CVE-2025-63000 to CVE-2025-63999
20 CVEs with public proof-of-concept exploits.
- CVE-2025-632131 PoCThe QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to improper input…
- CVE-2025-633071 PoCalexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create,…
- CVE-2025-633534 PoCsA vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be…
- CVE-2025-633871 PoCDify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the…
- CVE-2025-634063 PoCsAn issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the…
- CVE-2025-634082 PoCsLocal Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access…
- CVE-2025-634191 PoCCross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the…
- CVE-2025-634201 PoCCrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling…
- CVE-2025-634991 PoCAlinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.
- CVE-2025-636011 PoCSnipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious…
- CVE-2025-636021 PoCA vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MSRs (such as LSTAR)…
- CVE-2025-636081 PoCA SQL injection vulnerability exists in CSZ-CMS <=1.3.0 in the Form Builder view functionality. The vulnerability is located in the field…
- CVE-2025-636471 PoCA NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attackers to cause a…
- CVE-2025-637081 PoCCross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows remote attackers to…
- CVE-2025-637291 PoCAn issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA…
- CVE-2025-638881 PoCThe read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code execution vulnerability.
- CVE-2025-638921 PoCA vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the…
- CVE-2025-638951 PoCAn issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service…
- CVE-2025-638961 PoCAn issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to…
- CVE-2025-639131 PoCAn issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the…