CVE-2025-65000 to CVE-2025-65999
36 CVEs with public proof-of-concept exploits.
- CVE-2025-650071 PoCMissing Authentication for Critical Function in WODESYS WD-R608U router
- CVE-2025-650081 PoCOS Command Injection in WODESYS WD-R608U router
- CVE-2025-650091 PoCInsecure Password Storage in WODESYS WD-R608U router
- CVE-2025-650101 PoCMissing authorizations for admin panel password change in WODESYS WD-R608U router
- CVE-2025-650111 PoCUnauthorized Access to files in WODESYS WD-R608U router
- CVE-2025-650141 PoCLibreNMS has Weak Password Policy
- CVE-2025-650151 PoCjoserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
- CVE-2025-650182 PoCsLIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`
- CVE-2025-650191 PoCAstro Cloudflare adapter has a Stored Cross Site Scripting vulnerability in /_image endpoint
- CVE-2025-650261 PoCesm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
- CVE-2025-650271 PoCRomM Chained XSS and CSRF Vulnerabilities Enable Admin Account Takeover
- CVE-2025-650931 PoCLibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint
- CVE-2025-650981 PoCTypebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization Bypass
- CVE-2025-650991 PoCClaude Code vulnerable to command execution prior to startup trust dialog
- CVE-2025-651031 PoCOpenSTAManager has an authenticated SQL Injection vulnerability in API via 'display' parameter
- CVE-2025-651101 PoCVega Cross-Site Scripting (XSS) via expression abusing vlSelectionTuples function array map calls in environments with satisfactory…
- CVE-2025-651331 PoCA SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated…
- CVE-2025-651351 PoCIn manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in…
- CVE-2025-652641 PoCThe kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface, allowing an…
- CVE-2025-652711 PoCClient-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the…
- CVE-2025-653181 PoCWhen using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a…
- CVE-2025-653191 PoCWhen using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a…
- CVE-2025-653461 PoCalexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows…
- CVE-2025-653541 PoCImproper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injection via the…
- CVE-2025-654821 PoCAn XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via…
- CVE-2025-656371 PoCA denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line payload larger than…
- CVE-2025-657531 PoCAn issue in the TLS certification mechanism of Guardian Gryphon v01.06.0006.22 allows attackers to execute commands as root.
- CVE-2025-657541 PoCCross Site Scripting vulnerability in Algernon v1.17.4 allows attackers to execute arbitrary code via injecting a crafted payload into a…
- CVE-2025-657901 PoCA reflected cross-site scripting (XSS) vulnerability exists in FuguHub 8.1 when serving SVG files through the /fs/ file manager interface.…
- CVE-2025-658561 PoCAuthentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows…
- CVE-2025-658581 PoCA Stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 allows attackers to inject malicious JavaScript into the…
- CVE-2025-658651 PoCAn integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- CVE-2025-658991 PoCKalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application returns different…
- CVE-2025-659451 PoCauth0/node-jws improper HMAC signature verification vulnerability
- CVE-2025-659581 PoCOpen WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web
- CVE-2025-659642 PoCsn8n Vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook