Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | ASP.NET Core 2.3 | 2.3 ~ 2.3.6 | - | |
| Microsoft | ASP.NET Core 8.0 | 8.0 ~ 8.0.21 | - | |
| Microsoft | ASP.NET Core 9.0 | 9.0 ~ 9.0.10 | - | |
| Microsoft | Microsoft Visual Studio 2022 version 17.10 | 17.10.0 ~ 17.10.20 | - | |
| Microsoft | Microsoft Visual Studio 2022 version 17.12 | 17.12.0 ~ 17.12.13 | - | |
| Microsoft | Microsoft Visual Studio 2022 version 17.14 | 17.14.0 ~ 17.14.17 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Playground to experiment with different behavior on patched/unpatched Kestrel for the CVE-2025-55315 HTTP smuggling vulnerability | https://github.com/nickcopi/CVE-2025-55315-detection-playground | POC Details |
| 2 | None | https://github.com/sirredbeard/CVE-2025-55315-repro | POC Details |
| 3 | None | https://github.com/snowcrashlord/CVE-2025-55315 | POC Details |
| 4 | None | https://github.com/RootAid/CVE-2025-55315 | POC Details |
| 5 | None | https://github.com/digitalsnemesis/CVE-2025-55315 | POC Details |
| 6 | 专业级HTTP请求走私漏洞利用与自动化渗透测试工具 | https://github.com/7huukdlnkjkjba/CVE-2025-55315- | POC Details |
| 7 | Quick and Simple Scripts to Scan for Vulnerable Servers and Packet Level Monitors | https://github.com/jlinebau/CVE-2025-55315-Scanner-Monitor | POC Details |
| 8 | None | https://github.com/blackquantas/CVE-2025-55315 | POC Details |
| 9 | CVE-2025-55315 PoC Exploit | https://github.com/ZemarKhos/CVE-2025-55315-PoC-Exploit | POC Details |
| 10 | Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle requests past proxies and load balancers in vulnerable ASP.NET Core/Kestrel servers. | https://github.com/MartinFabianIonut/CVE-2025-55315 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-49708 | 9.9 CRITICAL | Microsoft Graphics Component Elevation of Privilege Vulnerability |
| CVE-2025-59287 | 9.8 CRITICAL | Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
| CVE-2025-58718 | 8.8 HIGH | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2025-58715 | 8.8 HIGH | Windows Speech Runtime Elevation of Privilege Vulnerability |
| CVE-2025-58716 | 8.8 HIGH | Windows Speech Runtime Elevation of Privilege Vulnerability |
| CVE-2025-59228 | 8.8 HIGH | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2025-59295 | 8.8 HIGH | Windows URL Parsing Remote Code Execution Vulnerability |
| CVE-2025-59213 | 8.8 HIGH | Configuration Manager Elevation of Privilege Vulnerability |
| CVE-2025-59237 | 8.8 HIGH | Microsoft SharePoint Remote Code Execution Vulnerability |
| CVE-2025-59249 | 8.8 HIGH | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2025-53782 | 8.4 HIGH | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2025-59236 | 8.4 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2025-59291 | 8.2 HIGH | Confidential Azure Container Instances Elevation of Privilege Vulnerability |
| CVE-2025-59292 | 8.2 HIGH | Azure Compute Gallery Elevation of Privilege Vulnerability |
| CVE-2025-59250 | 8.1 HIGH | JDBC Driver for SQL Server Spoofing Vulnerability |
| CVE-2025-55696 | 7.8 HIGH | NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability |
| CVE-2025-59277 | 7.8 HIGH | Windows Authentication Elevation of Privilege Vulnerability |
| CVE-2025-55694 | 7.8 HIGH | Windows Error Reporting Service Elevation of Privilege Vulnerability |
| CVE-2025-53150 | 7.8 HIGH | Windows Digital Media Elevation of Privilege Vulnerability |
| CVE-2025-59207 | 7.8 HIGH | Windows Kernel Elevation of Privilege Vulnerability |
Showing top 20 of 167 CVEs. View all on vendor page → →
No comments yet