CVE-2025-9000 to CVE-2025-9999
480 CVEs with public proof-of-concept exploits.
- CVE-2025-90001 PoCMechrevo Control Center GX V2 reg File uncontrolled search path
- CVE-2025-90012 PoCsLemonOS HTTP Client main.cpp HTTPGet stack-based overflow
- CVE-2025-90021 PoCSurbowl dormitory-management-php login.php sql injection
- CVE-2025-90041 PoCmtons mblog password excessive authentication
- CVE-2025-90051 PoCmtons mblog register information exposure
- CVE-2025-90061 PoCTenda CH22 delFileName formdelFileName buffer overflow
- CVE-2025-90071 PoCTenda CH22 editFileName formeditFileName buffer overflow
- CVE-2025-90081 PoCitsourcecode Online Tour and Travel Management System sms_setting.php sql injection
- CVE-2025-90091 PoCitsourcecode Online Tour and Travel Management System email_setup.php sql injection
- CVE-2025-90101 PoCitsourcecode Online Tour and Travel Management System booking_report.php sql injection
- CVE-2025-90111 PoCPHPGurukul Online Shopping Portal Project signup.php sql injection
- CVE-2025-90121 PoCPHPGurukul Online Shopping Portal Project bill-ship-addresses.php sql injection
- CVE-2025-90131 PoCPHPGurukul Online Shopping Portal Project password-recovery.php sql injection
- CVE-2025-90161 PoCMechrevo Control Center GX V2 Powershell Script Command uncontrolled search path
- CVE-2025-90171 PoCPHPGurukul Zoo Management System add-foreigner-ticket.php cross site scripting
- CVE-2025-90192 PoCstcpreplay tcpprep cidr.c mask_cidr6 heap-based overflow
- CVE-2025-90231 PoCTenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow
- CVE-2025-90241 PoCPHPGurukul Beauty Parlour Management System book-appointment.php sql injection
- CVE-2025-90251 PoCcode-projects Simple Cafe Ordering System portal.php sql injection
- CVE-2025-90261 PoCD-Link DIR-860L Simple Service Discovery Protocol cgibin ssdpcgi_main os command injection
- CVE-2025-90271 PoCcode-projects Online Medicine Guide addelivery.php sql injection
- CVE-2025-90281 PoCcode-projects Online Medicine Guide adphar.php sql injection
- CVE-2025-90341 PoCWp Edit Password Protected < 1.3.5 - Open Redirect
- CVE-2025-90461 PoCTenda AC20 setMacFilterCfg sub_46A2AC stack-based overflow
- CVE-2025-90471 PoCprojectworlds Visitor Management System visitor_out.php sql injection
- CVE-2025-90501 PoCprojectworlds Travel Management System addcategory.php sql injection
- CVE-2025-90511 PoCprojectworlds Travel Management System updatecategory.php sql injection
- CVE-2025-90521 PoCprojectworlds Travel Management System updatepackage.php sql injection
- CVE-2025-90531 PoCprojectworlds Travel Management System updatesubcategory.php sql injection
- CVE-2025-907420 PoCsDocker Desktop allows unauthenticated access to Docker Engine API from containers
- CVE-2025-90831 PoCNinja-forms < 3.11.1 - Unauthenticated PHP Objection
- CVE-2025-90871 PoCTenda AC20 SetNetControlList Endpoint set_qosMib_list stack-based overflow
- CVE-2025-90881 PoCTenda AC20 formSetVirtualSer save_virtualser_data stack-based overflow
- CVE-2025-90891 PoCTenda AC20 SetIpMacBind sub_48E628 stack-based overflow
- CVE-2025-90903 PoCsTenda AC20 Telnet Service telnet websFormDefine command injection
- CVE-2025-90911 PoCTenda AC20 shadow hard-coded credentials
- CVE-2025-90931 PoCBuzzFeed App com.buzzfeed.android AndroidManifest.xml improper export of android application components
- CVE-2025-90941 PoCThingsBoard Add Gateway special elements used in a template engine
- CVE-2025-90951 PoCExpressGateway express-gateway REST Endpoint users.js cross site scripting
- CVE-2025-90961 PoCExpressGateway express-gateway REST Endpoint apps.js cross site scripting
- CVE-2025-90971 PoCEuro Information CIC banque et compte en ligne App com.cic_prod.bad AndroidManifest.xml improper export of android application components
- CVE-2025-90981 PoCElseplus File Recovery App AndroidManifest.xml improper export of android application components
- CVE-2025-90991 PoCAcrel Environmental Monitoring Cloud Platform UploadNewsImg unrestricted upload
- CVE-2025-91001 PoCzhenfeng13 My-Blog Frontend Blog Article Comment comment authentication replay
- CVE-2025-91011 PoCzhenfeng13 My-Blog Tag save cross site scripting
- CVE-2025-91021 PoC1&1 Mail & Media mail.com App com.mail.mobile.android.mail AndroidManifest.xml improper export of android application components
- CVE-2025-91031 PoCZenCart CKEditor cross site scripting
- CVE-2025-91041 PoCPortabilis i-Diario Informações Adicionais /planos-de-aulas-por-disciplina cross site scripting
- CVE-2025-91051 PoCPortabilis i-Diario Informações Adicionais /planos-de-ensino-por-areas-de-conhecimento cross site scripting
- CVE-2025-91061 PoCPortabilis i-Diario Informações Adicionais /planos-de-ensino-por-disciplina cross site scripting
- CVE-2025-91071 PoCPortabilis i-Diario search_autocomplete cross site scripting
- CVE-2025-91111 PoCWPBOT < 7.1.0 - Admin+ Stored XSS
- CVE-2025-91151 PoCEtsy Shop < 3.0.7 - Reflected XSS via $_SERVER['REQUEST_URI']
- CVE-2025-91161 PoCWPS Visitor Counter Plugin <= 1.4.8 - Reflected XSS via $_SERVER['REQUEST_URI']
- CVE-2025-91341 PoCAfterShip Package Tracker App com.aftership.AfterShip AndroidManifest.xml improper export of android application components
- CVE-2025-91351 PoCVerkehrsauskunft Österreich SmartRide/cleVVVer/BusBahnBim/Salzburg Verkehr AndroidManifest.xml improper export of android application…
