CVE-2025-7000 to CVE-2025-7999
469 CVEs with public proof-of-concept exploits.
- CVE-2025-70001 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2025-70011 PoCInsufficient Granularity of Access Control in GitLab
- CVE-2025-70211 PoCOpenAI Operator - API Spoofing through Locking Operator on FullScreen
- CVE-2025-70221 PoCMy Reservation System <= 2.3 - Reflected XSS
- CVE-2025-70672 PoCsHDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflow
- CVE-2025-70682 PoCsHDF5 H5FL.c H5FL__malloc memory leak
- CVE-2025-70692 PoCsHDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow
- CVE-2025-70741 PoCvercel hyper rimraf-standalone.js ignoreMap redos
- CVE-2025-70751 PoCBlackVue Dashcam 590X HTTP Endpoint upload.cgi unrestricted upload
- CVE-2025-70761 PoCBlackVue Dashcam 590X Configuration upload.cgi access control
- CVE-2025-70771 PoCShenzhen Libituo Technology LBT-T300-T310 appy.cgi config_3g_para buffer overflow
- CVE-2025-70781 PoC07FLYCMS/07FLY-CMS/07FlyCRM cross-site request forgery
- CVE-2025-70791 PoCmao888 bluebell-plus JWT Token jwt.go hard-coded password
- CVE-2025-70801 PoCDone-0 Jank JWT Token jwt_utils.go hard-coded password
- CVE-2025-70811 PoCBelkin F9K1122 webs formSetWanStatic os command injection
- CVE-2025-70821 PoCBelkin F9K1122 webs formBSSetSitesurvey os command injection
- CVE-2025-70831 PoCBelkin F9K1122 webs mp os command injection
- CVE-2025-70841 PoCBelkin F9K1122 webs formWpsStart stack-based overflow
- CVE-2025-70851 PoCBelkin F9K1122 webs formiNICWpsStart stack-based overflow
- CVE-2025-70861 PoCBelkin F9K1122 webs formPPTPSetup stack-based overflow
- CVE-2025-70871 PoCBelkin F9K1122 webs formL2TPSetup stack-based overflow
- CVE-2025-70881 PoCBelkin F9K1122 webs formPPPoESetup stack-based overflow
- CVE-2025-70891 PoCBelkin F9K1122 webs formWanTcpipSetup stack-based overflow
- CVE-2025-70901 PoCBelkin F9K1122 webs formConnectionSetting stack-based overflow
- CVE-2025-70911 PoCBelkin F9K1122 webs formWlanMP stack-based overflow
- CVE-2025-70921 PoCBelkin F9K1122 webs formWlanSetupWPS stack-based overflow
- CVE-2025-70931 PoCBelkin F9K1122 webs formSetLanguage stack-based overflow
- CVE-2025-70941 PoCBelkin F9K1122 webs formBSSetSitesurvey stack-based overflow
- CVE-2025-70952 PoCsComodo Internet Security Premium Update certificate validation
- CVE-2025-70962 PoCsComodo Internet Security Premium Manifest File cis_update_x64.xml integrity check
- CVE-2025-70973 PoCsComodo Internet Security Premium Manifest File cis_update_x64.xml os command injection
- CVE-2025-70983 PoCsComodo Internet Security Premium File Name path traversal
- CVE-2025-70991 PoCBoyunCMS Installation install2.php deserialization
- CVE-2025-71001 PoCBoyunCMS Index.php unrestricted upload
- CVE-2025-71011 PoCBoyunCMS Configuration File install_ok.php code injection
- CVE-2025-71022 PoCsBoyunCMS Server.php sql injection
- CVE-2025-71031 PoCBoyunCMS curl Index.php server-side request forgery
- CVE-2025-71071 PoCSimStudioAI sim route.ts handleLocalFile path traversal
- CVE-2025-71081 PoCrisesoft-y9 Digital-Infrastructure Y9FileController.java deleteFile path traversal
- CVE-2025-71091 PoCPortabilis i-Educar Student Benefits Registration educar_aluno_beneficio_lst.php cross site scripting
- CVE-2025-71101 PoCPortabilis i-Educar School Module educar_escola_lst.php cross site scripting
- CVE-2025-71111 PoCPortabilis i-Educar Course Module educar_curso_det.php cross site scripting
- CVE-2025-71121 PoCPortabilis i-Educar Function Management Module educar_funcao_det.php cross site scripting
- CVE-2025-71131 PoCPortabilis i-Educar Curricular Components Module edit cross site scripting
- CVE-2025-71141 PoCSimStudioAI sim Session route.ts POST missing authentication
- CVE-2025-71161 PoCUTT 进取 750W Fast_wireless_conf buffer overflow
- CVE-2025-71171 PoCUTT HiPER 840G websWhiteList buffer overflow
- CVE-2025-71181 PoCUTT HiPER 840G formPictureUrl buffer overflow
- CVE-2025-71191 PoCCampcodes Complaint Management System index.php sql injection
- CVE-2025-71201 PoCCampcodes Complaint Management System check_availability.php sql injection
- CVE-2025-71211 PoCCampcodes Complaint Management System complaint-details.php sql injection
- CVE-2025-71221 PoCCampcodes Complaint Management System index.php sql injection
- CVE-2025-71231 PoCCampcodes Complaint Management System complaint-details.php sql injection
- CVE-2025-71241 PoCcode-projects Online Note Sharing Profile Image userprofile.php unrestricted upload
- CVE-2025-71251 PoCitsourcecode Employee Management System editempeducation.php sql injection
- CVE-2025-71261 PoCitsourcecode Employee Management System adminprofile.php sql injection
- CVE-2025-71271 PoCitsourcecode Employee Management System changepassword.php sql injection
- CVE-2025-71281 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-71291 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-71301 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-71311 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-71321 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-71331 PoCCodeAstro Online Movie Ticket Booking System cross-site request forgery
- CVE-2025-71341 PoCCampcodes Online Recruitment Management System ajax.php sql injection
- CVE-2025-71351 PoCCampcodes Online Recruitment Management System ajax.php sql injection
- CVE-2025-71361 PoCCampcodes Online Recruitment Management System view_vacancy.php sql injection
- CVE-2025-71371 PoCSourceCodester Best Salon Management System schedule-staff.php sql injection
- CVE-2025-71381 PoCSourceCodester Best Salon Management System admin-profile.php sql injection
- CVE-2025-71391 PoCSourceCodester Best Salon Management System Update Customer Details Page edit-customer-detailed.php cross site scripting
- CVE-2025-71401 PoCSourceCodester Best Salon Management System Update Staff Page edit-staff.php cross site scripting
- CVE-2025-71411 PoCSourceCodester Best Salon Management System Update Staff Page edit_plan.php cross site scripting
- CVE-2025-71421 PoCSourceCodester Best Salon Management System search-appointment.php cross site scripting
- CVE-2025-71431 PoCSourceCodester Best Salon Management System Update Tax Page edit-tax.php cross site scripting
- CVE-2025-71441 PoCSourceCodester Best Salon Management System Admin Profile Page admin-profile.php cross site scripting
- CVE-2025-71471 PoCCodeAstro Patient Record Management System login.php sql injection
- CVE-2025-71481 PoCCodeAstro Simple Hospital Management System POST Parameter patient.html cross site scripting
- CVE-2025-71491 PoCCampcodes Advanced Online Voting System candidates_delete.php sql injection
- CVE-2025-71501 PoCCampcodes Advanced Online Voting System voters_delete.php sql injection
- CVE-2025-71511 PoCCampcodes Advanced Online Voting System voters_add.php unrestricted upload
- CVE-2025-71521 PoCCampcodes Advanced Online Voting System candidates_add.php unrestricted upload
- CVE-2025-71531 PoCCodeAstro Simple Hospital Management System POST Parameter doctor.html cross site scripting
- CVE-2025-71541 PoCTOTOLINK N200RE cstecgi.cgi sub_41A0F8 os command injection
- CVE-2025-71551 PoCPHPGurukul Online Notes Sharing System Cookie Dashboard sql injection
- CVE-2025-71561 PoChitsz-ids airda completions execute sql injection
- CVE-2025-71571 PoCcode-projects Online Note Sharing login.php sql injection
- CVE-2025-71581 PoCPHPGurukul Zoo Management System manage-normal-ticket.php sql injection
- CVE-2025-71591 PoCPHPGurukul Zoo Management System manage-animals.php sql injection
- CVE-2025-71602 PoCsPHPGurukul Zoo Management System index.php sql injection
- CVE-2025-71611 PoCPHPGurukul Zoo Management System add-normal-ticket.php sql injection
- CVE-2025-71621 PoCPHPGurukul Zoo Management System add-foreigners-ticket.php sql injection
- CVE-2025-71631 PoCPHPGurukul Zoo Management System add-animals.php sql injection
- CVE-2025-71641 PoCPHPGurukul/Campcodes Cyber Cafe Management System index.php sql injection
- CVE-2025-71651 PoCPHPGurukul/Campcodes Cyber Cafe Management System forgot-password.php sql injection
- CVE-2025-71661 PoCcode-projects Responsive Blog Site single.php sql injection
- CVE-2025-71671 PoCcode-projects Responsive Blog Site category.php sql injection
- CVE-2025-71681 PoCcode-projects Crime Reporting System userlogin.php sql injection
- CVE-2025-71691 PoCcode-projects Crime Reporting System complainer_page.php sql injection
- CVE-2025-71701 PoCcode-projects Crime Reporting System registration.php sql injection
- CVE-2025-71711 PoCcode-projects Crime Reporting System policelogin.php sql injection
- CVE-2025-71721 PoCcode-projects Crime Reporting System headlogin.php sql injection
- CVE-2025-71731 PoCcode-projects Library System add-student.php sql injection
- CVE-2025-71741 PoCcode-projects Library System teacher-issue-book.php sql injection
- CVE-2025-71751 PoCcode-projects E-Commerce Site users_photo.php unrestricted upload
- CVE-2025-71761 PoCPHPGurukul Hospital Management System view-medhistory.php sql injection
- CVE-2025-71771 PoCPHPGurukul Car Washing Management System editcar-washpoint.php sql injection
- CVE-2025-71781 PoCcode-projects Food Distributor Site login.php sql injection
- CVE-2025-71791 PoCcode-projects Library System add-teacher.php sql injection
- CVE-2025-71801 PoCcode-projects Staff Audit System login.php sql injection
- CVE-2025-71811 PoCcode-projects Staff Audit System test.php unrestricted upload
- CVE-2025-71821 PoCitsourcecode Student Transcript Processing System edit.php cross site scripting
- CVE-2025-71831 PoCCampcodes Sales and Inventory System customer_account.php sql injection
- CVE-2025-71841 PoCcode-projects Library System books.php sql injection
- CVE-2025-71851 PoCcode-projects Library System approve.php sql injection
- CVE-2025-71861 PoCcode-projects Chat System fetch_chat.php sql injection
- CVE-2025-71871 PoCcode-projects Chat System fetch_member.php sql injection
- CVE-2025-71881 PoCcode-projects Chat System addmember.php sql injection
- CVE-2025-71891 PoCcode-projects Chat System send_message.php sql injection
- CVE-2025-71901 PoCcode-projects Library Management System student_edit_photo.php unrestricted upload
- CVE-2025-71911 PoCcode-projects Student Enrollment System login.php sql injection
- CVE-2025-71921 PoCD-Link DIR-645 ssdpcgi cgibin ssdpcgi_main command injection
