CVE-2025-66000 to CVE-2025-66999
69 CVEs with public proof-of-concept exploits.
- CVE-2025-660201 PoCValibot has a ReDoS vulnerability in `EMOJI_REGEX`
- CVE-2025-660211 PoCOWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
- CVE-2025-660347 PoCsfontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
- CVE-2025-660391 PoCFreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
- CVE-2025-660401 PoCSpotipy has a XSS vulnerability in OAuth callback server
- CVE-2025-661771 PoCThere is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an…
- CVE-2025-662191 PoCwillitmerge has a command Injection vulnerability
- CVE-2025-662211 PoCWerkzeug safe_join() allows Windows special device names
- CVE-2025-662241 PoCOrangeHRM is Vulnerable to Code Execution Through Arbitrary File Write from Sendmail Parameter Injection
- CVE-2025-662491 PoCApache Livy: Unauthorized directory access
- CVE-2025-662501 PoCUnauthenticated Arbitrary File Upload (status_contents.php)
- CVE-2025-662511 PoCUnauthenticated Path Traversal with Arbitrary File Deletion
- CVE-2025-662521 PoCInfinite Loop Denial of Service via Failed File Deletion
- CVE-2025-662531 PoCUnauthenticated OS Command Injection (start_upgrade.php)
- CVE-2025-662541 PoCUnauthenticated Arbitrary File Deletion (upgrade_contents.php)
- CVE-2025-662551 PoCUnauthenticated Arbitrary File Upload (upgrade_contents.php)
- CVE-2025-662561 PoCUnauthenticated Arbitrary File Upload (patch_contents.php)
- CVE-2025-662571 PoCUnauthenticated Arbitrary File Deletion (patch_contents.php)
- CVE-2025-662581 PoCStored Cross-Site Scripting via XML Injection
- CVE-2025-662591 PoCAuthenticated Root Remote Code Execution through improper filtering of HTTP post request parameters
- CVE-2025-662601 PoCPostgreSQL SQL Injection (status_sql.php)
- CVE-2025-662611 PoCUnauthenticated OS Command Injection (restore_settings.php)
- CVE-2025-662621 PoCArbitrary File Overwrite via Tar Extraction Path Traversal
- CVE-2025-662631 PoCUnauthenticated Arbitrary File Read via Null Byte Injection
- CVE-2025-662921 PoCDPanel has an arbitrary file deletion vulnerability in /api/common/attach/delete interface
- CVE-2025-662931 PoCLIBPNG has an out-of-bounds read in png_image_read_composite
- CVE-2025-662942 PoCsGrav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
- CVE-2025-662971 PoCGrav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
- CVE-2025-662991 PoCSecurity Sandbox Bypass with SSTI (Server Side Template Injection) in the Grav CMS
- CVE-2025-663001 PoCGrav is vulnerable to Arbitrary File Read
- CVE-2025-663012 PoCsGrav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
- CVE-2025-663021 PoCGrav vulnerable to Path Traversal allowing server files backup
- CVE-2025-663041 PoCGrav Exposes Password Hashes Leading to privilege escalation
- CVE-2025-663051 PoCGrav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter
- CVE-2025-663071 PoCGrav Admin Plugin vulnerable to User Enumeration & Email Disclosure
- CVE-2025-663081 PoCGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`
- CVE-2025-663091 PoCGrav vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in…
- CVE-2025-663101 PoCGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab
- CVE-2025-663111 PoCGrav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters
- CVE-2025-663121 PoCGrav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`
- CVE-2025-663911 PoCIn Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g.,…
- CVE-2025-663983 PoCsSignal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
- CVE-2025-664041 PoCmcp-server-kubernetes potential security issue in exec_in_pod tool
- CVE-2025-664101 PoCGin-vue-admin has an arbitrary file deletion vulnerability
- CVE-2025-664171 PoCGLPI has an unauthenticated SQL injection through the inventory endpoint
- CVE-2025-664541 PoCArcade MCP Default Hardcoded Worker Secret Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
- CVE-2025-664571 PoCElysia affected by arbitrary code injection through cookie config
- CVE-2025-664691 PoCNiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection
- CVE-2025-664701 PoCNiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG content
- CVE-2025-664721 PoCXWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication
- CVE-2025-664821 PoCMisskey has a login rate limit bypass via spoofed X-Forwarded-For header
- CVE-2025-664901 PoCTraefik doesn't Prevent Path Normalization Bypass in Router + Middleware Rules
- CVE-2025-665163 PoCsApache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
- CVE-2025-665551 PoCAirKeyboard iOS App 1.0.5 - Remote Input Injection
- CVE-2025-665711 PoCUNA CMS 9.0.0-RC1 - 14.0.0-RC4 PHP Object Injection
- CVE-2025-665721 PoCLoaded Commerce 6.6 Client-Side Template Injection (CSTI)
- CVE-2025-665731 PoCSolstice Pod API Session Key Extraction via API Endpoint
- CVE-2025-665741 PoCTranzAxis 3.2.41.10.26 - Stored Cross-Site Scripting (XSS)
- CVE-2025-665751 PoCVeeVPN 1.6.1 - Unquoted Service Path Remote Code Execution
- CVE-2025-665761 PoCRemote Keyboard Desktop 1.0.1 - Remote Code Execution (RCE)
- CVE-2025-666261 PoCargoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links
- CVE-2025-666451 PoCNiceGUI Path Traversal Vulnerability in app.add_media_files() Allows Arbitrary File Reading
- CVE-2025-666481 PoC`vega-functions` vulnerable to Cross-site Scripting via `setdata` function
- CVE-2025-666781 PoCAn issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to…
- CVE-2025-666801 PoCAn issue in the WiseDelfile64.sys component of WiseCleaner Wise Force Deleter 7.3.2 and earlier allows attackers to delete arbitrary files…
- CVE-2025-667441 PoCIn Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal,…
- CVE-2025-669021 PoCAn input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive information or cause…
- CVE-2025-669471 PoCSQL injection vulnerability in krishanmuraiji SMS v.1.0, within the /studentms/admin/edit-class-detail.php via the editid GET parameter.…
- CVE-2025-669541 PoCA vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid…