Total CVEs

138,943

Critical Severity

3,617

High Severity

12,982

Last 7 Days

947
Quick preset (or use dates below)
Clear Filters
Showing 3,101 - 3,120 of 12,982 CVEs
CVE-2018-25374 HIGH - 7.5

Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access ...

Vendor: Softneta
Product: MedDream PACS Server Premium
Published: May 25, 2026
Source: NVD
CVE-2018-25373 HIGH - 8.4

SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious text file with carefully constructed p...

Vendor: SocuSoft
Product: DVD Photo Slideshow Professional
Published: May 25, 2026
Source: NVD
CVE-2018-25372 HIGH - 8.2

MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Attackers can submit crafted POST requests to the userSignup.php endpoint with SQL payloads in ...

Vendor: MedDream
Product: PACS Server Premium
Published: May 25, 2026
Source: NVD
CVE-2018-25371 HIGH - 8.2

mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniq...

Vendor: Moosocial
Product: mooSocial Store Plugin
Published: May 25, 2026
Source: NVD
CVE-2018-25368 HIGH - 7.5

Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash...

Vendor: Nordvpn
Product: NordVPN
Published: May 25, 2026
Source: NVD
CVE-2018-25366 HIGH - 8.4

CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut ...

Vendor: globalscape
Product: CuteFTP
Published: May 25, 2026
Source: NVD
CVE-2018-25365 HIGH - 7.5

PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use path traversal sequences ../../../../../../../../../../../../etc/passwd to access sensitive system files...

Vendor: PCViewer
Product: PCViewer
Published: May 25, 2026
Source: NVD
CVE-2018-25364 HIGH - 8.2

Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the name parameter. Attackers can submit crafted payloads to the search.php endpoint to extract database information including usernames, ...

Vendor: Fyffe
Product: PHP-Twitter-Clone
Published: May 25, 2026
Source: NVD
CVE-2018-25362 HIGH - 8.2

Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information includin...

Vendor: Fyffe
Product: PHP-Twitter-Clone
Published: May 25, 2026
Source: NVD
CVE-2018-25360 HIGH - 8.4

AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and jump instructions ...

Vendor: Agatasoft
Product: Auto PingMaster
Published: May 25, 2026
Source: NVD
CVE-2018-25359 HIGH - 8.4

Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable...

Vendor: Splinterware
Product: Splinterware System Scheduler Pro
Published: May 25, 2026
Source: NVD
CVE-2026-9461 HIGH - 8.8

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly an...

Published: May 25, 2026
Source: NVD
CVE-2026-9460 HIGH - 8.8

A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made availabl...

Published: May 25, 2026
Source: NVD
CVE-2026-9459 HIGH - 8.8

A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow. It is possible to initiate the attack remotely....

Published: May 25, 2026
Source: NVD
CVE-2026-9453 HIGH - 7.3

A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/application/skills-loader.ts of the component SkillsLoader. Performing a manipulation of the argument requires.bins results in command injection. The ...

Published: May 25, 2026
Source: NVD
CVE-2026-9452 HIGH - 7.3

A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit...

Published: May 25, 2026
Source: NVD
CVE-2026-9447 HIGH - 7.3

A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Name results in sql injection. The attack is possible to be carried out remotely. The exploit has been ...

Published: May 25, 2026
Source: NVD
CVE-2026-9443 HIGH - 8.8

A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The manipulation of the argument L2TPUserName leads to buffer overflow. The attack may be initiated remo...

Published: May 25, 2026
Source: NVD
CVE-2026-9442 HIGH - 8.8

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipulation of the argument selSSID can lead to buffer overflow. The attack can be launched remotely. The e...

Published: May 25, 2026
Source: NVD
CVE-2026-45361 HIGH - 8.1

Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advised to upgrade to `apache-airflow-pr...

Vendor: Apache Software Foundation
Product: Apache Airflow Google provider
Published: May 25, 2026
Source: NVD