CVE-2025-67000 to CVE-2025-67999
34 CVEs with public proof-of-concept exploits.
- CVE-2025-670701 PoCA vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker to bypass the…
- CVE-2025-671111 PoCAn integer overflow in the RTPS protocol implementation of OpenDDS DDS before v3.33.0 allows attackers to cause a Denial of Service (DoS)…
- CVE-2025-671461 PoCMultiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)…
- CVE-2025-671471 PoCMultiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment'…
- CVE-2025-672231 PoCThe Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable…
- CVE-2025-672461 PoCA local information disclosure vulnerability exists in the Ludashi driver before 5.1025 due to a lack of access control in the IOCTL…
- CVE-2025-672891 PoCAn arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code…
- CVE-2025-673036 PoCsAn issue in ComfyUI-Manager prior to version 3.38 allowed remote attackers to potentially manipulate its configuration and critical data.…
- CVE-2025-673251 PoCUnrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to…
- CVE-2025-674451 PoCTOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of-service vulnerability in /cgi-bin/cstecgi.cgi. The CGI reads the…
- CVE-2025-674461 PoCImproper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a…
- CVE-2025-674471 PoCThe network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The…
- CVE-2025-674481 PoCThe SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize…
- CVE-2025-674871 PoCStatic Web Server is vulnerable to symbolic link Path Traversal
- CVE-2025-674881 PoCSiYuan: ZipSlip -> Arbitrary File Overwrite -> RCE
- CVE-2025-674891 PoC@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server
- CVE-2025-674941 PoCZITADEL Vulnerable to Unauthenticated Full-Read SSRF via V2 Login
- CVE-2025-675111 PoCCybersecurity AI (CAI) vulnerable to Command Injection in run_ssh_command_with_credentials Agent tool
- CVE-2025-675861 PoCWordPress Highlight and Share plugin <= 5.2.0 - Broken Access Control vulnerability
- CVE-2025-676441 PoCLangGraph SQLite Checkpoint is vulnerable to SQL Injection via metadata filter key in checkpointer list method
- CVE-2025-677121 PoCHTML injection issue in ArcGIS Web App Builder
- CVE-2025-677201 PoCPyrofork has a Path Traversal in download_media Method
- CVE-2025-677291 PoClmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()
- CVE-2025-677301 PoCFrappe authenticated users can execute XSS through form description fields
- CVE-2025-677331 PoCValkey Affected by RESP Protocol Injection via Lua error_reply
- CVE-2025-677351 PoCNetty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
- CVE-2025-677471 PoCFickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list
- CVE-2025-677481 PoCFickling has Code Injection vulnerability via pty.spawn()
- CVE-2025-677792 PoCsIt was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service…
- CVE-2025-677801 PoCSpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via unauthenticated LAN…
- CVE-2025-678861 PoCBitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can…
- CVE-2025-678872 PoCs1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can…
- CVE-2025-678881 PoCAn issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php…
- CVE-2025-679231 PoCWordPress JetEngine plugin <= 3.7.7 - Cross Site Scripting (XSS) vulnerability