- CVE-2025-71931 PoCitsourcecode Agri-Trading Online Shopping System suppliercontroller.php sql injection
- CVE-2025-71941 PoCD-Link DI-500WF jhttpd ip_position.asp sprintf stack-based overflow
- CVE-2025-71961 PoCcode-projects Jonnys Liquor browse.php sql injection
- CVE-2025-71971 PoCcode-projects Jonnys Liquor delete-row.php sql injection
- CVE-2025-71981 PoCcode-projects Jonnys Liquor admin-area.php sql injection
- CVE-2025-71991 PoCcode-projects Library System notapprove.php sql injection
- CVE-2025-72001 PoCkrishna9772 Pharmacy Management System quantity_upd.php sql injection
- CVE-2025-72061 PoCD-Link DIR-825 httpd switch_language.cgi sub_410DDC stack-based overflow
- CVE-2025-72072 PoCsmruby nregs codegen.c scope_new heap-based overflow
- CVE-2025-72081 PoC9fans plan9port x509.c edump heap-based overflow
- CVE-2025-72092 PoCs9fans plan9port x509.c value_decode null pointer dereference
- CVE-2025-72101 PoCcode-projects/Fabian Ros Library Management System profile_update.php unrestricted upload
- CVE-2025-72111 PoCcode-projects LifeStyle Store cart_add.php sql injection
- CVE-2025-72121 PoCitsourcecode Insurance Management System insertAgent.php sql injection
- CVE-2025-72131 PoCFNKvision FNK-GU2 UART Interface on-chip debug and test interface with improper access control
- CVE-2025-72141 PoCFNKvision FNK-GU2 MD5 shadow risky encryption
- CVE-2025-72151 PoCFNKvision FNK-GU2 wpa_supplicant.conf cleartext storage
- CVE-2025-72161 PoClty628 Aidigu PHP Object common.php checkUserCookie deserialization
- CVE-2025-72171 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-72181 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-72191 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-72201 PoCCampcodes Payroll Management System ajax.php sql injection
- CVE-2025-73371 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-73402 PoCsHT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload
- CVE-2025-73461 PoCAny unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packages
- CVE-2025-73841 PoCDatabase for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion
- CVE-2025-73961 PoCCurve25519 Blinding
- CVE-2025-74042 PoCsCalibre Web 0.6.24 & Autocaliweb 0.7.0 - Blind C
- CVE-2025-74071 PoCNetgear D6400 diag.cgi os command injection
- CVE-2025-74081 PoCSourceCodester Zoo Management System animal_form_template.php cross site scripting
- CVE-2025-74091 PoCcode-projects Mobile Shop LoginAsAdmin.php sql injection
- CVE-2025-74101 PoCcode-projects LifeStyle Store cart_remove.php sql injection
- CVE-2025-74111 PoCcode-projects LifeStyle Store success.php sql injection
- CVE-2025-74121 PoCcode-projects Library System profile.php unrestricted upload
- CVE-2025-74131 PoCcode-projects Library System profile.php unrestricted upload
- CVE-2025-74141 PoCTenda O3V2 httpd setPingInfo fromNetToolGet os command injection
- CVE-2025-74151 PoCTenda O3V2 httpd getTraceroute fromTraceroutGet command injection
- CVE-2025-74161 PoCTenda O3V2 httpd setSysTimeInfo fromSysToolTime stack-based overflow
- CVE-2025-74171 PoCTenda O3V2 httpd setPingInfo fromNetToolGet stack-based overflow
- CVE-2025-74181 PoCTenda O3V2 httpd setPing fromPingResultGet stack-based overflow
- CVE-2025-74191 PoCTenda O3V2 httpd setRateTest fromSpeedTestSet stack-based overflow
- CVE-2025-74201 PoCTenda O3V2 httpd setWrlBasicInfo formWifiBasicSet stack-based overflow
- CVE-2025-74211 PoCTenda O3V2 httpd operateMacFilter fromMacFilterModify stack-based overflow
- CVE-2025-74221 PoCTenda O3V2 httpd setNetworkService setAutoReboot stack-based overflow
- CVE-2025-74231 PoCTenda O3V2 httpd setWrlFilterList formWifiMacFilterSet stack-based overflow
- CVE-2025-74312 PoCsKnowledge Base <= 2.3.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Slug
- CVE-2025-74341 PoCTenda FH451 POST Request addressNat fromAddressNat stack-based overflow
- CVE-2025-74351 PoCLiveHelperChat lhc-php-resque Extension List list cross site scripting
- CVE-2025-74361 PoCCampcodes Online Recruitment Management System ajax.php sql injection
- CVE-2025-74414 PoCsStoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload
- CVE-2025-74491 PoCAllocation of Resources Without Limits or Throttling in GitLab
- CVE-2025-74501 PoCletseeqiji gorobbs API user.go ResetUserAvatar path traversal
- CVE-2025-74521 PoCkone-net go-chat Endpoint file_controller.go GetFile path traversal
- CVE-2025-74531 PoCsaltbo zpan JSON Web Token token.go NewToken hard-coded password
- CVE-2025-74541 PoCCampcodes Online Movie Theater Seat Reservation System manage_theater.php sql injection
- CVE-2025-74551 PoCCampcodes Online Movie Theater Seat Reservation System manage_reserve.php sql injection
- CVE-2025-74561 PoCCampcodes Online Movie Theater Seat Reservation System reserve.php sql injection
- CVE-2025-74571 PoCCampcodes Online Movie Theater Seat Reservation System manage_movie.php sql injection
- CVE-2025-74591 PoCcode-projects Mobile Shop EditMobile.php sql injection
- CVE-2025-74601 PoCTOTOLINK T6 HTTP POST Request cstecgi.cgi setWiFiAclRules buffer overflow
- CVE-2025-74612 PoCscode-projects Modern Bag action.php sql injection
