible with a crafted request
- CVE-2025-577601 PoCLangflow Vulnerable to Privilege Escalation via CLI Superuser Creation
- CVE-2025-577611 PoCWeGIA SQL Injection vulnerability via 'id_funcionario' param at endpoint `/html/funcionario/dependente_remover.php`
- CVE-2025-577621 PoCWeGIA Stored Cross-Site Scripting (XSS) vulnerability in the endpoint 'dependente_docdependente.php' with parameter 'nome'
- CVE-2025-577631 PoCCross-Site Scripting (XSS) Reflected in 'insere_despacho.php' parameter 'sccs'
- CVE-2025-577641 PoCWeGIA Cross-Site Scripting (XSS) Reflected endpoint 'cargos.php' parameter 'msg_e'
- CVE-2025-577651 PoCWeGIA Cross-Site Scripting (XSS) Reflected endpoint 'pre_cadastro_adotante.php' parameter 'msg_e'
- CVE-2025-577721 PoCDataease H2 JDBC RCE Bypass
- CVE-2025-577883 PoCsUnauthorized API Access Risk
- CVE-2025-577891 PoCVulnerability in Initial Administrator Login Process
- CVE-2025-577901 PoCPath Traversal Vulnerability
- CVE-2025-577911 PoCArgument Injection Vulnerability in CommServe
- CVE-2025-578001 PoCAudiobookshelf vulnerable to OIDC token exfiltration and account takeover
- CVE-2025-578011 PoCgnark is vulnerable to signature malleability in EdDSA and ECDSA due to missing scalar checks
- CVE-2025-578032 PoCsImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow
- CVE-2025-578071 PoCImageMagick BlobStream Forward-Seek Under-Allocation
- CVE-2025-578083 PoCsESP-IDF web_server basic auth bypass using empty or incomplete Authorization header
- CVE-2025-5781924 PoCsKEVFreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
- CVE-2025-578221 PoCNext.js Improper Middleware Redirect Handling Leads to SSRF
- CVE-2025-578336 PoCsAn issue was discovered in Django 4.2 before 4.2.24, 5.1 before 5.1.12, and 5.2 before 5.2.6. FilteredRelation is subject to SQL injection…