CVE-2025-68000 to CVE-2025-68999
50 CVEs with public proof-of-concept exploits.
- CVE-2025-680012 PoCsWordPress g-FFL Checkout plugin <= 2.1.0 - Arbitrary File Upload vulnerability
- CVE-2025-680431 PoCWordPress LottieFiles plugin <= 3.0.0 - Broken Access Control vulnerability
- CVE-2025-680551 PoCWordPress Hydra Booking plugin <= 1.1.32 - SQL Injection vulnerability
- CVE-2025-681091 PoCChurchCRM vulnerable to RCE with database restore functionality
- CVE-2025-681161 PoCFileRise vulnerable to Cross-Site Scripting (XSS) in SVG File Handling
- CVE-2025-681371 PoCEVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loop
- CVE-2025-681431 PoCmcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations
- CVE-2025-681541 PoCCommand Injection in fsSize() on Windows
- CVE-2025-681551 PoC@vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on Development
- CVE-2025-682721 PoCSignal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding
- CVE-2025-682731 PoCSignal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints
- CVE-2025-682781 PoCtinacms vulnerable to arbitrary code execution
- CVE-2025-683251 PoCnet/sched: sch_cake: Fix incorrect qlen reduction in cake_drop
- CVE-2025-684282 PoCsjsPDF has Local File Inclusion/Path Traversal vulnerability
- CVE-2025-684371 PoCCraft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
- CVE-2025-684551 PoCCraft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
- CVE-2025-684722 PoCsMindsDB has improper sanitation of filepath that leads to information disclosure and DOS
- CVE-2025-684751 PoCFedify has ReDoS Vulnerability in HTML Parsing Regex
- CVE-2025-684771 PoCLangflow vulnerable to Server-Side Request Forgery
- CVE-2025-684781 PoCLangflow Vulnerable to External Control of File Name or Path
- CVE-2025-684933 PoCsApache Struts, Apache Struts: XXE vulnerability in outdated XWork component
- CVE-2025-685091 PoCWordPress User Submitted Posts plugin <= 20251121 - Open Redirection vulnerability
- CVE-2025-686021 PoCWordPress Accept Donations with PayPal plugin <= 1.5.2 - Open Redirection vulnerability
- CVE-2025-6861336 PoCsKEVn8n Vulnerable to Remote Code Execution via Expression Injection
- CVE-2025-686141 PoCLibreNMS Alert Rule API Cross-Site Scripting Vulnerability
- CVE-2025-686152 PoCsNet-SNMP snmptrapd crash
- CVE-2025-686161 PoCWeasyPrint Vulnerable to Server-Side Request Forgery (SSRF) Protection Bypass via HTTP Redirect
- CVE-2025-686181 PoCMagick's failure to limit the depth of SVG file reads caused a DoS attack.
- CVE-2025-686191 PoCSignal K Server Vulnerable to Remote Code Execution via Malicious npm Package
- CVE-2025-686201 PoCSignal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling
- CVE-2025-686211 PoCTrilium Notes has a Timing Attack Vulnerability in /api/login/sync
- CVE-2025-686458 PoCsKEVA Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of…
- CVE-2025-686644 PoCsLangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
- CVE-2025-686651 PoCLangChain serialization injection vulnerability enables secret extraction
- CVE-2025-686684 PoCsn8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
- CVE-2025-686961 PoChttparty Has Potential SSRF Vulnerability That Leads to API Key Leakage
- CVE-2025-687051 PoCRustFS Path Traversal Vulnerability
- CVE-2025-687131 PoCAn issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability…
- CVE-2025-687211 PoCAxigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account…
- CVE-2025-687221 PoCAxigen Mail Server before 10.5.57 and 10.6.x before 10.6.26 contains a Cross-Site Request Forgery (CSRF) vulnerability in the WebAdmin…
- CVE-2025-687231 PoCAxigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three…
- CVE-2025-688602 PoCsWordPress Mobile builder plugin <= 1.4.2 - Broken Authentication vulnerability
- CVE-2025-689213 PoCsSteelSeries Nahimic 3 1.10.7 allows Directory traversal.
- CVE-2025-689265 PoCsRustFS has a gRPC Hardcoded Token Authentication Bypass
- CVE-2025-689271 PoCImproper Neutralization of HTML Tags in a Web Page in libredesk
- CVE-2025-689301 PoCTraccar Missing Origin Validation in WebSockets
- CVE-2025-689371 PoCForgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of…
- CVE-2025-689472 PoCsNSecsoft NSecKrnl process termination privilege escalation
- CVE-2025-689511 PoCphpMyFAQ has stored XSS in admin "List of users" via display_name HTML entity decoding (html_entity_decode) + Twig |raw
- CVE-2025-689992 PoCsWordPress Happy Addons for Elementor plugin <= 3.20.4 - SQL Injection vulnerability