- CVE-2025-74631 PoCTenda FH1201 HTTP POST Request AdvSetWrlsafeset formWrlsafeset buffer overflow
- CVE-2025-74651 PoCTenda FH1201 HTTP POST Request fromRouteStatic buffer overflow
- CVE-2025-74661 PoC1000projects ABC Courier Management add_dealerrequest.php sql injection
- CVE-2025-74671 PoCcode-projects Modern Bag product-detail.php sql injection
- CVE-2025-74681 PoCTenda FH1201 HTTP POST Request fromSafeUrlFilter buffer overflow
- CVE-2025-74691 PoCCampcodes Sales and Inventory System product_add.php sql injection
- CVE-2025-74701 PoCCampcodes Sales and Inventory System product_add.php unrestricted upload
- CVE-2025-74711 PoCcode-projects Modern Bag login-back.php sql injection
- CVE-2025-74741 PoCcode-projects Job Diary search.php sql injection
- CVE-2025-74751 PoCcode-projects Simple Car Rental System pay.php sql injection
- CVE-2025-74761 PoCcode-projects Simple Car Rental System approve.php sql injection
- CVE-2025-74771 PoCcode-projects Simple Car Rental System add_cars.php unrestricted upload
- CVE-2025-74781 PoCcode-projects Modern Bag category-list.php sql injection
- CVE-2025-74791 PoCPHPGurukul Vehicle Parking Management System view--detail.php sql injection
- CVE-2025-74801 PoCPHPGurukul Vehicle Parking Management System signup.php sql injection
- CVE-2025-74811 PoCPHPGurukul Vehicle Parking Management System profile.php sql injection
- CVE-2025-74821 PoCPHPGurukul Vehicle Parking Management System print.php sql injection
- CVE-2025-74831 PoCPHPGurukul Vehicle Parking Management System forgot-password.php sql injection
- CVE-2025-74841 PoCPHPGurukul Vehicle Parking Management System view-outgoingvehicle-detail.php sql injection
- CVE-2025-74871 PoCJoeyBling SpringBoot_MyBatisPlus upload SysFileController unrestricted upload
- CVE-2025-74881 PoCJoeyBling SpringBoot_MyBatisPlus download path traversal
- CVE-2025-74891 PoCPHPGurukul Vehicle Parking Management System search-vehicle.php sql injection
- CVE-2025-74901 PoCPHPGurukul Vehicle Parking Management System reg-users.php sql injection
- CVE-2025-74911 PoCPHPGurukul Vehicle Parking Management System manage-outgoingvehicle.php sql injection
- CVE-2025-74921 PoCPHPGurukul Vehicle Parking Management System manage-incomingvehicle.php sql injection
- CVE-2025-75031 PoCAn OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet service (port 23) with undocumented,…
- CVE-2025-75051 PoCTenda FH451 HTTP POST Request L7Prot frmL7ProtForm stack-based overflow
- CVE-2025-75061 PoCTenda FH451 HTTP POST Request Natlimit fromNatlimit stack-based overflow
- CVE-2025-75081 PoCcode-projects Modern Bag product-update.php sql injection
- CVE-2025-75091 PoCcode-projects Modern Bag slide.php sql injection
- CVE-2025-75101 PoCcode-projects Modern Bag productadd_back.php sql injection
- CVE-2025-75111 PoCcode-projects Chat System update_account.php sql injection
- CVE-2025-75121 PoCcode-projects Modern Bag contact-back.php sql injection
- CVE-2025-75131 PoCcode-projects Modern Bag slideupdate.php sql injection
- CVE-2025-75141 PoCcode-projects Modern Bag contact-list.php sql injection
- CVE-2025-75151 PoCcode-projects Online Appointment Booking System ulocateus.php sql injection
- CVE-2025-75161 PoCcode-projects Online Appointment Booking System cancelbookingpatient.php sql injection
- CVE-2025-75171 PoCcode-projects Online Appointment Booking System getDay.php sql injection
- CVE-2025-75201 PoCPHPGurukul Vehicle Parking Management System manage-category.php sql injection
- CVE-2025-75211 PoCPHPGurukul Vehicle Parking Management System index.php sql injection
- CVE-2025-75221 PoCPHPGurukul Vehicle Parking Management System bwdates-reports-details.php sql injection
- CVE-2025-75231 PoCJinher OA DelTemp.aspx xml external entity reference
- CVE-2025-75241 PoCTOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg command injection
- CVE-2025-75251 PoCTOTOLINK T6 HTTP POST Request cstecgi.cgi setTracerouteCfg command injection
- CVE-2025-75271 PoCTenda FH1202 AdvSetWan fromAdvSetWan stack-based overflow
- CVE-2025-75281 PoCTenda FH1202 GstDhcpSetSer fromGstDhcpSetSer stack-based overflow
- CVE-2025-75291 PoCTenda FH1202 Natlimit fromNatlimit stack-based overflow
- CVE-2025-75301 PoCTenda FH1202 PPTPDClient fromPptpUserAdd stack-based overflow
- CVE-2025-75311 PoCTenda FH1202 PPTPUserSetting fromPptpUserSetting stack-based overflow
- CVE-2025-75321 PoCTenda FH1202 webExcptypemanFilter fromwebExcptypemanFilter stack-based overflow
- CVE-2025-75331 PoCcode-projects Job Diary view-details.php sql injection
- CVE-2025-75341 PoCPHPGurukul Student Result Management System GET Parameter notice-details.php sql injection
- CVE-2025-75351 PoCCampcodes Sales and Inventory System reprint_cash.php sql injection
- CVE-2025-75361 PoCCampcodes Sales and Inventory System receipt_credit.php sql injection
- CVE-2025-75371 PoCCampcodes Sales and Inventory System product_update.php sql injection
- CVE-2025-75381 PoCCampcodes Sales and Inventory System product_update.php unrestricted upload
- CVE-2025-75391 PoCcode-projects Online Appointment Booking System getdoctordaybooking.php sql injection
- CVE-2025-75401 PoCcode-projects Online Appointment Booking System getclinic.php sql injection
- CVE-2025-75411 PoCcode-projects Online Appointment Booking System get_town.php sql injection
- CVE-2025-75421 PoCPHPGurukul User Registration & Login and User Management System user-profile.php sql injection
- CVE-2025-75431 PoCPHPGurukul User Registration & Login and User Management System manage-users.php sql injection
- CVE-2025-75441 PoCTenda AC1206 setMacFilterCfg formSetMacFilterCfg stack-based overflow
- CVE-2025-75452 PoCsGNU Binutils objcopy.c copy_section heap-based overflow
- CVE-2025-75461 PoCGNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds write
- CVE-2025-75471 PoCCampcodes Online Movie Theater Seat Reservation System admin_class.php save_movie unrestricted upload
- CVE-2025-75481 PoCTenda FH1201 SafeEmailFilter formSafeEmailFilter stack-based overflow
- CVE-2025-75491 PoCTenda FH1201 L7Prot frmL7ProtForm stack-based overflow
- CVE-2025-75501 PoCTenda FH1201 GstDhcpSetSer fromGstDhcpSetSer stack-based overflow
- CVE-2025-75511 PoCTenda FH1201 PPTPDClient fromPptpUserAdd stack-based overflow
- CVE-2025-75551 PoCcode-projects Voting System voters_add.php sql injection
- CVE-2025-75561 PoCcode-projects Voting System voters_edit.php sql injection
- CVE-2025-75571 PoCcode-projects Voting System voters_row.php sql injection
- CVE-2025-75582 PoCscode-projects Voting System positions_add.php sql injection
- CVE-2025-75591 PoCPHPGurukul Online Fire Reporting System bwdates-report-result.php sql injection
- CVE-2025-75601 PoCPHPGurukul Online Fire Reporting System workin-progress-requests.php sql injection
- CVE-2025-75611 PoCPHPGurukul Online Fire Reporting System team-ontheway-requests.php sql injection
- CVE-2025-75621 PoCPHPGurukul Online Fire Reporting System new-requests.php sql injection
- CVE-2025-75631 PoCPHPGurukul Online Fire Reporting System completed-requests.php sql injection
- CVE-2025-75641 PoCLB-LINK BL-AC3600 shadow hard-coded credentials
- CVE-2025-75651 PoCLB-LINK BL-AC3600 Web Management Interface lighttpd.cgi geteasycfg information disclosure
- CVE-2025-75661 PoCjshERP SystemConfigController.java exportExcelByParam path traversal
- CVE-2025-75671 PoCShopXO header.html cross site scripting
- CVE-2025-75681 PoCqianfox FoxCMS Video.php batchCope sql injection
- CVE-2025-75691 PoCBigotry OneBase think_exception.tpl parse_args cross site scripting
- CVE-2025-75701 PoCUTT HiPER 840G aspRemoteApConfTempSend buffer overflow
- CVE-2025-75711 PoCUTT HiPER 840G aspApBasicConfigUrcp buffer overflow
- CVE-2025-75721 PoCLB-LINK BL-WR9000 lighttpd.cgi bs_GetHostInfo information disclosure
- CVE-2025-75731 PoCLB-LINK BL-WR9000 lighttpd.cgi bs_GetManPwd information disclosure
- CVE-2025-75741 PoCLB-LINK BL-WR9000 Web Interface lighttpd.cgi restore improper authentication
- CVE-2025-75761 PoCTeledyne FLIR FB-Series O/FLIR FH-Series ID Production Tools production.html access control
- CVE-2025-75771 PoCTeledyne FLIR FB-Series O/FLIR FH-Series ID hard-coded password
- CVE-2025-75791 PoCchinese-poetry server.js redos
- CVE-2025-75801 PoCcode-projects Voting System positions_row.php sql injection
- CVE-2025-75811 PoCcode-projects Voting System positions_edit.php sql injection
- CVE-2025-75821 PoCPHPGurukul Online Fire Reporting System assigned-requests.php sql injection
- CVE-2025-75831 PoCPHPGurukul Online Fire Reporting System all-requests.php sql injection
- CVE-2025-75841 PoCPHPGurukul Online Fire Reporting System add-team.php sql injection
- CVE-2025-75851 PoCPHPGurukul Online Fire Reporting System manage-site.php sql injection
- CVE-2025-75861 PoCTenda AC500 setWtpData formSetAPCfg stack-based overflow
- CVE-2025-75871 PoCcode-projects Online Appointment Booking System cover.php sql injection
- CVE-2025-75881 PoCPHPGurukul Dairy Farm Shop Management System edit-product.php sql injection
- CVE-2025-75891 PoCPHPGurukul Dairy Farm Shop Management System edit-company.php sql injection
- CVE-2025-75901 PoCPHPGurukul Dairy Farm Shop Management System edit-category.php sql injection
- CVE-2025-75911 PoCPHPGurukul Dairy Farm Shop Management System view-invoice.php sql injection
- CVE-2025-75921 PoCPHPGurukul Dairy Farm Shop Management System invoices.php sql injection
- CVE-2025-75931 PoCcode-projects Job Diary view-all.php sql injection
- CVE-2025-75941 PoCcode-projects Job Diary view-emp.php sql injection
- CVE-2025-75951 PoCcode-projects Job Diary view-cad.php sql injection
- CVE-2025-75961 PoCTenda FH1205 WifiExtraSet formWifiExtraSet stack-based overflow
- CVE-2025-75971 PoCTenda AX1803 setMacFilterCfg formSetMacFilterCfg stack-based overflow
- CVE-2025-75981 PoCTenda AX1803 setWifiFilterCfg formSetWifiMacFilterCfg stack-based overflow
- CVE-2025-75991 PoCPHPGurukul Dairy Farm Shop Management System invoice.php sql injection
- CVE-2025-76001 PoCPHPGurukul Online Library Management System student-history.php sql injection
- CVE-2025-76011 PoCPHPGurukul Online Library Management System student-history.php cross site scripting
- CVE-2025-76021 PoCD-Link DI-8100 HTTP Request arp_sys.asp stack-based overflow
- CVE-2025-76031 PoCD-Link DI-8100 HTTP Request jingx.asp stack-based overflow
