Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,536
Quick preset (or use dates below)
Clear Filters
Showing 7,461 - 7,480 of 13,544 CVEs
CVE-2026-5610 HIGH - 8.8

A vulnerability has been found in Belkin F9K1015 1.00.10. Affected by this issue is the function formWISP5G of the file /goform/formWISP5G. Such manipulation of the argument webpage leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to ...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5609 HIGH - 8.8

A flaw has been found in Tenda i12 1.0.0.11(3862). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset of the component Parameter Handler. This manipulation of the argument index/wl_radio causes stack-based buffer overflow. It is possible to initiate the att...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5608 HIGH - 8.8

A vulnerability was detected in Belkin F9K1122 1.00.33. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument webpage results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used. The v...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5605 HIGH - 8.8

A weakness has been identified in Tenda CH22 1.0.0.1. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. Executing a manipulation of the argument GO can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public...

Published: Apr 06, 2026
Source: NVD
CVE-2026-5604 HIGH - 8.8

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formCertLocalPrecreate of the file /goform/CertLocalPrecreate of the component Parameter Handler. Performing a manipulation of the argument standard results in stack-based buffer overflow. Remote exploita...

Published: Apr 05, 2026
Source: NVD
CVE-2026-4272 HIGH - 8.1

Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before GK000432BAA, from D1 Base(Ingenic x1600) before HE000085BAA, from A1/B1 Base(IMX25) before BK000763BAA_BK0007...

Published: Apr 05, 2026
Source: NVD
CVE-2019-25704 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the filter_user_mail parameter. Attackers can send crafted requests with malicious SQL statements to extract sensitive database information or modify data.

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25702 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_project parameter. Attackers can send crafted requests with malicious SQL statements in the id_project parameter to extract sensitive database informat...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25700 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the sort_direction parameter. Attackers can submit malicious SQL statements in the sort_direction parameter to extract sensitive database information or modif...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25698 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the id_to_delete parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_delete field to extract or modify sensitive databas...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25696 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the language_tag parameter. Attackers can submit malicious SQL statements in the language_tag parameter to extract sensitive database information or modify da...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25694 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted requests with malicious SQL payloads to extract sensitive database information or modify ...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25692 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_modify field to extract sensitive datab...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25690 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database in...

Vendor: Kados
Product: Kados R10 GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25688 HIGH - 8.2

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive datab...

Vendor: Kados
Product: Kados GreenBee
Published: Apr 05, 2026
Source: NVD
CVE-2019-25686 HIGH - 7.5

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violatio...

Vendor: Coreftp
Product: Core FTP
Published: Apr 05, 2026
Source: NVD
CVE-2019-25685 HIGH - 8.8

phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserial...

Vendor: phpBB
Product: phpBB
Published: Apr 05, 2026
Source: NVD
CVE-2019-25684 HIGH - 8.2

OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to...

Vendor: opendocman
Product: OpenDocMan
Published: Apr 05, 2026
Source: NVD
CVE-2019-25681 HIGH - 8.4

Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual s...

Vendor: Xlightftpd
Product: Xlight
Published: Apr 05, 2026
Source: NVD
CVE-2019-25680 HIGH - 8.2

Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to e...

Vendor: Phpscriptsmall
Product: Advance Gift Shop Pro Script
Published: Apr 05, 2026
Source: NVD