- CVE-2025-91373 PoCsScada-LTS scheduled_events.shtm cross site scripting
- CVE-2025-91382 PoCsScada-LTS new cross site scripting
- CVE-2025-91391 PoCScada-LTS WatchListDwr.init.dwr information disclosure
- CVE-2025-91402 PoCsShanghai Lingdang Information Technology Lingdang CRM tabdetail_moduleSave.php sql injection
- CVE-2025-91432 PoCsScada-LTS mailing_lists.shtm cross site scripting
- CVE-2025-91442 PoCsScada-LTS publisher_edit.shtm cross site scripting
- CVE-2025-91452 PoCsScada-LTS SVG File view_edit.shtm cross site scripting
- CVE-2025-91481 PoCCodePhiliaX Chat2DB JDBC Connection DataSourceController.java sql injection
- CVE-2025-91491 PoCWavlink WL-NU516U1 wireless.cgi sub_4032E4 command injection
- CVE-2025-91501 PoCSurbowl dormitory-management-php violation_add.php sql injection
- CVE-2025-91511 PoCLiuYuYang01 ThriveX-Blog web updateJsonValueByName improper authorization
- CVE-2025-91531 PoCitsourcecode Online Tour and Travel Management System travellers.php unrestricted upload
- CVE-2025-91541 PoCitsourcecode Online Tour and Travel Management System page-login.php sql injection
- CVE-2025-91551 PoCitsourcecode Online Tour and Travel Management System forget_password.php sql injection
- CVE-2025-91561 PoCitsourcecode Sports Management System sports.php sql injection
- CVE-2025-91571 PoCappneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after free
- CVE-2025-91651 PoCLibTIFF tiffcmp tiffcmp.c InitCCITTFax3 memory leak
- CVE-2025-91671 PoCSolidInvoice Recurring Invoice recurring cross site scripting
- CVE-2025-91681 PoCSolidInvoice Invoice Creation invoice cross site scripting
- CVE-2025-91691 PoCSolidInvoice Quote quotes cross site scripting
- CVE-2025-91701 PoCSolidInvoice Tax Rates rates cross site scripting
- CVE-2025-91712 PoCsSolidInvoice Clients clients cross site scripting
- CVE-2025-91741 PoCneurobin shc Filename shc.c make os command injection
- CVE-2025-91751 PoCneurobin shc shc.c make stack-based overflow
- CVE-2025-91761 PoCneurobin shc Environment Variable shc.c make os command injection
- CVE-2025-91931 PoCTOTVS Portal Meu RH Password Reset redirect
- CVE-2025-91961 PoCTrinity Audio <= 5.21.0 - Unauthenticated Information Exposure
- CVE-2025-92092 PoCsRestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT
- CVE-2025-92151 PoCStoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated…
- CVE-2025-92161 PoCStoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated…
- CVE-2025-92221 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-92231 PoCCommand Injection
- CVE-2025-92331 PoCScada-LTS view_edit.shtm cross site scripting
- CVE-2025-92341 PoCScada-LTS maintenance_events.shtm cross site scripting
- CVE-2025-92351 PoCScada-LTS compound_events.shtm cross site scripting
- CVE-2025-92361 PoCPortabilis i-Educar Tipos de usuàrio educar_tipo_usuario_lst.php sql injection
- CVE-2025-92372 PoCsCodeAstro Ecommerce Website Edit Your Account my_account.php cross site scripting
- CVE-2025-92381 PoCSwatadru Exam-Seating-Arrangement Student Login student.php sql injection
- CVE-2025-92401 PoCelunez eladmin info information disclosure
- CVE-2025-92411 PoCelunez eladmin exportUser csv injection
- CVE-2025-92423 PoCsKEVWatchGuard Firebox iked Out of Bounds Write Vulnerability
- CVE-2025-92441 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 addStaticRoute os command injection
- CVE-2025-92451 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 WPSSTAPINEnr stack-based overflow
- CVE-2025-92461 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 check_port_conflict stack-based overflow
- CVE-2025-92471 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setVlan stack-based overflow
- CVE-2025-92481 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_pingGatewayByBBS stack-based overflow
- CVE-2025-92491 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DHCPReserveAddGroup stack-based overflow
- CVE-2025-92501 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setPWDbyBBS stack-based overflow
- CVE-2025-92511 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 sta_wps_pin stack-based overflow
- CVE-2025-92521 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 DisablePasswordAlertRedirect stack-based overflow
- CVE-2025-92531 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_doSpecifySiteSurvey stack-based overflow
- CVE-2025-92622 PoCswong2 mcp-cli oAuth provider.js redirectToAuthorization os command injection
- CVE-2025-92631 PoCXuxueli xxl-job JobLogController.java getJobsByGroup resource injection
- CVE-2025-92641 PoCXuxueli xxl-job Jobs JobInfoController.java remove resource injection
- CVE-2025-92861 PoCAppy Pie Connect for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Privilege Escalation via reset_user_password
- CVE-2025-92872 PoCsMissing type checks leading to hash rewind and passing on crafted data
- CVE-2025-92882 PoCsMissing type checks leading to hash rewind and passing on crafted data
- CVE-2025-92961 PoCEmlog Pro blogger.php unrestricted upload
- CVE-2025-92971 PoCTenda i22 wxportalauth formWeixinAuthInfoGet stack-based overflow
- CVE-2025-92981 PoCTenda M3 QuickIndex formQuickIndex stack-based overflow
- CVE-2025-92991 PoCTenda M3 getMasterPassengerAnalyseData formGetMasterPassengerAnalyseData stack-based overflow
- CVE-2025-93002 PoCssaitoha libsixel img2sixel encoder.c sixel_debug_print_palette stack-based overflow
- CVE-2025-93011 PoCcmake cmForEachCommand.cxx ReplayItems assertion
- CVE-2025-93021 PoCPHPGurukul User Management System signup.php sql injection
- CVE-2025-93031 PoCTOTOLINK A720R cstecgi.cgi setParentalRules buffer overflow
- CVE-2025-93041 PoCSourceCodester Online Bank Management System show.php sql injection
- CVE-2025-93051 PoCSourceCodester Online Bank Management System mnotice.php sql injection
- CVE-2025-93061 PoCSourceCodester Advanced School Management System addNotice cross site scripting
- CVE-2025-93071 PoCPHPGurukul Online Course Registration session.php sql injection
- CVE-2025-93091 PoCTenda AC10 MD5 Hash shadow hard-coded credentials
- CVE-2025-93101 PoCyeqifu carRental Druid login.html hard-coded credentials
- CVE-2025-93111 PoCitsourcecode Apartment Management System addfair.php sql injection
- CVE-2025-93141 PoCDeveloper Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload
- CVE-2025-93162 PoCsN-central unauthenticated sessionID generation
- CVE-2025-93451 PoCFile Manager, Code Editor, and Backup by Managefy <= 1.4.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Download
- CVE-2025-93551 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 scheduleAdd stack-based overflow
- CVE-2025-93561 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 inboundFilterAdd stack-based overflow
- CVE-2025-93571 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 langSwitchByBBS stack-based overflow
- CVE-2025-93581 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setSysAdm stack-based overflow
- CVE-2025-93591 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 RP_checkCredentialsByBBS stack-based overflow
- CVE-2025-93601 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 accessControlAdd stack-based overflow
- CVE-2025-93611 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 ipRangeBlockManageRule stack-based overflow
- CVE-2025-93621 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 urlFilterManageRule stack-based overflow
- CVE-2025-93631 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 portTriggerManageRule stack-based overflow
- CVE-2025-93801 PoCFNKvision Y215 CCTV Camera Firmware passwd hard-coded credentials
- CVE-2025-93811 PoCFNKvision Y215 CCTV Camera wpa_supplicant.conf information disclosure
- CVE-2025-93821 PoCFNKvision Y215 CCTV Camera Telnet Sevice s1_rf_test_config backdoor
- CVE-2025-93831 PoCFNKvision Y215 CCTV Camera passwd crypt weak hash
- CVE-2025-93842 PoCsappneta tcpreplay parse_args.c tcpedit_post_args null pointer dereference
- CVE-2025-93852 PoCsappneta tcpreplay tcprewrite edit_packet.c fix_ipv6_checksums use after free
- CVE-2025-93862 PoCsappneta tcpreplay tcprewrite get.c get_l2len_protocol use after free
- CVE-2025-93871 PoCDCN DCME-720 Web Management Backend ip_block.php os command injection
- CVE-2025-93881 PoCScada-LTS watch_list.shtm cross site scripting
- CVE-2025-93892 PoCsvim memmove-vec-unaligned-erms.S __memmove_avx_unaligned_erms memory corruption
- CVE-2025-93902 PoCsvim xxd xxd.c main buffer overflow
- CVE-2025-93911 PoCBjskzy Zhiyou ERP com.artery.workflow.ServiceImpl getFieldValue sql injection
- CVE-2025-93921 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 qosClassifier stack-based overflow
- CVE-2025-93931 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 addStaProfile stack-based overflow
- CVE-2025-93942 PoCsPoDoFo PDF Dictionary PdfTokenizer.cpp DetermineDataType use after free
- CVE-2025-93951 PoCwangsongyan wblog backup.go RestorePost server-side request forgery
- CVE-2025-93962 PoCsckolivas lrzip strtol_l.c __GI_____strtol_l_internal null pointer dereference
- CVE-2025-93971 PoCgivanz Vvveb media.php unrestricted upload
- CVE-2025-93981 PoCYiFang CMS Migrate.php exportInstallTable information disclosure
- CVE-2025-93991 PoCYiFang CMS L_tool.php sql injection
- CVE-2025-94001 PoCYiFang CMS P_file.php mergeMultipartUpload unrestricted upload
- CVE-2025-94011 PoCHuangDou UTCMS Login login.php comparison
- CVE-2025-94021 PoCHuangDou UTCMS Config update.php server-side request forgery
- CVE-2025-94032 PoCsjqlang jq JSON jq_test.c run_jq_tests assertion
- CVE-2025-94041 PoCScada-LTS Folder pointHierarchySLTS cross site scripting
- CVE-2025-94051 PoCOpen5GS gmm-sm.c gmm_state_exception assertion
- CVE-2025-94061 PoCxuhuisheng lemon CmsArticleController.java uploadImage unrestricted upload
- CVE-2025-94071 PoCmtons mblog profile cross site scripting
- CVE-2025-94091 PoClostvip-com ruoyi-go CommonController.go DownloadUpload path traversal
- CVE-2025-94101 PoClostvip-com ruoyi-go GenTableDao.go SelectListByPage sql injection
- CVE-2025-94111 PoClostvip-com ruoyi-go LoginInforService.go SelectPageList sql injection
- CVE-2025-94121 PoClostvip-com ruoyi-go DictDataDao.go SelectListByPage sql injection
- CVE-2025-94131 PoClostvip-com ruoyi-go system_router.go SelectListByPage sql injection
- CVE-2025-94141 PoCkalcaddle kodbox Download from Link serverDownload server-side request forgery
- CVE-2025-94151 PoCGreenCMS index.php unrestricted upload
- CVE-2025-94161 PoCoitcode samarium Pages Image webpage cross site scripting