- CVE-2025-76041 PoCPHPGurukul Hospital Management System user-login.php sql injection
- CVE-2025-76052 PoCscode-projects AVL Rooms profile.php sql injection
- CVE-2025-76062 PoCscode-projects AVL Rooms city.php sql injection
- CVE-2025-76071 PoCcode-projects Simple Shopping Cart save_order.php sql injection
- CVE-2025-76081 PoCcode-projects Simple Shopping Cart userlogin.php sql injection
- CVE-2025-76091 PoCcode-projects Simple Shopping Cart register.php sql injection
- CVE-2025-76101 PoCcode-projects Electricity Billing System change_password.php sql injection
- CVE-2025-76111 PoCcode-projects Wedding Reservation global.php sql injection
- CVE-2025-76121 PoCcode-projects Mobile Shop login.php sql injection
- CVE-2025-76131 PoCTOTOLINK T6 HTTP POST Request cstecgi.cgi CloudSrvVersionCheck command injection
- CVE-2025-76141 PoCTOTOLINK T6 HTTP POST Request cstecgi.cgi delDevice command injection
- CVE-2025-76151 PoCTOTOLINK T6 HTTP POST Request cstecgi.cgi clearPairCfg command injection
- CVE-2025-76161 PoCgmg137 snap7-rs Public API pthread_cond_destroy memory corruption
- CVE-2025-76251 PoCYiJiuSmile kkFileViewOfficeEdit download path traversal
- CVE-2025-76261 PoCYiJiuSmile kkFileViewOfficeEdit onlinePreview path traversal
- CVE-2025-76271 PoCYiJiuSmile kkFileViewOfficeEdit fileUpload unrestricted upload
- CVE-2025-76281 PoCYiJiuSmile kkFileViewOfficeEdit deleteFile path traversal
- CVE-2025-76591 PoCOrigin Validation Error in GitLab
- CVE-2025-76911 PoCPrivilege Defined With Unsafe Actions in GitLab
- CVE-2025-77281 PoCScada-LTS users.shtm cross site scripting
- CVE-2025-77291 PoCScada-LTS usersProfiles.shtm cross site scripting
- CVE-2025-77341 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-77361 PoCIncorrect Authorization in GitLab
- CVE-2025-77391 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-77471 PoCTenda FH451 POST Request WizardHandle fromWizardHandle buffer overflow
- CVE-2025-77481 PoCZCMS Create Article Page cross site scripting
- CVE-2025-77491 PoCcode-projects Online Appointment Booking System getmanagerregion.php sql injection
- CVE-2025-77501 PoCcode-projects Online Appointment Booking System adddoctorclinic.php sql injection
- CVE-2025-77511 PoCcode-projects Online Appointment Booking System addclinic.php sql injection
- CVE-2025-77521 PoCcode-projects Online Appointment Booking System deletedoctor.php sql injection
- CVE-2025-77532 PoCscode-projects Online Appointment Booking System adddoctor.php sql injection
- CVE-2025-77541 PoCcode-projects Patient Record Management System xray_form.php sql injection
- CVE-2025-77551 PoCcode-projects Online Ordering System edit_product.php unrestricted upload
- CVE-2025-77561 PoCcode-projects E-Commerce Site cross-site request forgery
- CVE-2025-77571 PoCPHPGurukul Land Record System edit-property.php sql injection
- CVE-2025-77581 PoCTOTOLINK T6 HTTP POST Request cstecgi.cgi setDiagnosisCfg buffer overflow
- CVE-2025-77592 PoCsthinkgem JeeSite UEditor Image Grabber ActionEnter.java server-side request forgery
- CVE-2025-77621 PoCD-Link DI-8100 HTTP Request menu_nat_more.asp stack-based overflow
- CVE-2025-77631 PoCthinkgem JeeSite Site Controller SiteController.java select redirect
- CVE-2025-77641 PoCcode-projects Online Appointment Booking System deletedoctorclinic.php sql injection
- CVE-2025-77651 PoCcode-projects Online Appointment Booking System addmanagerclinic.php sql injection
- CVE-2025-77662 PoCsLantronix Provisioning Manager Improper Restriction of XML External Entity Reference
- CVE-2025-77671 PoCPHPGurukul Art Gallery Management System edit-art-medium-detail.php cross site scripting
- CVE-2025-77692 PoCsImproper Neutralization of Special Elements used in a Command ('Command Injection') in Tigo Energy Cloud Connect Advanced
- CVE-2025-777110 PoCsCode Execution / Escalation of Privileges in ThrottleStop
- CVE-2025-77754 PoCsKEVMemory overflow vulnerability leading to Remote Code Execution and/or Denial of Service
- CVE-2025-77831 PoCUsage of unsafe random function in form-data for choosing boundary
- CVE-2025-77851 PoCthinkgem JeeSite SsoController.java sso redirect
- CVE-2025-77861 PoCGnuboard g6 Post Reply qa cross site scripting
- CVE-2025-77871 PoCXuxueli xxl-job SampleXxlJob.java httpJobHandler server-side request forgery
- CVE-2025-77881 PoCXuxueli xxl-job SampleXxlJob.java commandJobHandler os command injection
- CVE-2025-77891 PoCXuxueli xxl-job Token Generation IndexController.java makeToken weak password hash
- CVE-2025-77901 PoCD-Link DI-8100 HTTP Request menu_nat.asp stack-based overflow
- CVE-2025-77911 PoCPHPGurukul Online Security Guards Hiring System search.php cross site scripting
- CVE-2025-77921 PoCTenda FH451 SafeEmailFilter formSafeEmailFilter stack-based overflow
- CVE-2025-77931 PoCTenda FH451 webtypelibrary formWebTypeLibrary stack-based overflow
- CVE-2025-77941 PoCTenda FH451 NatStaticSetting fromNatStaticSetting stack-based overflow
- CVE-2025-77953 PoCsTenda FH451 P2pListFilter fromP2pListFilter stack-based overflow
- CVE-2025-77961 PoCTenda FH451 PPTPDClient fromPptpUserAdd stack-based overflow
