Total CVEs

124,116

Critical Severity

2,092

High Severity

7,265

Last 7 Days

1,051
Quick preset (or use dates below)
Clear Filters
๐Ÿ“† Custom Date Range: Apr 4, 2026 - Apr 4, 2026 Clear Custom Dates โ†’
Showing 1 - 20 of 77 CVEs
CVE-2026-5526 HIGH - 7.3

A security flaw has been discovered in Tenda 4G03 Pro up to 1.0/1.1/04.03.01.53/192.168.0.1. Affected by this vulnerability is an unknown functionality of the file /bin/httpd. The manipulation results in improper access controls. The attack may be performed from remote. The exploit has been released...

Published: Apr 04, 2026
Source: NVD
CVE-2018-25246 HIGH - 7.5

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated characters into the search bar to trigger an application crash.

Vendor: Wikipedia
Product: Wikipedia
Published: Apr 04, 2026
Source: NVD
CVE-2016-20054 MEDIUM - 4.3

Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious forms. Attackers can trick authenticated administrators into submitting requests to admin/user_manipulate and admin/settings/generall endpoints to cre...

Vendor: nodcms
Product: nodCMS
Published: Apr 04, 2026
Source: NVD
CVE-2018-25255 HIGH - 8.4

10-Strike LANState 8.8 contains a local buffer overflow vulnerability in structured exception handling that allows local attackers to execute arbitrary code by crafting malicious LSM map files. Attackers can create a specially formatted LSM file with a payload in the ObjCaption parameter that overfl...

Vendor: 10-Strike
Product: Strike LANState
Published: Apr 04, 2026
Source: NVD
CVE-2018-25254 CRITICAL - 9.8

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect...

Vendor: nico-ftp
Product: NICO-FTP
Published: Apr 04, 2026
Source: NVD
CVE-2018-25253 MEDIUM - 6.2

Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. Attackers can paste a 2000-byte payload into the Settings User interface language field to crash the ap...

Vendor: Compuphase
Product: Termite
Published: Apr 04, 2026
Source: NVD
CVE-2018-25252 MEDIUM - 6.2

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP fie...

Vendor: Serv-U
Product: FTP Voyager
Published: Apr 04, 2026
Source: NVD
CVE-2018-25251 HIGH - 8.4

Snes9K 0.0.9z contains a buffer overflow vulnerability in the Netplay Socket Port Number field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Socket Port Number field via the Netplay Options menu to...

Vendor: Sourceforge
Product: Snes9K 0.0.9z
Published: Apr 04, 2026
Source: NVD
CVE-2018-25250 HIGH - 7.2

MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags. Attackers can create threads with script payloads in the subject field that execute when users ...

Vendor: MyBB
Product: MyBB Last User's Threads in Profile Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2018-25249 MEDIUM - 6.4

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add crafted HTML and JavaScript payloads in the comment field that execute when other users view or edit th...

Vendor: MyBB
Product: MyBB My Arcade Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2018-25248 HIGH - 7.2

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a new download with HTML/JavaScript code in the title parameter, which executes when administrators vali...

Vendor: MyBB
Product: MyBB Downloads Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2018-25247 MEDIUM - 6.1

MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can craft post subjects containing script tags that execute when other users view the attacker's profil...

Vendor: MyBB
Product: MyBB Like Plugin
Published: Apr 04, 2026
Source: NVD
CVE-2018-25245 HIGH - 7.5

Microsoft 7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 7700 characters into the search bar to trigger an application crash.

Vendor: 7Tik
Product: 7 Tik
Published: Apr 04, 2026
Source: NVD
CVE-2018-25244 MEDIUM - 6.2

Microsoft Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar and trigger a crash by initiat...

Vendor: EcoSearch
Product: Eco Search
Published: Apr 04, 2026
Source: NVD
CVE-2018-25243 MEDIUM - 6.2

Microsoft FastTube 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 1900 characters into the search bar and trigger a crash when the search ope...

Vendor: FastTube
Product: FastTube
Published: Apr 04, 2026
Source: NVD
CVE-2018-25242 MEDIUM - 6.2

Microsoft One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar to trigger an unhandled ex...

Vendor: OneSearch
Product: One Search
Published: Apr 04, 2026
Source: NVD
CVE-2018-25241 HIGH - 7.5

Microsoft VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled except...

Vendor: VPNBrowser
Product: VPN Browser+
Published: Apr 04, 2026
Source: NVD
CVE-2018-25240 MEDIUM - 6.2

Microsoft Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 8145 characters into the search bar and trigger a search operation to cause t...

Vendor: Watchr
Product: Watchr
Published: Apr 04, 2026
Source: NVD
CVE-2018-25239 MEDIUM - 6.2

Microsoft Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that...

Vendor: SmartVPN
Product: Smart VPN
Published: Apr 04, 2026
Source: NVD
CVE-2018-25238 MEDIUM - 6.2

Microsoft VSCO 1.1.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string through the search functionality. Attackers can paste a buffer of 5000 characters into the search bar and navigate back to trigger an applic...

Vendor: vsco
Product: VSCO
Published: Apr 04, 2026
Source: NVD