- CVE-2025-94171 PoCitsourcecode Apartment Management System addemployee.php sql injection
- CVE-2025-94181 PoCitsourcecode Apartment Management System addowner.php sql injection
- CVE-2025-94191 PoCitsourcecode Apartment Management System addunit.php sql injection
- CVE-2025-94201 PoCitsourcecode Apartment Management System addfloor.php sql injection
- CVE-2025-94211 PoCitsourcecode Apartment Management System addcomplain.php sql injection
- CVE-2025-94221 PoCoitcode samarium Team Image team cross site scripting
- CVE-2025-94231 PoCCampcodes Online Water Billing System editecex.php sql injection
- CVE-2025-94241 PoCRuijie WS7204-A branch_import.php os command injection
- CVE-2025-94251 PoCitsourcecode Online Tour and Travel Management System enquiry.php sql injection
- CVE-2025-94261 PoCitsourcecode Online Tour and Travel Management System package.php sql injection
- CVE-2025-94291 PoCmtons mblog Post submit cross site scripting
- CVE-2025-94301 PoCmtons mblog update cross site scripting
- CVE-2025-94311 PoCmtons mblog search cross site scripting
- CVE-2025-94321 PoCmtons mblog Admin Panel list cross site scripting
- CVE-2025-94331 PoCmtons mblog Admin Panel list cross site scripting
- CVE-2025-94341 PoC1000projects Online Project Report Submission and Evaluation System edit_title.php cross site scripting
- CVE-2025-94351 PoCPath Traversal
- CVE-2025-94381 PoC1000projects Online Project Report Submission and Evaluation System add_student.php cross site scripting
- CVE-2025-94391 PoC1000projects Online Project Report Submission and Evaluation System edit_faculty.php cross site scripting
- CVE-2025-94401 PoC1000projects Online Project Report Submission and Evaluation System add_title.php cross site scripting
- CVE-2025-94431 PoCTenda CH22 editUserName formeditUserName buffer overflow
- CVE-2025-94441 PoC1000projects Online Project Report Submission and Evaluation System delete_group_student.php sql injection
- CVE-2025-94611 PoCdiyhi bbs File Compression FilePackageManageAction.java information disclosure
- CVE-2025-94681 PoCitsourcecode Apartment Management System add_bill.php sql injection
- CVE-2025-94691 PoCitsourcecode Apartment Management System add_fund.php sql injection
- CVE-2025-94701 PoCitsourcecode Apartment Management System add_m_committee.php sql injection
- CVE-2025-94711 PoCitsourcecode Apartment Management System add_maintenance_cost.php sql injection
- CVE-2025-94721 PoCitsourcecode Apartment Management System add_owner_utility.php sql injection
- CVE-2025-94731 PoCSourceCodester Online Bank Management System feedback.php sql injection
- CVE-2025-94741 PoCMihomo Party Socket sysproxy.ts enableSysProxy temp file
- CVE-2025-94751 PoCSourceCodester Human Resource Information System editemployee_process.php unrestricted upload
- CVE-2025-94761 PoCSourceCodester Human Resource Information System editemployee_process.php unrestricted upload
- CVE-2025-94781 PoCUse after free in ANGLE in Google Chrome prior to 139.0.7258.154 allowed a remote attacker to potentially exploit heap corruption via a…
- CVE-2025-94811 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 setIpv6 stack-based overflow
- CVE-2025-94821 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 portRangeForwardAdd stack-based overflow
- CVE-2025-94831 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 singlePortForwardAdd stack-based overflow
- CVE-2025-94841 PoCMissing Authorization in GitLab
- CVE-2025-94861 PoCIncorrect Privilege Assignment in GitLab
- CVE-2025-94871 PoCAdmin and Site Enhancements < 7.9.8 - Authenticated Stored XSS via SVG
- CVE-2025-94911 PoCMicrosoft Windows LNK File UI Misrepresentation Remote Code Execution Vulnerability
- CVE-2025-94921 PoCCampcodes Online Water Billing System addclient1.php sql injection
- CVE-2025-95012 PoCsW3 Total Cache < 2.8.13 - Unauthenticated Command Injection
- CVE-2025-95021 PoCCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-95031 PoCCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-95041 PoCCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-95051 PoCCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-95061 PoCCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-95071 PoCitsourcecode Apartment Management System visitor_info.php sql injection
- CVE-2025-95081 PoCitsourcecode Apartment Management System rented_info.php sql injection
- CVE-2025-95091 PoCitsourcecode Apartment Management System fair_info_all.php sql injection
- CVE-2025-95101 PoCitsourcecode Apartment Management System addbranch.php sql injection
- CVE-2025-95111 PoCitsourcecode Apartment Management System addvisitor.php sql injection
- CVE-2025-95121 PoCSchema & Structured Data for WP & AMP < 1.50 - Unauthenticated Stored-XSS
- CVE-2025-95191 PoCEasy Timer <= 4.2.1 - Authenticated (Editor+) Remote Code Execution via Shortcode
- CVE-2025-95231 PoCTenda AC1206 GetParentControlInfo stack-based overflow
- CVE-2025-95251 PoCLinksys E1700 setWan stack-based overflow
- CVE-2025-95261 PoCLinksys E1700 setSysAdm stack-based overflow
- CVE-2025-95271 PoCLinksys E1700 QoSSetup stack-based overflow
- CVE-2025-95281 PoCLinksys E1700 systemCommand os command injection
- CVE-2025-95291 PoCCampcodes Payroll Management System index.php include file inclusion
- CVE-2025-95312 PoCsPortabilis i-Educar Agenda agenda.php sql injection