- CVE-2025-77971 PoCGPAC dash_client.c gf_dash_download_init_segment null pointer dereference
- CVE-2025-77981 PoCBeijing Shenzhou Shihan Technology Multimedia Integrated Business Display System companyManage sql injection
- CVE-2025-78011 PoCBossSoft CRM HNDCBas_customPrmSearchDtl.jsp sql injection
- CVE-2025-78021 PoCPHPGurukul Complaint Management System complaint-search.php cross site scripting
- CVE-2025-78051 PoCTenda FH451 PPTPUserSetting fromPptpUserSetting stack-based overflow
- CVE-2025-78061 PoCTenda FH451 SafeClientFilter fromSafeClientFilter stack-based overflow
- CVE-2025-78071 PoCTenda FH451 SafeUrlFilter fromSafeUrlFilter stack-based overflow
- CVE-2025-78081 PoCWP Shopify < 1.5.4 - Reflected XSS
- CVE-2025-78141 PoCcode-projects Food Ordering Review System signup_function.php sql injection
- CVE-2025-78151 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request manage-newvisitors.php cross site scripting
- CVE-2025-78161 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request visitor-detail.php cross site scripting
- CVE-2025-78171 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request bwdates-reports.php cross site scripting
- CVE-2025-78181 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request category.php cross site scripting
- CVE-2025-78191 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request create-pass.php cross site scripting
- CVE-2025-78231 PoCJinher OA ProjectScheduleDelete.aspx xml external entity reference
- CVE-2025-78241 PoCJinher OA XmlHttp.aspx xml external entity reference
- CVE-2025-78291 PoCcode-projects Church Donation System login.php sql injection
- CVE-2025-78301 PoCcode-projects Church Donation System reg.php sql injection
- CVE-2025-78311 PoCcode-projects Church Donation System Tithes.php sql injection
- CVE-2025-78321 PoCcode-projects Church Donation System offering.php sql injection
- CVE-2025-78331 PoCcode-projects Church Donation System giving.php sql injection
- CVE-2025-78341 PoCPHPGurukul Complaint Management System cross-site request forgery
- CVE-2025-78361 PoCD-Link DIR-816L Environment Variable cgibin lxmldbc_system command injection
- CVE-2025-78371 PoCTOTOLINK T6 MQTT Service recvSlaveStaInfo buffer overflow
- CVE-2025-78381 PoCCampcodes Online Movie Theater Seat Reservation System manage_seat.php sql injection
- CVE-2025-78402 PoCsCampcodes Online Movie Theater Seat Reservation System Reserve Your Seat Page index.php cross site scripting
- CVE-2025-78471 PoCAI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload
- CVE-2025-78531 PoCTenda FH451 SetIpBind fromSetIpBind stack-based overflow
- CVE-2025-78541 PoCTenda FH451 VirtualSer fromVirtualSer stack-based overflow
- CVE-2025-78551 PoCTenda FH451 qossetting fromqossetting stack-based overflow
- CVE-2025-78561 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request pass-details.php cross site scripting
- CVE-2025-78571 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request bwdates-passreports-details.php cross site scripting
- CVE-2025-78581 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request admin-profile.php cross site scripting
- CVE-2025-78591 PoCcode-projects Church Donation System update_password_admin.php sql injection
- CVE-2025-78601 PoCcode-projects Church Donation System login_admin.php sql injection
- CVE-2025-78611 PoCcode-projects Church Donation System search.php sql injection
- CVE-2025-78621 PoCTOTOLINK T6 Telnet Service cstecgi.cgi setTelnetCfg missing authentication
- CVE-2025-78631 PoCthinkgem JeeSite ServletUtils.java redirectUrl
- CVE-2025-78641 PoCthinkgem JeeSite FileUploadController.java upload unrestricted upload
- CVE-2025-78651 PoCthinkgem JeeSite XSS Filter EncodeUtils.java xssFilter cross site scripting
- CVE-2025-78661 PoCPortabilis i-Educar Disabilities Module educar_deficiencia_lst.php cross site scripting
- CVE-2025-78671 PoCPortabilis i-Educar Agenda agenda.php cross site scripting
- CVE-2025-78681 PoCPortabilis i-Educar Calendar educar_calendario_dia_motivo_cad.php cross site scripting
- CVE-2025-78691 PoCPortabilis i-Educar Turma Module educar_turma_tipo_det.php cross site scripting
- CVE-2025-78701 PoCPortabilis i-Diario justificativas-de-falta Endpoint cross site scripting
- CVE-2025-78711 PoCPortabilis i-Diario conteudos cross site scripting
- CVE-2025-78721 PoCPortabilis i-Diario justificativas-de-falta cross site scripting
- CVE-2025-78731 PoCMetasoft 美特软件 MetaCRM mcc_login.jsp sql injection
- CVE-2025-78741 PoCMetasoft 美特软件 MetaCRM env.jsp information disclosure
- CVE-2025-78751 PoCMetasoft 美特软件 MetaCRM debug.jsp improper authentication
- CVE-2025-78761 PoCMetasoft 美特软件 MetaCRM download.jsp AnalyzeParam deserialization
- CVE-2025-78771 PoCMetasoft 美特软件 MetaCRM sendfile.jsp unrestricted upload
- CVE-2025-78781 PoCMetasoft 美特软件 MetaCRM upload2.jsp unrestricted upload
- CVE-2025-78791 PoCMetasoft 美特软件 MetaCRM mobileupload.jsp unrestricted upload
- CVE-2025-78801 PoCMetasoft 美特软件 MetaCRM sendsms.jsp unrestricted upload
- CVE-2025-78811 PoCMercusys MW301R Web Interface password recovery
- CVE-2025-78821 PoCMercusys MW301R Login excessive authentication
- CVE-2025-78831 PoCEluktronics Control Center Powershell Script Command command injection
