CVE-2025-58000 to CVE-2025-58999
43 CVEs with public proof-of-concept exploits.
- CVE-2025-580343 PoCsKEVAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in…
- CVE-2025-580441 PoCJumpServer has an Open Redirect Vulnerability
- CVE-2025-580561 PoCNetty is vulnerable to request smuggling due to incorrect parsing of chunk extensions
- CVE-2025-580572 PoCsNetty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
- CVE-2025-580581 PoCgithub.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives
- CVE-2025-580601 PoCcups has Authentication bypass with AuthType Negotiate
- CVE-2025-580631 PoCCoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
- CVE-2025-581591 PoCWeGIA Authenticated Arbitrary File Upload Leading To Remote Code Execution (RCE)
- CVE-2025-581612 PoCsMobSF Path Traversal in GET /download/<filename> using absolute filenames
- CVE-2025-581622 PoCsMobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
- CVE-2025-581761 PoCDive's improper processing of custom urls can lead to Remote Code Execution
- CVE-2025-581793 PoCsAstro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
- CVE-2025-581802 PoCsOctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
- CVE-2025-582261 PoCWordPress 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure Vulnerability
- CVE-2025-582461 PoCWordPress <= 6.8.2 - (Contributor+) Sensitive Data Exposure Vulnerability
- CVE-2025-583571 PoC5ire Chat Message XSS Vulnerability Enables Remote Code Execution
- CVE-2025-583581 PoCMarkdownify is vulnerable to command injection through pptx-to-markdown tool
- CVE-2025-583608 PoCsKEVGeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
- CVE-2025-583641 PoCcups: Remote DoS via null dereference
- CVE-2025-584302 PoCslistmonk Vulnerable to CSRF to XSS Chain That Can Lead to Admin Account Takeover
- CVE-2025-584311 PoCZimaOS reads arbitrary files using localhost calls to File API Download
- CVE-2025-584321 PoCZimaOS Privilege Escalation using localhost calls to File API Upload
- CVE-2025-5843418 PoCsFlowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
- CVE-2025-584433 PoCsFOG's authentication bypass leads to full SQL DB dump
- CVE-2025-584452 PoCsAtlantis Exposes Service Version Publicly on /status API Endpoint
- CVE-2025-584462 PoCsxgrammar vulnerable to denial of service by huge enum grammar
- CVE-2025-584491 PoCMaho Vulnerable to Authenticated Remote Code Execution via File Upload
- CVE-2025-584501 PoCpREST has Systemic SQL Injection Vulnerability
- CVE-2025-584521 PoCWeGIA vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint 'listar_despachos.php' parameter 'id_memorando'
- CVE-2025-584531 PoCWeGIA vulnerable to Blind Time-Based SQL Injection in endpoint 'exibe_anexo.php' parameter 'id_anexo'
- CVE-2025-584541 PoCWeGIA vulnerable to Blind Time-Based SQL Injection in endpoint 'listar_despachos.php' parameter 'id_memorando'
- CVE-2025-586741 PoCWordPress <= 6.8.2 - (Author+) Cross Site Scripting (XSS) Vulnerability
- CVE-2025-587261 PoCWindows SMB Server Elevation of Privilege Vulnerability
- CVE-2025-587451 PoCWeGIA has a bypass for the fix for CVE-2025-22133 - Arbitrary File Upload leads to Remote Code Execution (RCE)
- CVE-2025-587491 PoCWAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode
- CVE-2025-587514 PoCsVite middleware may serve files starting with the same name with the public directory
- CVE-2025-587522 PoCsVite's `server.fs` settings were not applied to HTML files
- CVE-2025-587542 PoCsAxios is vulnerable to DoS attack through lack of data size check
- CVE-2025-587561 PoCMONAI's unsafe torch usage may lead to arbitrary code execution
- CVE-2025-587571 PoCMONAI's unsafe use of Pickle deserialization may lead to RCE
- CVE-2025-587601 PoCTautulli vulnerable to Unauthenticated Path Traversal in `/image` endpoint
- CVE-2025-587611 PoCTautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`
- CVE-2025-587681 PoCDeepChat's Mermaid rendering has XSS leading to RCE