- CVE-2025-95323 PoCsPortabilis i-Educar view sql injection
- CVE-2025-95331 PoCTOTOLINK T10 formLoginAuth.htm improper authentication
- CVE-2025-95401 PoCMarkup Markdown < 3.20.10 - Contributor+ Stored XSS
- CVE-2025-95411 PoCMarkup Markdown < 3.20.10 - Contributor+ Stored XSS
- CVE-2025-95431 PoCFlexTable Google Sheets Connector < 3.19.2 - Admin+ Stored XSS
- CVE-2025-95441 PoCDoppler Forms <= 2.5.1 - Subscriber+ Limited Plugin Installation
- CVE-2025-95751 PoCLinksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 upload.cgi cgiMain os command injection
- CVE-2025-95761 PoCseeedstudio ReSpeaker Administrative shadow default credentials
- CVE-2025-95771 PoCTOTOLINK X2000R Administrative shadow.sample default credentials
- CVE-2025-95791 PoCLB-LINK BL-X26 HTTP set_hidessid_cfg os command injection
- CVE-2025-95801 PoCLB-LINK BL-X26 HTTP set_blacklist os command injection
- CVE-2025-95811 PoCComfast CF-N1 webmgnt multi_pppoe command injection
- CVE-2025-95821 PoCComfast CF-N1 webmgnt ntp_timezone command injection
- CVE-2025-95831 PoCComfast CF-N1 webmgnt ping_config command injection
- CVE-2025-95841 PoCComfast CF-N1 webmgnt update_interface_png command injection
- CVE-2025-95851 PoCComfast CF-N1 webmgnt wifilith_delete_pic_file command injection
- CVE-2025-95861 PoCComfast CF-N1 webmgnt wireless_device_dissoc command injection
- CVE-2025-95871 PoCCTL Behance Importer Lite <= 1.0 - Unauthenticated SQL Injection
- CVE-2025-95891 PoCCudy WR1200EA shadow default password
- CVE-2025-95901 PoCWeaver E-Mobile Mobile Management Platform cross site scripting
- CVE-2025-95911 PoCZrLog Theme Configuration Form config cross site scripting
- CVE-2025-95921 PoCitsourcecode Apartment Management System bill_info.php sql injection
- CVE-2025-95931 PoCitsourcecode Apartment Management System unit_status_info.php sql injection
- CVE-2025-95941 PoCitsourcecode Apartment Management System complain_info.php sql injection
- CVE-2025-95951 PoCcode-projects Student Information Management System login.php cross site scripting
- CVE-2025-95961 PoCitsourcecode Sports Management System login.php sql injection
- CVE-2025-95971 PoCitsourcecode Apartment Management System rented_all_info.php sql injection
- CVE-2025-95981 PoCitsourcecode Apartment Management System year_setup.php sql injection
- CVE-2025-95991 PoCitsourcecode Apartment Management System month_setup.php sql injection
- CVE-2025-96001 PoCitsourcecode Apartment Management System member_type_setup.php sql injection
- CVE-2025-96011 PoCitsourcecode Apartment Management System employee_salary_setup.php sql injection
- CVE-2025-96021 PoCXinhu RockOA index.php publicsaveAjax improper authorization
- CVE-2025-96031 PoCTelesquare TLR-2005KSH internet.cgi command injection
- CVE-2025-96051 PoCTenda AC21/AC23 GetParentControlInfo stack-based overflow
- CVE-2025-96061 PoCPortabilis i-Educar agenda_preferencias.php sql injection
- CVE-2025-96071 PoCPortabilis i-Educar Tabelas de Arredondamento view sql injection
- CVE-2025-96081 PoCPortabilis i-Educar Formula de Cálculo de Média view sql injection
- CVE-2025-96091 PoCPortabilis i-Educar consulta improper authorization
- CVE-2025-96101 PoCcode-projects Online Event Judging System create_account.php sql injection
- CVE-2025-96421 PoCImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2025-96431 PoCitsourcecode Apartment Management System utility_bill_setup.php sql injection
- CVE-2025-96441 PoCitsourcecode Apartment Management System bill_setup.php sql injection
- CVE-2025-96451 PoCitsourcecode Apartment Management System r_all_info.php sql injection
- CVE-2025-96461 PoCO2OA calendarConfig cross site scripting
- CVE-2025-96471 PoCmtons mblog list cross site scripting
- CVE-2025-96492 PoCsappneta tcpreplay send_packets.c calc_sleep_time divide by zero
- CVE-2025-96501 PoCyeqifu carRental AppFileUtils.java removeFileByPath path traversal
- CVE-2025-96511 PoCshafhasan chatbox chat.php sql injection
- CVE-2025-96522 PoCsPortabilis i-Educar Cadastrar tipo de transferência educar_transferencia_tipo_cad.php cross site scripting
- CVE-2025-96532 PoCsPortabilis i-Educar Cadastrar projeto educar_projeto_cad.php cross site scripting
- CVE-2025-96561 PoCPHPGurukul Directory Management System add-directory.php cross site scripting
- CVE-2025-96571 PoCO2OA Personal Profile script cross site scripting
- CVE-2025-96581 PoCO2OA Personal Profile dict cross site scripting
- CVE-2025-96591 PoCO2OA Personal Profile widget cross site scripting
- CVE-2025-96601 PoCSourceCodester Bakeshop Online Ordering System passwordrecover.php sql injection
- CVE-2025-96621 PoCcode-projects Simple Grading System Admin Panel login.php sql injection
- CVE-2025-96631 PoCcode-projects Simple Grading System Admin Panel edit_account.php sql injection
- CVE-2025-96641 PoCcode-projects Simple Grading System Admin Panel add_student_grade.php sql injection
- CVE-2025-96651 PoCcode-projects Simple Grading System Admin Panel edit_student.php sql injection
- CVE-2025-96661 PoCcode-projects Simple Grading System Admin Panel delete_student.php sql injection
- CVE-2025-96671 PoCcode-projects Simple Grading System Admin Panel delete_account.php sql injection
- CVE-2025-96691 PoCJinher OA GetTreeDate.aspx sql injection
- CVE-2025-96701 PoCmixmark-io turndown commonmark-rules.js redos
- CVE-2025-96711 PoCUAB Paytend App com.passport.cash AndroidManifest.xml improper export of android application components
- CVE-2025-96721 PoCRejseplanen App de.hafas.android.rejseplanen AndroidManifest.xml improper export of android application components
- CVE-2025-96731 PoCKakao 헤이카카오 Hey Kakao App com.kakao.i.connect AndroidManifest.xml improper export of android application components
- CVE-2025-96741 PoCTransbyte Scooper News App com.hatsune.eagleee AndroidManifest.xml improper export of android application components
- CVE-2025-96751 PoCVoice Changer App com.tuyangkeji.changevoice AndroidManifest.xml improper export of android application components
- CVE-2025-96761 PoCNCSOFT Universe App com.ncsoft.universeapp AndroidManifest.xml improper export of android application components
- CVE-2025-96771 PoCModo Legend of the Phoenix com.duige.hzw.multilingual AndroidManifest.xml improper export of android application components
- CVE-2025-96781 PoCCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-96791 PoCitsourcecode Student Information System course_edit1.php sql injection
- CVE-2025-96801 PoCO2OA Personal Profile page cross site scripting
- CVE-2025-96811 PoCO2OA Personal Profile agent cross site scripting
- CVE-2025-96821 PoCO2OA Personal Profile appdict cross site scripting
- CVE-2025-96831 PoCO2OA Personal Profile form cross site scripting
- CVE-2025-96841 PoCPortabilis i-Educar Formula de Cálculo de Média edit sql injection
- CVE-2025-96851 PoCPortabilis i-Educar Listagem de áreas de conhecimento view sql injection
- CVE-2025-96861 PoCPortabilis i-Educar Listagem de áreas de conhecimento edit sql injection
- CVE-2025-96871 PoCPortabilis i-Educar processamentoApi improper authorization
- CVE-2025-96881 PoCMupen64Plus is_viewer.c write_is_viewer integer overflow
- CVE-2025-96891 PoCSourceCodester Advanced School Management System item_select sql injection
- CVE-2025-96901 PoCSourceCodester Advanced School Management System vendordetails sql injection
- CVE-2025-96911 PoCCampcodes Online Shopping System login.php sql injection
- CVE-2025-96921 PoCCampcodes Online Shopping System product.php sql injection
- CVE-2025-96941 PoCCampcodes Advanced Online Voting System login.php sql injection
- CVE-2025-96951 PoCGalleryVault Gallery Vault App com.thinkyeah.galleryvault AndroidManifest.xml improper export of android application components
- CVE-2025-96971 PoCAjax WooSearch <= 1.0.0 - Unauthenticated SQL Injection
- CVE-2025-96981 PoCThe Plus Addons for Elementor < 6.3.16 - Author+ Stored XSS
- CVE-2025-96991 PoCSourceCodester Online Polling System Code checklogin.php sql injection
- CVE-2025-97001 PoCSourceCodester Online Book Store publisher_list.php sql injection
- CVE-2025-97011 PoCSourceCodester Simple Cafe Billing System receipt.php sql injection
- CVE-2025-97021 PoCSourceCodester Simple Cafe Billing System sales_report.php sql injection
- CVE-2025-97031 PoCUltimate Addons for Elementor Lite < 2.5.0 - Author+ Stored XSS
- CVE-2025-97041 PoCSourceCodester Water Billing System viewbill.php sql injection
- CVE-2025-97051 PoCSourceCodester Water Billing System paybill.php sql injection
- CVE-2025-97061 PoCSourceCodester Water Billing System edit.php sql injection
- CVE-2025-97101 PoCResponsive Lightbox & Gallery < 2.5.3 - Unauthenticated Stored-XSS via Comments
- CVE-2025-97151 PoCO2OA Personal Profile script cross site scripting
- CVE-2025-97161 PoCO2OA Personal Profile form cross site scripting
- CVE-2025-97171 PoCO2OA Personal Profile unit cross site scripting
- CVE-2025-97181 PoCO2OA Personal Profile process cross site scripting
- CVE-2025-97191 PoCO2OA Personal Profile script cross site scripting
- CVE-2025-97201 PoCPortabilis i-Educar Cadastrar tabela de arredondamento edit cross site scripting
- CVE-2025-97211 PoCPortabilis i-Educar edit cross site scripting
- CVE-2025-97221 PoCPortabilis i-Educar educar_tipo_ocorrencia_disciplinar_cad.php cross site scripting
- CVE-2025-97231 PoCPortabilis i-Educar educar_tipo_regime_cad.php cross site scripting
- CVE-2025-97241 PoCPortabilis i-Educar educar_nivel_ensino_cad.php cross site scripting
- CVE-2025-97251 PoCCudy LT500E Web shadow hard-coded password
- CVE-2025-97261 PoCCampcodes Farm Management System review.php sql injection
- CVE-2025-97271 PoCD-Link DIR-816L soap.cgi soapcgi_main os command injection
- CVE-2025-97282 PoCsgivanz Vvveb login.tpl cross site scripting
- CVE-2025-97291 PoCPHPGurukul Online Course Registration student-registration.php sql injection
- CVE-2025-97301 PoCitsourcecode Apartment Management System updateProfile.php sql injection
- CVE-2025-97311 PoCTenda AC9 Administrative shadow hard-coded credentials
- CVE-2025-97331 PoCcode-projects Human Resource Integrated System login_timeee.php sql injection
- CVE-2025-97341 PoCO2OA Personal Profile stat cross site scripting
- CVE-2025-97351 PoCO2OA Personal Profile table cross site scripting
- CVE-2025-97361 PoCO2OA Personal Profile statement cross site scripting
- CVE-2025-97371 PoCO2OA Personal Profile importmodel cross site scripting
- CVE-2025-97382 PoCsPortabilis i-Educar educar_tipo_ensino_cad.php cross site scripting
- CVE-2025-97391 PoCCampcodes Online Water Billing System process.php sql injection
