Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,645
Quick preset (or use dates below)
Clear Filters
Showing 7,301 - 7,320 of 13,935 CVEs
CVE-2026-5597 MEDIUM - 6.3

A flaw has been found in griptape-ai griptape 0.19.4. This affects an unknown part of the file griptape\tools\computer\tool.py of the component ComputerTool. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack remotely. The exploit has be...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5596 MEDIUM - 6.3

A vulnerability was detected in griptape-ai griptape 0.19.4. Affected by this issue is some unknown functionality of the file griptape/tools/sql/tool.py of the component SqlTool. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit is now pu...

Published: Apr 05, 2026
Source: NVD
CVE-2019-25683 MEDIUM - 6.2

FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by ...

Vendor: Filezilla-Project
Product: FileZilla
Published: Apr 05, 2026
Source: NVD
CVE-2019-25682 MEDIUM - 4.3

CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with...

Vendor: VictorAlagwu
Product: CMSsite
Published: Apr 05, 2026
Source: NVD
CVE-2019-25677 MEDIUM - 6.2

WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation a...

Vendor: Win-Rar
Product: WinRAR
Published: Apr 05, 2026
Source: NVD
CVE-2019-25667 MEDIUM - 6.2

TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registratio...

Vendor: Iarsn
Product: TaskInfo
Published: Apr 05, 2026
Source: NVD
CVE-2019-25666 MEDIUM - 6.2

SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.

Vendor: Nsauditor
Product: SpotAuditor
Published: Apr 05, 2026
Source: NVD
CVE-2019-25665 MEDIUM - 6.2

River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to activation fields. Attackers can paste 300 bytes of data into the Email textbox and Activation code textarea via the Help menu's...

Vendor: Riverpast
Product: River Past Ringtone Converter
Published: Apr 05, 2026
Source: NVD
CVE-2019-25661 MEDIUM - 6.2

Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the a...

Vendor: Lizardsystems
Product: Remote Process Explorer
Published: Apr 05, 2026
Source: NVD
CVE-2019-25660 MEDIUM - 6.2

LanHelper 1.74 contains a local buffer overflow vulnerability that allows attackers to crash the application by sending excessively long input strings. Attackers can exploit the Form Send Message feature by pasting 6000 bytes of data into the Message text field to trigger a denial of service conditi...

Vendor: Hainsoft
Product: LanHelper
Published: Apr 05, 2026
Source: NVD
CVE-2019-25659 MEDIUM - 6.2

ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application cra...

Vendor: Xlinesoft
Product: ASPRunner Professional
Published: Apr 05, 2026
Source: NVD
CVE-2019-25658 MEDIUM - 5.5

a-Mac Address Change 5.4 contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input to registration form fields. Attackers can paste 212 bytes of data into the 'Your Name', 'Your Company', or 'Register Cod...

Vendor: Amac
Product: Mac Address Change
Published: Apr 05, 2026
Source: NVD
CVE-2019-25657 MEDIUM - 5.5

AnyBurn 4.3 x86 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the image conversion function. Attackers can paste a large buffer into the source or destination image file fields and click Convert Now to trigg...

Vendor: Anyburn
Product: AnyBurn x86
Published: Apr 05, 2026
Source: NVD
CVE-2018-25256 MEDIUM - 5.5

IP TOOLS 2.50 contains a local buffer overflow vulnerability in the SNMP Scanner component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data into the 'From Addr' and 'To Addr' fields and trigger the crash by clic...

Vendor: Ks-Soft
Product: IP TOOLS
Published: Apr 05, 2026
Source: NVD
CVE-2026-5595 MEDIUM - 6.3

A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save_content_to_file/save_memory_artifacts_to_disk of the component FileManagerTool. Such manipulation leads to path traversal. The atta...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5594 MEDIUM - 6.3

A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.py. This manipulation of the argument result causes code injection. The attack is possible to be carried out remotely. The exploit has been made availab...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5587 MEDIUM - 6.3

A vulnerability was identified in wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4. This affects the function _execute_sql of the file core/agents.py of the component Refiner Agent. The manipulation leads to sql injection. Remote exploitation of the attack is possible. The exploit...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5586 MEDIUM - 6.3

A vulnerability was determined in zhongyu09 openchatbi up to 0.2.1. The impacted element is an unknown function of the component Multi-stage Text2SQL Workflow. Executing a manipulation of the argument keywords can lead to sql injection. The attack may be launched remotely. The exploit has been publi...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5585 MEDIUM - 5.3

A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of the component Task Detail Endpoint. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has ...

Published: Apr 05, 2026
Source: NVD
CVE-2026-5583 MEDIUM - 6.3

A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /my-profile.php of the component Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. ...

Published: Apr 05, 2026
Source: NVD