Total CVEs

139,442

Critical Severity

3,643

High Severity

13,079

Last 7 Days

1,302
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,001 - 7,020 of 12,776 CVEs
CVE-2026-4272 HIGH - 8.1

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK0007...

Published: Apr 05, 2026
Source: NVD
CVE-2019-25704 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. Attackers can send crafted requests with malicious SQL statements to extract sensitive database information or modify data.

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25702 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database informat...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25700 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL statements in the sort_direction parameter to extract sensitive database information or modif...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25698 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive databas...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25696 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify da...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25694 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted requests with malicious SQL payloads to extract sensitive database information or modify ...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25692 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_modify field to extract sensitive datab...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25690 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database in...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25688 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive datab...

Vendor: Kados
Product: Kados GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25686 HIGH - 7.5

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violatio...

Vendor: Coreftp
Product: Core FTP
Published: Apr 05, 2026
Source: NVD
CVE-2019-25685 HIGH - 8.8

phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserial...

Vendor: phpBB
Product: phpBB
Published: Apr 05, 2026
Source: NVD
CVE-2019-25684 HIGH - 8.2

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to...

Vendor: opendocman
Product: OpenDocMan
Published: Apr 05, 2026
Source: NVD
CVE-2019-25681 HIGH - 8.4

Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual s...

Vendor: Xlightftpd
Product: Xlight
Published: Apr 05, 2026
Source: NVD
CVE-2019-25680 HIGH - 8.2

Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to e...

Vendor: Phpscriptsmall
Product: Advance Gift Shop Pro Script
Published: Apr 05, 2026
Source: NVD
CVE-2019-25679 HIGH - 7.8

RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain an...

Vendor: Realterm
Product: RealTerm: Serial Terminal
Published: Apr 05, 2026
Source: NVD
CVE-2019-25678 HIGH - 8.2

C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the site parameter. Attackers can send GET requests to the users_select.php endpoint with crafted SQL...

Vendor: C4G
Product: Basic Laboratory Information System
Published: Apr 05, 2026
Source: NVD
CVE-2019-25676 HIGH - 8.2

Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view param...

Vendor: Phpscriptsmall
Product: Ask Expert Script
Published: Apr 05, 2026
Source: NVD
CVE-2019-25675 HIGH - 8.2

eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters. Attackers can exploit the key parameter in the login endpoint with union-based SQL injection to a...

Vendor: edirectory
Product: eDirectory
Published: Apr 05, 2026
Source: NVD
CVE-2019-25674 HIGH - 8.2

CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database info...

Vendor: VictorAlagwu
Product: CMSsite
Published: Apr 05, 2026
Source: NVD