- CVE-2025-97401 PoCcode-projects Human Resource Integrated System log_query.php sql injection
- CVE-2025-97411 PoCcode-projects Human Resource Integrated System login_query12.php sql injection
- CVE-2025-97421 PoCcode-projects Human Resource Integrated System login.php sql injection
- CVE-2025-97431 PoCcode-projects Human Resource Integrated System login_attendance2.php sql injection
- CVE-2025-97442 PoCsCampcodes Online Loan Management System ajax.php sql injection
- CVE-2025-97451 PoCD-Link DI-500WF jhttpd version_upgrade.asp os command injection
- CVE-2025-97461 PoCCampcodes Hospital Management System Edit Doctor Specialization edit-doctor-specialization.php cross site scripting
- CVE-2025-97471 PoCKoillection csrf_protection_controller.js cross-site request forgery
- CVE-2025-97481 PoCTenda CH22 httpd IPSECsave fromIpsecitem stack-based overflow
- CVE-2025-97491 PoCHKritesh009 Grocery List Management Web App update.php sql injection
- CVE-2025-97501 PoCCampcodes Online Learning Management System login.php sql injection
- CVE-2025-97511 PoCCampcodes Online Learning Management System login.php sql injection
- CVE-2025-97521 PoCD-Link DIR-852 SOAP Service soap.cgi soapcgi_main os command injection
- CVE-2025-97531 PoCCampcodes Online Hospital Management System Patient Search patient-search.php cross site scripting
- CVE-2025-97541 PoCCampcodes Online Hospital Management System Edit Profile edit-profile.php cross site scripting
- CVE-2025-97551 PoCKhanakag-17 Library Management System index.php cross site scripting
- CVE-2025-97561 PoCPHPGurukul User Management System change-emailid.php sql injection
- CVE-2025-97571 PoCCampcodes/SourceCodester Courier Management System ajax.php login sql injection
- CVE-2025-97582 PoCsdeepakmisal24 Chemical Inventory Management System inventory_form.php sql injection
- CVE-2025-97591 PoCCampcodes/SourceCodester Courier Management System ajax.php signup sql injection
- CVE-2025-97601 PoCPortabilis i-Educar Matricula API matricula improper authorization
- CVE-2025-97611 PoCCampcodes Online Feeds Product Inventory System Login index.php sql injection
- CVE-2025-97631 PoCCampcodes Online Learning Management System student_signup.php sql injection
- CVE-2025-97641 PoCitsourcecode Sports Management System resultdetails.php sql injection
- CVE-2025-97651 PoCitsourcecode Sports Management System tournament_details.php sql injection
- CVE-2025-97661 PoCitsourcecode Sports Management System facilitator.php sql injection
- CVE-2025-97671 PoCitsourcecode Sports Management System sporttype.php sql injection
- CVE-2025-97681 PoCitsourcecode Sports Management System mode.php sql injection
- CVE-2025-97691 PoCD-Link DI-7400G+ mng_platform.asp sub_478D28 command injection
- CVE-2025-97701 PoCCampcodes Hospital Management System Admin Dashboard Login admin sql injection
- CVE-2025-97711 PoCSourceCodester Eye Clinic Management System search_index_Diagnosis.php sql injection
- CVE-2025-97721 PoCRemoteClinic edit.php unrestricted upload
- CVE-2025-97731 PoCRemoteClinic edit.php cross site scripting
- CVE-2025-97741 PoCRemoteClinic edit-patient.php information disclosure
- CVE-2025-97751 PoCRemoteClinic edit-my-profile.php unrestricted upload
- CVE-2025-97761 PoCCatFolders – Tame Your WordPress Media Library by Category <= 2.5.2 - Authenticated (Author+) SQL Injection via CSV Import
- CVE-2025-97781 PoCTenda W12 Administrative shadow hard-coded credentials
- CVE-2025-97791 PoCTOTOLINK A702R formFilter sub_4162DC buffer overflow
- CVE-2025-97801 PoCTOTOLINK A702R formIpQoS sub_419BE0 buffer overflow
- CVE-2025-97811 PoCTOTOLINK A702R formFilter sub_4162DC buffer overflow
- CVE-2025-97821 PoCTOTOLINK A702R formOneKeyAccessButton sub_4466F8 buffer overflow
- CVE-2025-97831 PoCTOTOLINK A702R formParentControl sub_418030 buffer overflow
- CVE-2025-97841 PoCUndertow: undertow madeyoureset http/2 ddos vulnerability
- CVE-2025-97861 PoCCampcodes Online Learning Management System teacher_signup.php sql injection
- CVE-2025-97881 PoCSourceCodester/Campcodes School Log Management System admin_class.php sql injection
- CVE-2025-97891 PoCSourceCodester Online Hotel Reservation System edituser.php sql injection
- CVE-2025-97901 PoCSourceCodester Hotel Reservation System updateabout.php sql injection
- CVE-2025-97911 PoCTenda AC20 fromAdvSetMacMtuWan stack-based overflow
- CVE-2025-97921 PoCitsourcecode Apartment Management System e_all_info.php sql injection
- CVE-2025-97931 PoCitsourcecode Apartment Management System Setting admin.php sql injection
- CVE-2025-97942 PoCsCampcodes Computer Sales and Inventory System pos_transac.php sql injection
- CVE-2025-97951 PoCxujeff tianti 天梯 UploadController.java ajaxUploadFile unrestricted upload
- CVE-2025-97961 PoCthinkgem JeeSite EncodeUtils.java decodeUrl2 cross site scripting
- CVE-2025-97971 PoCmrvautin expressCart Edit Product edit injection
- CVE-2025-97991 PoCLangfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery
- CVE-2025-98001 PoCSimStudioAI sim HTML File route.ts import unrestricted upload
- CVE-2025-98011 PoCSimStudioAI sim path traversal
- CVE-2025-98051 PoCSimStudioAI sim route.ts server-side request forgery
- CVE-2025-98061 PoCTenda F1202 Administrative shadow hard-coded credentials
