Total CVEs

139,961

Critical Severity

3,664

High Severity

13,210

Last 7 Days

1,617
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,781 - 7,800 of 12,907 CVEs
CVE-2019-25650 HIGH - 8.4

River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll name field. Attackers can craft a payload with a 280-byte buffer, NSEH jump instruction, and SE...

Vendor: riverpast
Product: River Past CamDo
Published: Mar 26, 2026
Source: NVD
CVE-2018-25219 HIGH - 8.4

PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget ...

Vendor: Passfab
Product: Excel Password Recovery
Published: Mar 26, 2026
Source: NVD
CVE-2018-25218 HIGH - 8.4

PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into t...

Vendor: Passfab
Product: RAR Password Recovery
Published: Mar 26, 2026
Source: NVD
CVE-2018-25217 HIGH - 8.4

PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the ...

Vendor: Rttsoftware
Product: PDF Explorer
Published: Mar 26, 2026
Source: NVD
CVE-2018-25213 HIGH - 8.4

Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field...

Vendor: Nsauditor
Product: Nsauditor Local SEH Buffer Overflow
Published: Mar 26, 2026
Source: NVD
CVE-2018-25212 HIGH - 8.4

Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH cha...

Vendor: Boxoft
Product: WAV to WMA Converter
Published: Mar 26, 2026
Source: NVD
CVE-2018-25211 HIGH - 7.8

Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service or execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious payload exceeding 780 bytes, paste it into the License...

Vendor: Alloksoft
Product: Splitter
Published: Mar 26, 2026
Source: NVD
CVE-2026-1961 HIGH - 8.0

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By op...

Published: Mar 26, 2026
Source: NVD
CVE-2025-41359 HIGH - 7.8

Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher...

Vendor: Smallsrv
Product: Small HTTP
Published: Mar 26, 2026
Source: NVD
CVE-2025-41368 HIGH - 8.1

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the serve...

Vendor: Smallsrv
Product: Small HTTP
Published: Mar 26, 2026
Source: NVD
CVE-2018-25210 HIGH - 8.2

WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL payloads through the 'urun' parameter to execute boolean-based blind, error-ba...

Vendor: Web-Ofisi
Product: Ticaret V4
Published: Mar 26, 2026
Source: NVD
CVE-2018-25209 HIGH - 8.2

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sen...

Vendor: Sourceforge
Product: OpenBiz Cubi Lite
Published: Mar 26, 2026
Source: NVD
CVE-2018-25208 HIGH - 8.2

qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through filter_by parameters. Attackers can submit malicious POST requests to the timeReport endpoint with crafted filter_by[CommentCreatedFrom] and filter_by[...

Vendor: Qdpm
Product: qdPM
Published: Mar 26, 2026
Source: NVD
CVE-2018-25207 HIGH - 7.1

Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in POST parameters to ext...

Vendor: Hscripts
Product: Online Quiz Maker
Published: Mar 26, 2026
Source: NVD
CVE-2018-25206 HIGH - 8.2

KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_item_search' parameter in edit.php. Attackers can submit POST requests with malicious SQL payloads to extract sensitive database information using boolean-based blind or err...

Vendor: Sitemakin
Product: KomSeo Cart
Published: Mar 26, 2026
Source: NVD
CVE-2018-25205 HIGH - 8.2

ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sen...

Vendor: Mediasoftpro
Product: ASP.NET jVideo Kit
Published: Mar 26, 2026
Source: NVD
CVE-2018-25204 HIGH - 8.2

Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can send POST requests to the admin login endpoint with boolean-based blind SQL injection payloads in the username fi...

Vendor: Wecodex
Product: Library CMS
Published: Mar 26, 2026
Source: NVD
CVE-2018-25203 HIGH - 8.2

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind o...

Vendor: Wecodex
Product: Online Store System CMS
Published: Mar 26, 2026
Source: NVD
CVE-2018-25202 HIGH - 8.2

SAT CFDI 3.3 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id' parameter in the signIn endpoint. Attackers can submit POST requests with boolean-based blind, stacked queries, or time-based blind SQL injection...

Vendor: Wecodex
Product: SAT CFDI
Published: Mar 26, 2026
Source: NVD
CVE-2018-25201 HIGH - 7.1

School Management System CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious payloads using boolean-based blind SQL injection techniques to...

Vendor: Wecodex Solutions
Product: School Management System CMS
Published: Mar 26, 2026
Source: NVD