Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,543
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,881 - 10,900 of 13,241 CVEs
CVE-2019-25401 HIGH - 7.5

Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a denial of service vulnerability in the admin configuration page. Remote attackers can send crafted POST requests with malformed 'admin' and 'person' parameters to crash the printer's web service, cau...

Vendor: Bematech
Product: MP-4200
Published: Feb 18, 2026
Source: NVD
CVE-2019-25363 HIGH - 7.5

WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to crash the application by providing an oversized license input. Attackers can generate a 6000-byte payload and paste it into the 'License Name and License Code' field to trigger an a...

Vendor: Alloksoft
Product: WMV to AVI MPEG DVD WMV Convertor
Published: Feb 18, 2026
Source: NVD
CVE-2019-25359 HIGH - 8.2

SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST parameters 'idtyp' and 'idgremium'. Attackers can exploit this vulnerability by crafting specially formed POST requests to the /vorlagen/ ...

Vendor: Sitzungsdienst
Product: SD.NET RIM
Published: Feb 18, 2026
Source: NVD
CVE-2019-25358 HIGH - 7.5

FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when openi...

Vendor: nikkhokkho
Product: FileOptimizer
Published: Feb 18, 2026
Source: NVD
CVE-2019-25357 HIGH - 8.4

Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execu...

Vendor: WEBGATE Inc.
Product: Control Center PRO
Published: Feb 18, 2026
Source: NVD
CVE-2019-25355 HIGH - 7.5

gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversa...

Vendor: Genivia Inc.
Product: gSOAP
Published: Feb 18, 2026
Source: NVD
CVE-2019-25354 HIGH - 7.5

iSmartViewPro 1.3.34 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the camera ID input field. Attackers can paste a 257-character buffer into the camera DID and password fields to trigger an application crash on iOS devices.

Vendor: Shenzhen Smarteye Digital Electronics Co., Ltd.
Product: iSmartViewPro
Published: Feb 18, 2026
Source: NVD
CVE-2019-25353 HIGH - 7.5

Foscam Video Management System 1.1.4.9 contains a denial of service vulnerability in the username input field that allows attackers to crash the application. Attackers can overwrite the username with a 520-byte buffer of repeated 'A' characters to trigger an application crash during device...

Vendor: Diy Security SL
Product: Foscam Video Management System
Published: Feb 18, 2026
Source: NVD
CVE-2019-25352 HIGH - 7.5

Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Wind...

Vendor: Genivia Inc.
Product: Crystal Live HTTP Server
Published: Feb 18, 2026
Source: NVD
CVE-2019-25351 HIGH - 8.8

Centova Cast 3.2.11 contains a file download vulnerability that allows authenticated attackers to retrieve arbitrary system files through the server.copyfile API endpoint. Attackers can exploit the vulnerability by supplying crafted parameters to download sensitive files like /etc/passwd using curl ...

Vendor: Centova Technologies Inc.
Product: Centova Cast
Published: Feb 18, 2026
Source: NVD
CVE-2019-25350 HIGH - 7.5

XMedia Recode 3.4.8.6 contains a denial of service vulnerability that allows attackers to crash the application by loading a specially crafted .m3u playlist file. Attackers can create a malicious .m3u file with an oversized buffer to trigger an application crash when the file is opened.

Vendor: XMedia Recode
Product: XMedia Recode
Published: Feb 18, 2026
Source: NVD
CVE-2019-25349 HIGH - 7.5

ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer in the Servername field. Attackers can paste a 257-character buffer during login to trigger an application crash on iOS devices.

Vendor: scadaapp
Product: scadaApp for iOS
Published: Feb 18, 2026
Source: NVD
CVE-2026-26280 HIGH - 8.4

systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In `lib/wif...

Vendor: npm
Product: systeminformation
Published: Feb 18, 2026
Source: GitHub

Slyde is a program that creates animated presentations from XML. In versions 0.0.4 and below, Node.js automatically imports **/*.plugin.{js,mjs} files including those from node_modules, so any malicious package with a .plugin.js file can execute arbitrary code when installed or required. All project...

Vendor: npm
Product: @tygo-van-den-hurk/slyde
Published: Feb 18, 2026
Source: GitHub
CVE-2026-2668 HIGH - 7.3

A vulnerability was found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260206. This affects an unknown function of the file /dm/dispatch/user/add of the component User Handler. The manipulation results in improper access controls. The attack may be launched remotely. The ex...

Published: Feb 18, 2026
Source: NVD
CVE-2025-1272 HIGH - 7.7

The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode disabled without any warning. This may allow an attacker to gain access to sensitive information such kernel memory mappings, I/O ports, BPF and kprobes. Additionally unsigned modules...

Published: Feb 18, 2026
Source: NVD
CVE-2026-23491 HIGH - 7.5

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. a path traversal vulnerability exists in the `get_file` method of the `Guest` module's `Get` controller in InvoicePlane up to and including through 1.6.3. The vulnerability allows unauthenticated...

Vendor: InvoicePlane
Product: InvoicePlane
Published: Feb 18, 2026
Source: NVD
CVE-2026-0875 HIGH - 7.8

A maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: shared_components
Published: Feb 18, 2026
Source: NVD
CVE-2026-0874 HIGH - 7.8

A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

Vendor: autodesk
Product: shared_components
Published: Feb 18, 2026
Source: NVD
CVE-2025-70064 HIGH - 8.8

PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This ...

Vendor: phpgurukul
Product: hospital_management_system
Published: Feb 18, 2026
Source: NVD