- CVE-2025-78841 PoCEluktronics Control Center REG File data authenticity
- CVE-2025-78851 PoCHuashengdun WebSSH Login Page cross site scripting
- CVE-2025-78871 PoCZavy86 WikiDocs template.inc.php cross site scripting
- CVE-2025-78881 PoCTDuckCloud tduck-platform UserFormDataMapper.java UserFormDataMapper sql injection
- CVE-2025-78891 PoCCallApp Caller ID App caller.id.phone.number.block AndroidManifest.xml improper export of android application components
- CVE-2025-78901 PoCDunamu StockPlus App com.dunamu.stockplus AndroidManifest.xml improper export of android application components
- CVE-2025-78911 PoCInstantBits Web Video Cast App com.instantbits.cast.webvideo AndroidManifest.xml improper export of android application components
- CVE-2025-78922 PoCsIDnow App de.idnow AndroidManifest.xml improper export of android application components
- CVE-2025-78931 PoCForesight News App pro.foresightnews.appa AndroidManifest.xml improper export of android application components
- CVE-2025-78941 PoCOnyx Chat Interface a3_generate_simple_sql.py generate_simple_sql sql injection
- CVE-2025-78981 PoCCodecanyon iDentSoft Account Setting Page updateSetting unrestricted upload
- CVE-2025-79012 PoCsyangzongzhuan RuoYi Swagger UI index.html cross site scripting
- CVE-2025-79021 PoCyangzongzhuan RuoYi SysNoticeController.java addSave cross site scripting
- CVE-2025-79031 PoCyangzongzhuan RuoYi Image Source ui layer
- CVE-2025-79041 PoCitsourcecode Insurance Management System insertNominee.php sql injection
- CVE-2025-79051 PoCitsourcecode Insurance Management System insertPayment.php sql injection
- CVE-2025-79061 PoCyangzongzhuan RuoYi CommonController.java uploadFile unrestricted upload
- CVE-2025-79071 PoCyangzongzhuan RuoYi Druid application-druid.yml default credentials
- CVE-2025-79081 PoCD-Link DI-8100 jhttpd ddns.asp sprintf stack-based overflow
- CVE-2025-79091 PoCD-Link DIR-513 Boa Webserver formLanSetupRouterSettings sprintf stack-based overflow
- CVE-2025-79101 PoCD-Link DIR-513 Boa Webserver formSetWanNonLogin sprintf stack-based overflow
- CVE-2025-79111 PoCD-Link DI-8100 jhttpd upnp_ctrl.asp sprintf stack-based overflow
- CVE-2025-79121 PoCTOTOLINK T6 MQTT Service recvSlaveUpgstatus buffer overflow
- CVE-2025-79131 PoCTOTOLINK T6 MQTT Service updateWifiInfo buffer overflow
- CVE-2025-79151 PoCChanjet CRM Login Page mailinactive.php sql injection
- CVE-2025-79242 PoCsPHPGurukul Online Banquet Booking System admin-profile.php cross site scripting
- CVE-2025-79252 PoCsPHPGurukul Online Banquet Booking System login.php cross site scripting
- CVE-2025-79262 PoCsPHPGurukul Online Banquet Booking System booking-search.php cross site scripting
- CVE-2025-79271 PoCPHPGurukul Online Banquet Booking System view-user-queries.php sql injection
- CVE-2025-79281 PoCcode-projects Church Donation System edit_user.php sql injection
- CVE-2025-79291 PoCcode-projects Church Donation System edit_Members.php sql injection
- CVE-2025-79301 PoCcode-projects Church Donation System add_members.php sql injection
- CVE-2025-79311 PoCcode-projects Church Donation System admin_pic.php unrestricted upload
- CVE-2025-79321 PoCD-Link DIR‑817L ssdpcgi lxmldbc_system command injection
- CVE-2025-79331 PoCCampcodes Sales and Inventory System Setting settings_update.php sql injection
- CVE-2025-79341 PoCfuyang_lipengjun platform ScheduleJobController.java queryPage sql injection
- CVE-2025-79351 PoCfuyang_lipengjun platform SysLogController.java SysLogController sql injection
- CVE-2025-79361 PoCfuyang_lipengjun platform ScheduleJobLogController.java queryPage sql injection
- CVE-2025-79381 PoCjerryshensjf JPACookieShop 蛋糕商城JPA版 GoodsController.java updateGoods authorization
- CVE-2025-79401 PoCGenshin Albedo Cat House App com.house.auscat AndroidManifest.xml improper export of android application components
- CVE-2025-79412 PoCsPHPGurukul Time Table Generator System profile.php cross site scripting
- CVE-2025-79421 PoCPHPGurukul Taxi Stand Management System admin-profile.php cross site scripting
- CVE-2025-79431 PoCPHPGurukul Taxi Stand Management System search-autoortaxi.php cross site scripting
- CVE-2025-79441 PoCPHPGurukul Taxi Stand Management System search.php cross site scripting
- CVE-2025-79461 PoCPHPGurukul Apartment Visitors Management System HTTP POST Request search-visitor.php cross site scripting
- CVE-2025-79471 PoCjshERP Account delete improper authorization
- CVE-2025-79481 PoCjshERP updatePwd password recovery
- CVE-2025-79491 PoCSanluan PublicCMS preview.html redirect
- CVE-2025-79501 PoCcode-projects Public Chat Room login.php sql injection
- CVE-2025-79511 PoCcode-projects Public Chat Room send_message.php cross site scripting
- CVE-2025-79521 PoCTOTOLINK T6 MQTT Packet wireless.so ckeckKeepAlive command injection
- CVE-2025-79531 PoCSanluan PublicCMS viewer.html redirect
- CVE-2025-79551 PoCRingCentral Communications 1.5 - 1.6.8 - Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify…
- CVE-2025-79651 PoCCBX Restaurant Booking <= 1.2.1 - Plugin Reset via CSRF
- CVE-2025-79691 PoCMarkdown-it 14.1.0 - Cross-site scripting (XSS)