Total CVEs

126,186

Critical Severity

2,292

High Severity

7,951

Last 7 Days

1,204
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,141 - 1,160 of 22,591 CVEs
CVE-2026-7055 HIGH - 8.8

A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argument menufacturer/Go leads to buffer overflow. The attack is possible to be carried out remotely. The ex...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7054 HIGH - 8.8

A weakness has been identified in Tenda F456 1.0.0.5. This vulnerability affects the function fromPptpUserAdd of the file /goform/PPTPDClient of the component httpd. Executing a manipulation of the argument opttype/usernamewith can lead to buffer overflow. The attack can be executed remotely. The ex...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7053 HIGH - 8.8

A security flaw has been discovered in Tenda F456 1.0.0.5. This affects the function frmL7ProtForm of the file /goform/L7Prot of the component httpd. Performing a manipulation of the argument page results in buffer overflow. Remote exploitation of the attack is possible. The exploit has been release...

Vendor: tenda
Product: f456_firmware
Published: Apr 26, 2026
Source: NVD
CVE-2026-7045 MEDIUM - 6.3

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the comp...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7044 MEDIUM - 6.3

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The attack can be launched remotely. The exploit has been made public and could be used. This vulnerability ...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7043 MEDIUM - 6.3

A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be use...

Published: Apr 26, 2026
Source: NVD
CVE-2026-7042 HIGH - 7.3

A flaw has been found in 666ghj MiroFish up to 0.1.2. This affects the function create_app of the file backend/app/__init__.py of the component REST API Endpoint. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been published...

Published: Apr 26, 2026
Source: NVD
CVE-2018-25297 MEDIUM - 6.2

Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads into the Camera name and DID number fields during camera addition to trigger application crashes.

Vendor: Wansview
Product: Wansview
Published: Apr 26, 2026
Source: NVD
CVE-2018-25296 MEDIUM - 5.5

P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 2000-byte payload into the password field and click login to trigger an appl...

Vendor: P10
Product: Central Management Software
Published: Apr 26, 2026
Source: NVD
CVE-2018-25295 MEDIUM - 6.2

ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers can paste a 2000-byte buffer of repeated characters into the IP field and trigger a search operation ...

Vendor: P10
Product: ObserverIP Scan Tool
Published: Apr 26, 2026
Source: NVD
CVE-2018-25294 HIGH - 7.5

CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data into the email address and password fields to trigger a denial of service condition.

Vendor: Cewe-Photoworld
Product: CEWE Photoshow
Published: Apr 26, 2026
Source: NVD
CVE-2018-25293 MEDIUM - 6.2

Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to crash the application by supplying an excessively long string in the optional proxy password field. Attackers can trigger a denial of service by entering a 6000-byte payload into ...

Vendor: Mersenne
Product: Prime95
Published: Apr 26, 2026
Source: NVD
CVE-2018-25292 MEDIUM - 6.2

Bome Restorator 1793 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can create a malicious payload exceeding 4000 bytes and paste it into the Name input field to trigger an application...

Vendor: Bome
Product: Restorator
Published: Apr 26, 2026
Source: NVD
CVE-2018-25291 MEDIUM - 6.2

Project64 2.3.2 contains a buffer overflow vulnerability in the Plugin Directory settings field that allows local attackers to crash the application by supplying an excessively long string. Attackers can input a 6000-byte payload into the Plugin Directory field through the Options > Settings >...

Vendor: Pj64-Emu
Product: Project64
Published: Apr 26, 2026
Source: NVD
CVE-2018-25290 MEDIUM - 6.2

Easyboot 6.6.0 contains a buffer overflow vulnerability in the Replace Text function that allows local attackers to crash the application by supplying an oversized string. Attackers can trigger the vulnerability by accessing File > Tools > Replace Text and pasting a 7000-byte payload into the ...

Vendor: Ezbsystems
Product: Easyboot
Published: Apr 26, 2026
Source: NVD
CVE-2018-25289 MEDIUM - 6.2

Softdisk 3.0.3 contains a buffer overflow vulnerability in the registration code dialog that allows local attackers to crash the application by supplying an oversized string. Attackers can trigger the vulnerability by entering a 6000-byte payload in the Registration Name field through the Help menu&...

Vendor: Ezbsystems
Product: Softdisk
Published: Apr 26, 2026
Source: NVD
CVE-2018-25288 MEDIUM - 6.2

StyleWriter 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 6000-byte payload into the Pattern to Find or Advice Message fields in the Add Pattern dialog to trigger a denial of service co...

Vendor: Editorsoftware
Product: StyleWriter
Published: Apr 26, 2026
Source: NVD
CVE-2018-25287 MEDIUM - 5.5

Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a 6000-byte payload into the Name field and click Register to trigger a denial of service condition.

Vendor: Hdtune
Product: Drive Power Manager
Published: Apr 26, 2026
Source: NVD
CVE-2018-25286 MEDIUM - 6.2

Easy PhotoResQ 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Folder/filename field. Attackers can input a 6000-byte payload through the File Options dialog to trigger a denial of service condition.

Vendor: Hdtune
Product: Easy PhotoResQ
Published: Apr 26, 2026
Source: NVD
CVE-2018-25285 MEDIUM - 5.5

Fathom 2.4 contains a buffer overflow vulnerability in the Authorization Code field that allows local attackers to crash the application by submitting an oversized input string. Attackers can paste a 6000-byte payload into the Authorization Code field and click Activate to trigger a denial of servic...

Vendor: Fathom
Product: Fathom
Published: Apr 26, 2026
Source: NVD