Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,758
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 5,081 - 5,100 of 12,590 CVEs

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version 0.31.7.0, a theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote ...

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40902 HIGH - 7.5

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRowAttributes() method reads row numbers from XML attributes without validating them against the spreadsheet maximum r...

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40863 HIGH - 7.5

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does not validate the ss:Index row attribute against the maximum allowed row count (AddressRange::MAX_ROW = 1,048,576). An atta...

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-34084 HIGH - 9.8

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wra...

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7426 HIGH - 8.1

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length...

Vendor: amazon
Product: freertos-plus-tcp
Published: Apr 29, 2026
Source: NVD
CVE-2026-7400 HIGH - 7.3

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_tool. Such manipulation leads to path traversal. The attack can be launched remotely. The exploit has...

Published: Apr 29, 2026
Source: NVD
CVE-2026-34965 HIGH - 8.8

Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP c...

Vendor: Cockpit
Product: Cockpit CMS
Published: Apr 29, 2026
Source: NVD
CVE-2018-25315 HIGH - 8.4

Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with structured exception handler (SEH) overwrite and shellcode to achieve code exec...

Vendor: Alloksoft
Product: Video Joiner
Published: Apr 29, 2026
Source: NVD
CVE-2018-25314 HIGH - 8.4

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handle...

Vendor: Alloksoft
Product: WMV to AVI MPEG DVD WMV Converter
Published: Apr 29, 2026
Source: NVD
CVE-2018-25309 HIGH - 7.2

MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers o...

Vendor: mybb
Product: MyBB Recent threads
Published: Apr 29, 2026
Source: NVD
CVE-2018-25308 HIGH - 8.8

BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attackers can modify the field_hiddenfile and field_deleteimg parameters during profile editing to unlink f...

Vendor: donmik
Product: Buddypress Xprofile Custom Fields Type
Published: Apr 29, 2026
Source: NVD
CVE-2018-25307 HIGH - 8.4

SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key. Attackers can inject shellcode through the Unlock Key field during registration to execute arbitrar...

Vendor: Sysgauge
Product: SysGauge Pro
Published: Apr 29, 2026
Source: NVD
CVE-2018-25304 HIGH - 8.4

Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > ...

Vendor: Filehippo
Product: Free Download Manager
Published: Apr 29, 2026
Source: NVD
CVE-2018-25303 HIGH - 8.4

Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input string with 780 bytes of junk da...

Vendor: Alloksoft
Product: Allok Video to DVD Burner
Published: Apr 29, 2026
Source: NVD
CVE-2018-25302 HIGH - 7.8

Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, ...

Vendor: Alloksoft
Product: Allok AVI to DVD SVCD VCD Converter
Published: Apr 29, 2026
Source: NVD
CVE-2018-25301 HIGH - 8.4

Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious username string. Attackers can craft a payload containing junk data, SEH chain pointers, and shellcode that...

Vendor: Easy MPEG
Product: Easy MPEG to DVD Burner
Published: Apr 29, 2026
Source: NVD
CVE-2018-25300 HIGH - 8.2

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.

Vendor: xataboost
Product: XATABoost CMS
Published: Apr 29, 2026
Source: NVD
CVE-2018-25299 HIGH - 8.4

Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger ...

Vendor: Mersenne
Product: Prime95
Published: Apr 29, 2026
Source: NVD
CVE-2026-7466 HIGH - 8.8

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to lo...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7424 HIGH - 8.1

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware res...

Vendor: amazon
Product: freertos-plus-tcp
Published: Apr 29, 2026
Source: NVD