CVE-2025-62000 to CVE-2025-62999
52 CVEs with public proof-of-concept exploits.
- CVE-2025-620391 PoCWordPress AI ChatBot with ChatGPT and Content Generator by AYS plugin <= 2.6.6 - Sensitive Data Exposure vulnerability
- CVE-2025-621261 PoCWordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Sensitive Data Exposure vulnerability
- CVE-2025-621561 PoCargo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite
- CVE-2025-621621 PoCcel-rust May Panic During Parsing of Invalid CEL Expressions
- CVE-2025-621684 PoCsSquid vulnerable to information disclosure via authentication credential leakage in error handling
- CVE-2025-621711 PoCImageMagick vulnerable to denial of service via integer overflow in BMP decoder on 32-bit systems
- CVE-2025-621721 PoCHome Assistant vulnerable to Stored XSS in Energy dashboard from Energy Entity Name
- CVE-2025-622156 PoCsKEVWindows Kernel Elevation of Privilege Vulnerability
- CVE-2025-622211 PoCKEVWindows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2025-622221 PoCAgentic AI and Visual Studio Code Remote Code Execution Vulnerability
- CVE-2025-623601 PoCWeGIA SQL Injection via 'id_dependente' param at endpoint `/html/funcionario/dependente_documento.php`
- CVE-2025-623661 PoCMailgen vulnerable to HTML injection and cross-site scripting via plaintext email generation
- CVE-2025-623681 PoCTaiga Authenticated Remote Code Execution
- CVE-2025-623691 PoCXibo CMS: Remote Code Execution through module templates
- CVE-2025-623731 PoCPipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSerializer
- CVE-2025-623791 PoCOpen Redirect in reflex-dev/reflex
- CVE-2025-623801 PoCMailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails
- CVE-2025-623811 PoCsveltekit-superforms Prototype Pollution in `parseFormData` function of `formData.js`
- CVE-2025-624101 PoC--disallow-code-generation-from-strings is not sufficient for isolating untrusted JavaScript in happy-dom
- CVE-2025-624111 PoCStored XSS in Alert Transport name field in LibreNMS
- CVE-2025-624291 PoCClipBucket v5 executes arbitrary PHP code
- CVE-2025-624541 PoCWindows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
- CVE-2025-624701 PoCWindows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2025-625051 PoCSSRF in lobehub/lobe-chat with native web fetch module
- CVE-2025-625061 PoCMinIO vulnerable to privilege escalation via session policy bypass in service accounts and STS
- CVE-2025-625073 PoCsRedis: Bug in XACKDEL may lead to stack overflow and potential RCE
- CVE-2025-625121 PoCPiwigo Vulnerable to User Enumeration via Password Reset Endpoint
- CVE-2025-625152 PoCsRemote Code Execution by Pickle Deserialization via FlightServer in pyquokka
- CVE-2025-625181 PoCastral-tokio-tar Vulnerable to PAX Header Desynchronization
- CVE-2025-625191 PoCphpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
- CVE-2025-625211 PoCChurchCRM has unauthenticated RCE in its Install Wizard
- CVE-2025-625222 PoCsvite allows server.fs.deny bypass via backslash on Windows
- CVE-2025-625271 PoCTaguette vulnerable to password reset link poisoning
- CVE-2025-625932 PoCsKEVRay is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
- CVE-2025-625941 PoCImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)
- CVE-2025-625951 PoCKoa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
- CVE-2025-626081 PoCMLX has heap-buffer-overflow in load()
- CVE-2025-626111 PoCaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
- CVE-2025-626131 PoCVDO.Ninja Reflected XSS Vulnerability in control.html
- CVE-2025-626171 PoCAdmidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality
- CVE-2025-626411 PoCVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are…
- CVE-2025-626761 PoCAn Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows…
- CVE-2025-627061 PoCAuthlib : JWE zip=DEF decompression bomb enables DoS
- CVE-2025-627181 PoCAxios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF
- CVE-2025-627272 PoCsStarlette vulnerable to O(n^2) DoS via Range header merging in starlette.responses.FileResponse
- CVE-2025-627802 PoCschangedetection.io vulnerable to stored XSS in Watch update via API
- CVE-2025-627961 PoCPrivateBin persistent HTML injection in attachment filename enables redirect and defacement
- CVE-2025-628001 PoCFastMCP vulnerable to reflected XSS in client's callback page
- CVE-2025-628011 PoCFastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
- CVE-2025-628751 PoCLocal DoS in OpenSMTPD via UNIX domain socket smtpd.sock
- CVE-2025-628781 PoCLocal Path Provisioner vulnerable to Path Traversal via parameters.pathPattern
- CVE-2025-629501 PoCWordPress Contest Gallery plugin <= 28.0.0 - Cross Site Request Forgery (CSRF) vulnerability