Total CVEs

140,151

Critical Severity

3,698

High Severity

13,312

Last 7 Days

1,766
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,881 - 7,900 of 13,009 CVEs
CVE-2025-55262 HIGH - 8.3

HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database.

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD
CVE-2025-55261 HIGH - 8.1

HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his privileges and may compromise the application and may steal and manipulate the data.

Vendor: HCL
Product: Aftermarket DPC
Published: Mar 26, 2026
Source: NVD
CVE-2019-25650 HIGH - 8.4

River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll name field. Attackers can craft a payload with a 280-byte buffer, NSEH jump instruction, and SE...

Vendor: riverpast
Product: River Past CamDo
Published: Mar 26, 2026
Source: NVD
CVE-2018-25219 HIGH - 8.4

PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget ...

Vendor: Passfab
Product: Excel Password Recovery
Published: Mar 26, 2026
Source: NVD
CVE-2018-25218 HIGH - 8.4

PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into t...

Vendor: Passfab
Product: RAR Password Recovery
Published: Mar 26, 2026
Source: NVD
CVE-2018-25217 HIGH - 8.4

PDF Explorer 1.5.66.2 contains a structured exception handler (SEH) overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH records with malicious data. Attackers can craft a payload with buffer overflow, NSEH jump, and ROP gadget chains that execute when the ...

Vendor: Rttsoftware
Product: PDF Explorer
Published: Mar 26, 2026
Source: NVD
CVE-2018-25213 HIGH - 8.4

Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field...

Vendor: Nsauditor
Product: Nsauditor Local SEH Buffer Overflow
Published: Mar 26, 2026
Source: NVD
CVE-2018-25212 HIGH - 8.4

Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH cha...

Vendor: Boxoft
Product: WAV to WMA Converter
Published: Mar 26, 2026
Source: NVD
CVE-2018-25211 HIGH - 7.8

Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service or execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious payload exceeding 780 bytes, paste it into the License...

Vendor: Alloksoft
Product: Splitter
Published: Mar 26, 2026
Source: NVD
CVE-2026-1961 HIGH - 8.0

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By op...

Published: Mar 26, 2026
Source: NVD
CVE-2025-41359 HIGH - 7.8

Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name in a higher...

Vendor: Smallsrv
Product: Small HTTP
Published: Mar 26, 2026
Source: NVD
CVE-2025-41368 HIGH - 8.1

Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured on the serve...

Vendor: Smallsrv
Product: Small HTTP
Published: Mar 26, 2026
Source: NVD
CVE-2018-25210 HIGH - 8.2

WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL payloads through the 'urun' parameter to execute boolean-based blind, error-ba...

Vendor: Web-Ofisi
Product: Ticaret V4
Published: Mar 26, 2026
Source: NVD
CVE-2018-25209 HIGH - 8.2

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sen...

Vendor: Sourceforge
Product: OpenBiz Cubi Lite
Published: Mar 26, 2026
Source: NVD
CVE-2018-25208 HIGH - 8.2

qdPM 9.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through filter_by parameters. Attackers can submit malicious POST requests to the timeReport endpoint with crafted filter_by[CommentCreatedFrom] and filter_by[...

Vendor: Qdpm
Product: qdPM
Published: Mar 26, 2026
Source: NVD
CVE-2018-25207 HIGH - 7.1

Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in POST parameters to ext...

Vendor: Hscripts
Product: Online Quiz Maker
Published: Mar 26, 2026
Source: NVD
CVE-2018-25206 HIGH - 8.2

KomSeo Cart 1.3 contains an SQL injection vulnerability that allows attackers to inject SQL commands through the 'my_item_search' parameter in edit.php. Attackers can submit POST requests with malicious SQL payloads to extract sensitive database information using boolean-based blind or err...

Vendor: Sitemakin
Product: KomSeo Cart
Published: Mar 26, 2026
Source: NVD
CVE-2018-25205 HIGH - 8.2

ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sen...

Vendor: Mediasoftpro
Product: ASP.NET jVideo Kit
Published: Mar 26, 2026
Source: NVD
CVE-2018-25204 HIGH - 8.2

Library CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can send POST requests to the admin login endpoint with boolean-based blind SQL injection payloads in the username fi...

Vendor: Wecodex
Product: Library CMS
Published: Mar 26, 2026
Source: NVD
CVE-2018-25203 HIGH - 8.2

Online Store System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with the action=clientaccess parameter using boolean-based blind o...

Vendor: Wecodex
Product: Online Store System CMS
Published: Mar 26, 2026
Source: NVD