- CVE-2025-98081 PoCThe Events Calendar <= 6.15.2 - Missing Authorization to Unauthenticated Password-Protected Information Disclosure
- CVE-2025-98111 PoCCampcodes Farm Management System reviewInput.php sql injection
- CVE-2025-98121 PoCTenda CH22 exeCommand formexeCommand buffer overflow
- CVE-2025-98131 PoCTenda CH22 SetSambaConf formSetSambaConf buffer overflow
- CVE-2025-98141 PoCPHPGurukul Beauty Parlour Management System contact-us.php sql injection
- CVE-2025-98151 PoCalaneuler batteryKid NSXPCListener PrivilegeHelper.swift missing authentication
- CVE-2025-98161 PoCWP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header
- CVE-2025-98251 PoCMissing Authorization in GitLab
- CVE-2025-98281 PoCTenda CP6 uhttp sub_2B7D04 risky encryption
- CVE-2025-98291 PoCPHPGurukul Beauty Parlour Management System signup.php sql injection
- CVE-2025-98301 PoCPHPGurukul Beauty Parlour Management System add-customer-services.php sql injection
- CVE-2025-98311 PoCPHPGurukul Beauty Parlour Management System edit-services.php sql injection
- CVE-2025-98321 PoCSourceCodester Food Ordering Management System register-router.php sql injection
- CVE-2025-98331 PoCSourceCodester Online Farm Management System login.php sql injection
- CVE-2025-98341 PoCPHPGurukul Small CRM registration.php cross site scripting
- CVE-2025-98351 PoCmacrozheng mall cancelUserOrder cancelOrder authorization
- CVE-2025-98361 PoCmacrozheng mall paySuccess authorization
- CVE-2025-98371 PoCitsourcecode Student Information Management System index.php sql injection
- CVE-2025-98381 PoCitsourcecode Student Information Management System index.php sql injection
- CVE-2025-98391 PoCitsourcecode Student Information Management System index.php sql injection
- CVE-2025-98401 PoCitsourcecode Sports Management System gametype.php sql injection
- CVE-2025-98411 PoCcode-projects Mobile Shop Management System AddNewProduct.php unrestricted upload
- CVE-2025-98421 PoCDas Parking Management System 停车场管理系统 Search information disclosure
- CVE-2025-98431 PoCDas Parking Management System 停车场管理系统 FindAll information disclosure
- CVE-2025-98451 PoCcode-projects Fruit Shop Management System products.php cross site scripting
- CVE-2025-98471 PoCScriptAndTools Real Estate Management System register.php unrestricted upload
- CVE-2025-98481 PoCScriptAndTools Real Estate Management System userlist.php redirect
- CVE-2025-98621 PoCGhost 6.0.6 - SSRF via oEmbed Bookmark
- CVE-2025-99052 PoCsArbitary Code execution in Keras load_model()
- CVE-2025-99191 PoC1000projects Beauty Parlour Management System bwdates-reports-details.php sql injection
- CVE-2025-99201 PoCCampcodes Recruitment Management System index.php include file inclusion
- CVE-2025-99211 PoCcode-projects POS Pharmacy System products.php cross site scripting
- CVE-2025-99221 PoCCampcodes Sales and Inventory System index.php cross site scripting
- CVE-2025-99231 PoCCampcodes Sales and Inventory System index.php cross site scripting
- CVE-2025-99241 PoCprojectworlds Travel Management System enquiry.php sql injection
- CVE-2025-99251 PoCprojectworlds Travel Management System detail.php sql injection
- CVE-2025-99261 PoCprojectworlds Travel Management System viewsubcategory.php sql injection
- CVE-2025-99271 PoCprojectworlds Travel Management System viewpackage.php sql injection
- CVE-2025-99281 PoCprojectworlds Travel Management System viewcategory.php sql injection
- CVE-2025-99291 PoCcode-projects Responsive Blog Site blogs_view.php cross site scripting
- CVE-2025-99301 PoC1000projects Beauty Parlour Management System contact-us.php sql injection
- CVE-2025-99311 PoCJinher OA POST Request login!changePassWord.action cross site scripting
- CVE-2025-99321 PoCPHPGurukul Beauty Parlour Management System update-image.php sql injection
- CVE-2025-99332 PoCsPHPGurukul Beauty Parlour Management System view-appointment.php sql injection
- CVE-2025-99341 PoCTOTOLINK X5000R cstecgi.cgi sub_410C34 command injection
- CVE-2025-99351 PoCTOTOLINK N600R cstecgi.cgi sub_4159F8 command injection
- CVE-2025-99361 PoCfuyang_lipengjun platform queryAll AdController improper authorization
- CVE-2025-99371 PoCelunez eladmin LocalStorageController deleteFile improper authorization
- CVE-2025-99381 PoCD-Link DI-8400 yyxz.asp yyxz_dlink_asp stack-based overflow
- CVE-2025-99391 PoCCodeAstro Real Estate Management System propertyview.php cross site scripting
- CVE-2025-99401 PoCCodeAstro Real Estate Management System feature.php cross site scripting
- CVE-2025-99411 PoCCodeAstro Real Estate Management System register.php unrestricted upload
- CVE-2025-99421 PoCCodeAstro Real Estate Management System submitproperty.php unrestricted upload
- CVE-2025-99511 PoCRemote code execution via Heap Buffer Overflow in FFmpeg JPEG2000
- CVE-2025-99571 PoCIncorrect Authorization in GitLab
- CVE-2025-99581 PoCInsertion of Sensitive Information Into Sent Data in GitLab
- CVE-2025-99611 PoCAuthenticated RCE by CWMP binary
- CVE-2025-99741 PoCInsufficient Input Validation on WEBUI in Nokia ONT/Beacon product
- CVE-2025-99781 PoCJeg Elementor Kit < 2.7.0 - Author+ Stored XSS
- CVE-2025-99831 PoCLack of Authentication for RTSP stream
- CVE-2025-99851 PoCFeatured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File
- CVE-2025-99981 PoCImproper validation of packets sequencing