CVE-2025-70000 to CVE-2025-70999
22 CVEs with public proof-of-concept exploits.
- CVE-2025-702981 PoCGPAC v2.4.0 was discovered to contain an out-of-bounds read in the oggdmx_parse_tags function.
- CVE-2025-702991 PoCA heap overflow in the avi_parse_input_file() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2025-703021 PoCA heap overflow in the ghi_dmx_declare_opid_bin() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2025-703031 PoCA heap overflow in the uncv_parse_config() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted MP4…
- CVE-2025-703041 PoCA buffer overflow in the vobsub_get_subpic_duration() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a…
- CVE-2025-703051 PoCA stack overflow in the dmx_saf function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .saf file.
- CVE-2025-703071 PoCA stack overflow in the dump_ttxt_sample function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted packet.
- CVE-2025-703081 PoCAn out-of-bounds read in the GSF demuxer filter component of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2025-703091 PoCA stack overflow in the pcmreframe_flush_packet function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted…
- CVE-2025-703101 PoCA heap overflow in the vorbis_to_intern() function of GPAC v2.4.0 allows attackers to cause a Denial of Service (DoS) via a crafted .ogg…
- CVE-2025-703301 PoCEasy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific…
- CVE-2025-703361 PoCA Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject…
- CVE-2025-703421 PoCerase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an…
- CVE-2025-703681 PoCWorklenz version 2.1.5 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Project Updates feature. An attacker can submit a…
- CVE-2025-705592 PoCspdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python…
- CVE-2025-707951 PoCSTProcessMonitor 11.11.4.0, part of the Safetica Application suite, allows an admin-privileged user to send crafted IOCTL requests to…
- CVE-2025-708491 PoCArbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the…
- CVE-2025-708862 PoCsAn issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment…
- CVE-2025-708991 PoCPHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can…
- CVE-2025-709581 PoCMultiple reflected cross-site scripting (XSS) vulnerabilities in the installation module of Subrion CMS v4.2.1 allows attackers to execute…
- CVE-2025-709621 PoCZosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP…
- CVE-2025-709741 PoCFastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a…