Total CVEs

125,872

Critical Severity

2,276

High Severity

7,883

Last 7 Days

1,163
Quick preset (or use dates below)
Clear Filters
Showing 121 - 140 of 8,730 CVEs
CVE-2018-25313 MEDIUM - 6.2

SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can inject a large payload through the Proxy Server Host Name field in the Options menu to crash the applic...

Vendor: Sysgauge
Product: SysGauge
Published: Apr 29, 2026
Source: NVD
CVE-2018-25312 MEDIUM - 6.5

LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to arb...

Vendor: LifeSize
Product: ClearSea
Published: Apr 29, 2026
Source: NVD
CVE-2018-25311 MEDIUM - 6.5

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal sequences in the ID parameter. Attackers can submit requests to downloadsys.pl, download_xml.pl, downloa...

Vendor: VideoFlow Ltd.
Product: VideoFlow Digital Video Protection
Published: Apr 29, 2026
Source: NVD
CVE-2018-25310 MEDIUM - 4.3

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cross-site request forgery flaw in the web management interface. Attackers with valid credentials can lev...

Vendor: VideoFlow Ltd.
Product: VideoFlow Digital Video Protection
Published: Apr 29, 2026
Source: NVD
CVE-2018-25306 MEDIUM - 6.2

PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmentation fault in the XRef::getEntry function within libpoppler by providing a specially crafted PDF fi...

Vendor: poppler-utils
Product: PDFunite
Published: Apr 29, 2026
Source: NVD
CVE-2018-25305 MEDIUM - 6.2

librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service by processing malformed SVG files. Attackers can supply crafted SVG input to the rsvg conversion tool to trigger a segmentation fault in the cairo image compositor.

Vendor: xenial
Product: RSVG
Published: Apr 29, 2026
Source: NVD
CVE-2018-25298 MEDIUM - 5.3

Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack ...

Vendor: Merge
Product: Merge PACS
Published: Apr 29, 2026
Source: NVD
CVE-2026-7439 MEDIUM - 4.4

AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boundary enforcement on sensitive operations. Attackers can exploit this content-type validation wea...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7423 MEDIUM - 5.3

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validat...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7422 MEDIUM - 6.5

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mech...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7397 MEDIUM - 4.4

A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The exploit has been released to the public and may be used for ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-41499 MEDIUM - 6.5

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE vulnerabilities exist in parse_uname_string() (remoted_op.c). This function processes OS identification data from agents ...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-28221 MEDIUM - 6.5

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() in wazuh-remoted. The bug is triggered when formatting attacker-controlled bytes using sprintf(dst_buf...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-27105 MEDIUM - 6.3

Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write

Vendor: Dell
Product: Dell/Alienware Purchased Apps
Published: Apr 29, 2026
Source: NVD
CVE-2026-26206 MEDIUM - 6.5

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security/user/authenticate can be bypassed by sending concurrent authentication requests. Although the c...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-41483 MEDIUM - 5.9

OpenTelemetry.Resources.Azure has an unbounded HTTP response body read

Vendor: nuget
Product: OpenTelemetry.Resources.Azure
Published: Apr 29, 2026
Source: GitHub

beets has a Cross-site Scripting vulnerability

Vendor: pip
Product: beets
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7396 MEDIUM - 5.3

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7394 MEDIUM - 4.7

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be...

Published: Apr 29, 2026
Source: NVD
CVE-2026-26204 MEDIUM - 4.4

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 byte before the start of the buffer allocated by strdup. Due ...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD