Total CVEs

125,743

Critical Severity

2,263

High Severity

7,843

Last 7 Days

1,200
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 721 - 740 of 22,148 CVEs
CVE-2018-25281 MEDIUM - 5.5

iCash 7.6.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload through the Connect to Server dialog. Attackers can paste a 7000-byte string into the Host field and click Connect to trigger an application crash.

Vendor: Maxprog
Product: iCash
Published: Apr 26, 2026
Source: NVD
CVE-2018-25280 MEDIUM - 5.5

Infiltrator Network Security Scanner 4.6 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste a 6000-byte payload into the Scan Target field and trigger a denial of service condition when the Scan bu...

Vendor: Infiltration-Systems
Product: Infiltrator Network Security Scanner
Published: Apr 26, 2026
Source: NVD
CVE-2018-25279 MEDIUM - 6.2

jiNa OCR Image to Text 1.0 contains a denial of service vulnerability that allows local attackers to crash the application by processing a malformed PNG file. Attackers can create a specially crafted PNG file with an oversized buffer and trigger the crash when the application attempts to convert the...

Vendor: Convertimagetotext
Product: jiNa OCR Image to Text
Published: Apr 26, 2026
Source: NVD
CVE-2018-25278 MEDIUM - 6.2

PicaJet FX 2.6.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to registration fields. Attackers can paste a 6000-byte buffer into the Registration Name and Registration Key fields via the Help menu's Register PicaJ...

Vendor: Picajet
Product: PicaJet FX
Published: Apr 26, 2026
Source: NVD
CVE-2018-25277 MEDIUM - 6.2

PixGPS 1.1.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized string to the folder path input field. Attackers can craft a payload exceeding 6000 bytes and paste it into the 'Folder with picture files' field to trigger ...

Vendor: Br-Software
Product: PixGPS
Published: Apr 26, 2026
Source: NVD
CVE-2018-25276 MEDIUM - 5.5

RoboImport 1.2.0.72 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to registration fields. Attackers can paste a 6000-byte buffer into the Registration Name and Registration Key fields and click Register to trigger an app...

Vendor: Picajet
Product: RoboImport
Published: Apr 26, 2026
Source: NVD
CVE-2018-25275 MEDIUM - 6.2

Faleemi Plus 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can paste a 2000-byte payload into the Camera name and DID number fields during camera addition to trigger an application crash.

Vendor: faleemi
Product: Faleemi Plus
Published: Apr 26, 2026
Source: NVD
CVE-2018-25274 MEDIUM - 6.2

InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by importing a maliciously crafted text file. Attackers can create a text file containing 6000 bytes of data and import it through the Edit menu's Import function to trigger an app...

Vendor: infrarecorder
Product: InfraRecorder
Published: Apr 26, 2026
Source: NVD
CVE-2018-25273 MEDIUM - 6.2

CrossFont 7.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by submitting an oversized payload in the License Key field. Attackers can generate a malicious file containing 4000 bytes of data, paste it into the License Key input field, and trigger an ap...

Vendor: Acutesystems
Product: CrossFont
Published: Apr 26, 2026
Source: NVD
CVE-2018-25264 MEDIUM - 6.2

TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to crash the application by submitting an oversized string. Attackers can generate a payload file containing 4000 bytes of data, paste it into the License Key field, and trigger a denial...

Vendor: Acutesystems
Product: TransMac
Published: Apr 26, 2026
Source: NVD
CVE-2018-25263 HIGH - 8.4

Faleemi Desktop Software 1.8.2 contains a local buffer overflow vulnerability in the Device alias field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Device alias field within the Managing Log inte...

Vendor: faleemi
Product: Faleemi Desktop Software
Published: Apr 26, 2026
Source: NVD
CVE-2026-7041 LOW - 3.7

A vulnerability was detected in 666ghj MiroFish up to 0.1.2. The impacted element is an unknown function of the file /console of the component Werkzeug Debugger PIN Handler. Performing a manipulation of the argument SECRET results in information disclosure. It is possible to initiate the attack remo...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7039 HIGH - 7.8

A security vulnerability has been detected in tufantunc ssh-mcp up to 1.5.0. The affected element is the function shell.write of the file src/index.ts. Such manipulation of the argument Description leads to command injection. The attack must be carried out locally. The exploit has been disclosed pub...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7038 LOW - 3.3

A weakness has been identified in tufantunc ssh-mcp up to 1.5.0. Impacted is an unknown function of the file src/index.ts of the component Command Line Handler. This manipulation causes insufficiently protected credentials. The attack is restricted to local execution. The exploit has been made avail...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7037 CRITICAL - 9.8

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru results in os command injection. The attack can be executed remotely...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7036 HIGH - 7.3

A vulnerability was identified in Tenda i9 1.0.0.5(2204). This vulnerability affects the function R7WebsSecurityHandlerfunction of the component HTTP Handler. The manipulation leads to path traversal. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Vendor: tenda
Product: i9_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7035 HIGH - 8.8

A vulnerability was determined in Tenda FH1202 1.2.0.14. This affects the function fromWrlclientSet of the file /goform/WrlclientSet of the component httpd. Executing a manipulation of the argument Go can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been ...

Vendor: tenda
Product: fh1202_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7034 HIGH - 8.8

A vulnerability was found in Tenda FH1202 1.2.0.14(408). Affected by this issue is the function WrlExtraSet of the file /goform/WrlExtraSet of the component httpd. Performing a manipulation of the argument Go results in stack-based buffer overflow. The attack may be initiated remotely. The exploit h...

Vendor: tenda
Product: fh1202_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7033 HIGH - 8.8

A vulnerability has been found in Tenda F456 1.0.0.5. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Such manipulation of the argument menufacturer/Go leads to buffer overflow. The attack can be launched remotely. The exploit has been disclo...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7032 HIGH - 8.8

A flaw has been found in Tenda F456 1.0.0.5. Affected is the function SafeEmailFilter of the file /goform/SafeEmailFilter. This manipulation of the argument page causes buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD