CVE-2025-69000 to CVE-2025-69999
33 CVEs with public proof-of-concept exploits.
- CVE-2025-690801 PoCWordPress Gecko theme <= 1.9.8 - Local File Inclusion vulnerability
- CVE-2025-691941 PoCWget2: arbitrary file write via metalink path traversal in gnu wget2
- CVE-2025-691961 PoCFastMCP OAuth Proxy token reuse across MCP servers
- CVE-2025-692002 PoCsphpMyFAQ has unauthenticated config backup download via /api/setup/backup
- CVE-2025-692031 PoCSignal K Server Vulnerable to Access Request Spoofing
- CVE-2025-692061 PoCHemmelig has SSRF Filter bypass in Secret Request functionality
- CVE-2025-692071 PoCKhoj has an IDOR in Notion OAuth Flow Enables Index Poisoning
- CVE-2025-692101 PoCFacturaScripts vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
- CVE-2025-6921211 PoCsOpenSTAManager has an OS Command Injection in P7M File Processing
- CVE-2025-692131 PoCOpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)
- CVE-2025-692141 PoCOpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)
- CVE-2025-692151 PoCOpenSTAManager has an SQL Injection in the Stampe Module
- CVE-2025-692161 PoCOpenSTAManager has an SQL Injection in Scadenzario Print Template
- CVE-2025-692192 PoCsApache Airflow Providers Http: Unsafe Pickle Deserialization in apache-airflow-providers-http leading to RCE via HttpOperator
- CVE-2025-692551 PoCRustFS gRPC GetMetrics deserialization panic enables remote DoS
- CVE-2025-692561 PoCserverless MCP Server vulnerable to command injection in list-projects tool
- CVE-2025-692621 PoCpnpm vulnerable to Command Injection via environment variable substitution
- CVE-2025-692631 PoCpnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependencies
- CVE-2025-692641 PoCpnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
- CVE-2025-692871 PoCBSV Blockchain SDK has an Authentication Signature Data Preparation Vulnerability
- CVE-2025-694111 PoCWordPress ionCube tester plus plugin <= 1.3 - Arbitrary File Download vulnerability
- CVE-2025-694191 PoCOut of bounds write in PKCS12_get_friendlyname() UTF-8 conversion
- CVE-2025-694201 PoCMissing ASN1_TYPE validation in TS_RESP_verify_response() function
- CVE-2025-694211 PoCNULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function
- CVE-2025-695151 PoCAn issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting…
- CVE-2025-695162 PoCsA Server-Side Template Injection (SSTI) vulnerability in the /reporting/templates/preview/ endpoint of Amidaware Tactical RMM, affecting…
- CVE-2025-696001 PoCCommand injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via…
- CVE-2025-696041 PoCAn issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary…
- CVE-2025-696121 PoCA path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software. The "Download…
- CVE-2025-697251 PoCAn Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to…
- CVE-2025-699711 PoCFUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-coded secret key to…
- CVE-2025-699853 PoCsFUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in…
- CVE-2025-699931 PoCLeaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders…