CVE-2025-60000 to CVE-2025-60999
40 CVEs with public proof-of-concept exploits.
- CVE-2025-600121 PoCApache Livy: Restrict file access
- CVE-2025-600131 PoCF5OS-A FIPS HSM password vulnerability
- CVE-2025-600171 PoCUnitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass…
- CVE-2025-600211 PoCApache bRPC: Remote command injection vulnerability in heap builtin service
- CVE-2025-601883 PoCsWordPress Atarim plugin <= 4.2.1 - Sensitive Data Exposure vulnerability
- CVE-2025-602501 PoCUnitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554124a key and the…
- CVE-2025-602511 PoCUnitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring.
- CVE-2025-603311 PoCD-Link DIR-823G A1 v1.0.2B05 was discovered to contain a buffer overflow in the FillMacCloneMac parameter in the /EXCU_SHELL endpoint.…
- CVE-2025-603321 PoCA NULL pointer dereference in the SetWLanRadioSettings function of D-Link DIR-823G A1 v1.0.2B05 allows attackers to cause a Denial of…
- CVE-2025-603331 PoCTOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the wepkey2 parameter in the setWiFiMultipleConfig…
- CVE-2025-603341 PoCTOTOLINK N600R v4.3.0cu.7866_B20220506 was discovered to contain a stack overflow in the ssid parameter in the setWiFiBasicConfig…
- CVE-2025-603351 PoCA NULL pointer dereference in the main function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of Service…
- CVE-2025-603361 PoCA NULL pointer dereference in the sub_41773C function of TOTOLINK N600R v4.3.0cu.7866_B20220506 allows attackers to cause a Denial of…
- CVE-2025-603371 PoCTenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This…
- CVE-2025-603381 PoCTenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the DhcpListClient function. This…
- CVE-2025-603391 PoCMultiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of…
- CVE-2025-603401 PoCMultiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS)…
- CVE-2025-603411 PoCTenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the ssid parameter in the fast_setting_wifi_set function. This…
- CVE-2025-603421 PoCTenda AC6 V2.0 15.03.06.50 was discovered to contain a stack overflow in the page parameter in the addressNat function. This vulnerability…
- CVE-2025-603431 PoCMultiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS)…
- CVE-2025-603491 PoCAn issue was discovered in Prevx v3.0.5.220 allowing attackers to cause a denial of service via sending IOCTL code 0x22E044 to the…
- CVE-2025-603571 PoCAhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.
- CVE-2025-604581 PoCUxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger…
- CVE-2025-605001 PoCQDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type…
- CVE-2025-605111 PoCMoodle OpenAI Chat Block plugin 3.0.1 (2025021700) suffers from an Insecure Direct Object Reference (IDOR) vulnerability due to…
- CVE-2025-605741 PoCA Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which…
- CVE-2025-606891 PoCAn unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers…
- CVE-2025-606901 PoCA stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware…
- CVE-2025-607091 PoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2025-607102 PoCsKEVHost Process for Windows Tasks Elevation of Privilege Vulnerability
- CVE-2025-607191 PoCWindows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2025-607371 PoCCross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_07_21 allows a…
- CVE-2025-607381 PoCAn issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote…
- CVE-2025-607491 PoCDLL Hijacking vulnerability in Trimble SketchUp desktop 2025 via crafted libcef.dll used by sketchup_webhelper.exe.
- CVE-2025-607513 PoCsGeographicLib 2.5 is vulnerable to Buffer Overflow in GeoConvert DMS::InternalDecode.
- CVE-2025-6078710 PoCsMotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user…
- CVE-2025-608521 PoCA CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built with affected…
- CVE-2025-608541 PoCA vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change…
- CVE-2025-608761 PoCBusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the…
- CVE-2025-608981 PoCAn unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 allows a remote…