Total CVEs

140,284

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,815
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 8,361 - 8,380 of 13,041 CVEs
CVE-2026-4551 HIGH - 8.8

A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the argument menufacturer/Go results in stack-based buffer overflow. The attack is poss...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4546 HIGH - 7.0

A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The attack is restricted to local execution. The attack requires a high level of complexity. The exploitabi...

Published: Mar 22, 2026
Source: NVD
CVE-2019-25619 HIGH - 8.4

FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to over...

Vendor: Ftpshell
Product: FTP Shell Server
Published: Mar 22, 2026
Source: NVD
CVE-2019-25615 HIGH - 8.4

Lavavo CD Ripper 4.20 contains a structured exception handling (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Activation Name field. Attackers can craft a payload with controlled buffer data, NSEH jump instruct...

Vendor: Lavavosoftware
Product: Lavavo CD Ripper
Published: Mar 22, 2026
Source: NVD
CVE-2019-25613 HIGH - 7.5

Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large me...

Vendor: Echatserver
Product: Easy Chat
Published: Mar 22, 2026
Source: NVD
CVE-2019-25612 HIGH - 7.8

Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature...

Vendor: Admin-Express
Product: Admin-Express
Published: Mar 22, 2026
Source: NVD
CVE-2019-25611 HIGH - 8.4

MiniFtp contains a buffer overflow vulnerability in the parseconf_load_setting function that allows local attackers to execute arbitrary code by supplying oversized configuration values. Attackers can craft a miniftpd.conf file with values exceeding 128 bytes to overflow stack buffers and overwrite ...

Vendor: skyqinsc
Product: MiniFtp
Published: Mar 22, 2026
Source: NVD
CVE-2019-25609 HIGH - 8.4

JetAudio jetCast Server 2.0 contains a stack-based buffer overflow vulnerability in the Log Directory configuration field that allows local attackers to overwrite structured exception handling pointers. Attackers can inject alphanumeric encoded shellcode through the Log Directory field to trigger an...

Vendor: Jetaudio
Product: Server
Published: Mar 22, 2026
Source: NVD
CVE-2019-25608 HIGH - 8.4

Iperius Backup 6.1.0 contains a privilege escalation vulnerability that allows low-privilege users to execute arbitrary programs with elevated privileges by creating backup jobs. Attackers can configure backup jobs to execute malicious batch files or programs before or after backup operations, which...

Vendor: Iperius
Product: Iperius Backup
Published: Mar 22, 2026
Source: NVD
CVE-2019-25607 HIGH - 8.4

Axessh 4.2 contains a stack-based buffer overflow vulnerability in the log file name field that allows local attackers to execute arbitrary code by supplying an excessively long filename. Attackers can overflow the buffer at offset 214 bytes to overwrite the instruction pointer and execute shellcode...

Vendor: Labf
Product: Axessh
Published: Mar 22, 2026
Source: NVD
CVE-2019-25605 HIGH - 7.5

EquityPandit 1.0 contains an insecure logging vulnerability that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge. Attackers can use adb logcat to extract plaintext passwords logged during the forgot password function, exposing user ...

Vendor: Play
Product: EquityPandit
Published: Mar 22, 2026
Source: NVD
CVE-2019-25604 HIGH - 8.4

DVDXPlayer Pro 5.5 contains a local buffer overflow vulnerability with structured exception handling that allows local attackers to execute arbitrary code by crafting malicious playlist files. Attackers can create a specially crafted .plf file containing shellcode and NOP sleds that overflows a buff...

Vendor: Dvd-X-Player
Product: DVDXPlayer
Published: Mar 22, 2026
Source: NVD
CVE-2019-25603 HIGH - 8.4

TuneClone 2.20 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license code string. Attackers can craft a payload with a controlled buffer, NSEH jump instruction, and SEH handler address pointi...

Vendor: TuneClone
Product: TuneClone
Published: Mar 22, 2026
Source: NVD
CVE-2026-4545 HIGH - 7.0

A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PROPSYS.dll. Performing a manipulation results in uncontrolled search path. The attack is only possible with local access. The attack is considered to have high complexity. The explo...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4540 HIGH - 7.3

A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parameters Handler. The manipulation of the argument Benutzer results in SQL Injection. The attack can be executed remotely. The exploit i...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4536 HIGH - 7.3

A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1.1.0. This issue affects some unknown processing. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted e...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4535 HIGH - 8.8

A vulnerability has been found in Tenda FH451 1.0.0.9. This vulnerability affects the function WrlclientSet of the file /goform/WrlclientSet. Such manipulation of the argument GO leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public a...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4534 HIGH - 8.8

A flaw has been found in Tenda FH451 1.0.0.9. This affects the function formWrlExtraSet of the file /goform/WrlExtraSet. This manipulation of the argument GO causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used.

Published: Mar 22, 2026
Source: NVD
CVE-2026-4314 HIGH - 8.8

The 'The Ultimate WordPress Toolkit โ€“ WP Extended' plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.4. This is due to the `isDashboardOrProfileRequest()` method in the Menu Editor module using an insecure `strpos()` check against `$_SERVE...

Published: Mar 22, 2026
Source: NVD
CVE-2026-4529 HIGH - 8.8

A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This vulner...

Published: Mar 21, 2026
Source: NVD