CVE-2025-61000 to CVE-2025-61999
32 CVEs with public proof-of-concept exploits.
- CVE-2025-611521 PoCpython-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature verification. A…
- CVE-2025-612241 PoCCross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q…
- CVE-2025-612281 PoCAn issue in Shirt Pocket SuperDuper! V.3.10 and before allows a local attacker to execute arbitrary code via the software update mechanism
- CVE-2025-612291 PoCAn issue in Shirt Pocket's SuperDuper! 3.10 and earlier allow a local attacker to modify the default task template to execute an arbitrary…
- CVE-2025-612351 PoCAn issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted, where some fields…
- CVE-2025-612461 PoCindieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.
- CVE-2025-612601 PoCA vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context…
- CVE-2025-613191 PoCReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a…
- CVE-2025-616221 PoCApache Fory, Apache Fory: Python RCE via unguarded pickle fallback serializer in pyfory
- CVE-2025-616381 PoCSanitizer::validateAttributes data-XSS
- CVE-2025-616661 PoCTraccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File
- CVE-2025-616751 PoCFreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters
- CVE-2025-616784 PoCsFreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand parameter
- CVE-2025-616851 PoCMastra Docs MCP Server `@mastra/mcp-docs-server` Leads to Information Exposure
- CVE-2025-616862 PoCsReact Router has Path Traversal in File Session Storage
- CVE-2025-616871 PoCFlowiseAI/Flosise has File Upload vulnerability
- CVE-2025-617573 PoCsKEVVulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are…
- CVE-2025-617651 PoCpython-socketio vulnerable to arbitrary Python code execution (RCE) through malicious pickle deserialization in certain multi-server…
- CVE-2025-617731 PoCpyLoad CNL and captcha handlers allow code Injection via unsanitized parameters
- CVE-2025-617841 PoCLLaMA Factory's Chat API has Critical SSRF and LFI Vulnerabilities
- CVE-2025-617851 PoCDeno's --deny-write check does not prevent permission bypass
- CVE-2025-617861 PoCDeno's --deny-read check does not prevent permission bypass
- CVE-2025-617871 PoCDeno is Vulnerable to Command Injection on Windows During Batch File Execution
- CVE-2025-6188210 PoCsKEVVulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported…
- CVE-2025-618841 PoCKEVVulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected…
- CVE-2025-619111 PoCpython-ldap has sanitization bypass in ldap.filter.escape_filter_chars
- CVE-2025-619121 PoCpython-ldap Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination
- CVE-2025-619131 PoCFlowise is vulnerable to arbitrary file read, arbitrary file write
- CVE-2025-619201 PoCAuthlib is vulnerable to Denial of Service via Oversized JOSE Segments
- CVE-2025-619221 PoCPrestaShop Checkout allows customer account takeover via email
- CVE-2025-619251 PoCAstro's `X-Forwarded-Host` is reflected with no validation
- CVE-2025-619842 PoCsssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially…