CVE-2025-64000 to CVE-2025-64999
41 CVEs with public proof-of-concept exploits.
- CVE-2025-640811 PoCSQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows…
- CVE-2025-640871 PoCA Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport v1.0.0 to v2.1.0 allows…
- CVE-2025-640954 PoCsDNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
- CVE-2025-641041 PoCLangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
- CVE-2025-641111 PoCGogs's update .git/config file allows remote command execution
- CVE-2025-641181 PoCnode-tar vulnerable to race condition leading to uninitialized memory exposure
- CVE-2025-641553 PoCsAn improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0,…
- CVE-2025-641661 PoCMercurius: Incorrect Content-Type parsing can lead to CSRF attack
- CVE-2025-641741 PoCOpenMage is vulnerable to XSS in Admin Notifications
- CVE-2025-641811 PoCOpenEXR Makes Use of Uninitialized Memory
- CVE-2025-643241 PoCKubeVirt Vulnerable to Arbitrary Host File Read and Write
- CVE-2025-643282 PoCsKEVFreePBX Administration GUI is Vulnerable to Authenticated Command Injection
- CVE-2025-643401 PoCFastMCP has a Command Injection vulnerability - Gemini CLI
- CVE-2025-644241 PoCColify has command injection vulnerability in project git source
- CVE-2025-644301 PoCParse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI Format
- CVE-2025-644331 PoCKubeVirt Arbitrary Container File Read
- CVE-2025-644341 PoCKubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
- CVE-2025-644351 PoCKubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation
- CVE-2025-644361 PoCKubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
- CVE-2025-644371 PoCKubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes
- CVE-2025-644391 PoCLangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
- CVE-2025-6444615 PoCsKEVA relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through…
- CVE-2025-644581 PoCPotential denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
- CVE-2025-644597 PoCsPotential SQL injection via _connector keyword argument in QuerySet and Q objects
- CVE-2025-644951 PoCOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
- CVE-2025-644961 PoCOpen WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
- CVE-2025-645001 PoCSymfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
- CVE-2025-6451210 PoCspdfminer.six vulnerable to Arbitrary Code Execution via Crafted PDF Input
- CVE-2025-645161 PoCGLPI incorrectly authorizes access to documents
- CVE-2025-645191 PoCTorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
- CVE-2025-645221 PoCSoft Serve is vulnerable to SSRF through its Webhooks
- CVE-2025-645231 PoCFileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion Function
- CVE-2025-645252 PoCsAstro: URL manipulation via unsanitized headers leads to path-based middleware protections bypass, potential SSRF/cache-poisoning,…
- CVE-2025-647111 PoCPrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for users
- CVE-2025-647141 PoCPrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal
- CVE-2025-647201 PoCLIBPNG is vulnerable to a buffer overflow in `png_image_read_composite` via incorrect palette premultiplication
- CVE-2025-647451 PoCAstro development server error page vulnerable to reflected Cross-site Scripting
- CVE-2025-647561 PoCglob CLI: Command injection via -c/--cmd executes matches with shell:true
- CVE-2025-647571 PoCAstro Development Server is Vulnerable to Arbitrary Local File Read
- CVE-2025-647641 PoCAstro is vulnerable to Reflected XSS via the server islands feature
- CVE-2025-647671 PoChpke-js reuses AEAD nonces