CVE-2025-59000 to CVE-2025-59999
57 CVEs with public proof-of-concept exploits.
- CVE-2025-590461 PoCinteractive-git-checkout has Command Injection vulnerability
- CVE-2025-590492 PoCsMockoon has a Path Traversal and LFI in the static file serving endpoint
- CVE-2025-590501 PoCGreenshot — Insecure .NET deserialization via WM_COPYDATA enables local code execution
- CVE-2025-590551 PoCInstantCMS vulnerable to Server-Side Request Forgery via package installer
- CVE-2025-590571 PoCReact Router has XSS Vulnerability
- CVE-2025-591361 PoCWordPress Gerencianet Oficial plugin <= 3.1.3 - Sensitive Data Exposure vulnerability
- CVE-2025-591521 PoCX-Forwarded-For Header Spoofing Bypasses Litestar Rate Limiting
- CVE-2025-591591 PoCSillyTavern Web Interface Vulnerable to DNS Rebinding
- CVE-2025-591941 PoCWindows Kernel Elevation of Privilege Vulnerability
- CVE-2025-592131 PoCConfiguration Manager Elevation of Privilege Vulnerability
- CVE-2025-592141 PoCMicrosoft Windows File Explorer Spoofing Vulnerability
- CVE-2025-592541 PoCMicrosoft DWM Core Library Elevation of Privilege Vulnerability
- CVE-2025-592841 PoCWindows NTLM Spoofing Vulnerability
- CVE-2025-5928721 PoCsKEVWindows Server Update Service (WSUS) Remote Code Execution Vulnerability
- CVE-2025-592881 PoCPlaywright Spoofing Vulnerability
- CVE-2025-593331 PoC@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode
- CVE-2025-593412 PoCsLocal File Inclusion in esm.sh
- CVE-2025-593424 PoCsesm.sh writes arbitrary files via path traversal in `X-Zone-Id` header
- CVE-2025-593591 PoCOS command injection in Chaos Mesh via the cleanTcs mutation
- CVE-2025-593821 PoCQTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)
- CVE-2025-593901 PoCApache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly.
- CVE-2025-594172 PoCsLobe Chat Desktop Vulnerable to Remote Code Execution via XSS in Chat Messages
- CVE-2025-594191 PoCNetty netty-codec-smtp SMTP Command Injection Vulnerability Allowing Email Forgery
- CVE-2025-594201 PoCAuthlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)
- CVE-2025-594242 PoCsLinkAce Vulnerable to Stored XSS on the Audit Page
- CVE-2025-594261 PoClobe-chat has an Open Redirect
- CVE-2025-594271 PoCCloudflare vite plugin exposes secrets over the built-in dev server
- CVE-2025-594301 PoCMesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
- CVE-2025-594311 PoCMapServer - WFS XML Filter Query SQL injection
- CVE-2025-594331 PoC@conventional-changelog/git-client has an Argument Injection vulnerability
- CVE-2025-594701 PoCThis vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or…
- CVE-2025-594741 PoCJenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intentionally accessible…
- CVE-2025-594891 PoCUnity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code…
- CVE-2025-595011 PoCMicrosoft Configuration Manager Spoofing Vulnerability
- CVE-2025-595261 PoCMailgen: HTML injection vulnerability in plaintext e-mails
- CVE-2025-595271 PoCFlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
- CVE-2025-5952823 PoCsFlowise has Remote Code Execution vulnerability
- CVE-2025-595311 PoCUnauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload
- CVE-2025-595363 PoCsClaude Code's startup trust dialog could lead to Command Execution attack
- CVE-2025-595371 PoCargo-cd is vulnerable to unauthenticated DoS attack via malformed Gogs webhook payload
- CVE-2025-595381 PoCArgo CD is Vulnerable to Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook
- CVE-2025-595821 PoCWordPress Ajax Load More Plugin <= 7.6.0.2 - Sensitive Data Exposure Vulnerability
- CVE-2025-597121 PoCSnipe-IT before 8.1.18 allows XSS.
- CVE-2025-597131 PoCSnipe-IT before 8.1.18 allows unsafe deserialization.
- CVE-2025-597161 PoCownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of…
- CVE-2025-597182 PoCsKEVA improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8,…
- CVE-2025-597192 PoCsAn improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0…
- CVE-2025-598221 PoCHttp4s vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer section
- CVE-2025-598311 PoC`git-comiters` Command Injection vulnerability
- CVE-2025-598361 PoCOmni is Vulnerable to DoS via Empty Create/Update Resource Requests
- CVE-2025-598391 PoCStar Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
- CVE-2025-598401 PoCVega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global variable
- CVE-2025-598431 PoCFlagForgeCTF Exposes User Emails via Public /api/user/[username] API
- CVE-2025-598861 PoCImproper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access…
- CVE-2025-599321 PoCFlagForgeCTF Unauthenticated Resource Modification/Deletion
- CVE-2025-599341 PoCFormbricks missing JWT signature verification
- CVE-2025-599361 PoCget-jwks poisoned JWKS cache allows post-fetch issuer validation bypass