Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28475
Total
2191
Critical
8537
High
8862
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2018-25317 | CRITICAL | 9.8 | Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. … | Apr 29, 2026 |
| CVE-2018-25316 | CRITICAL | 9.8 | Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can … | Apr 29, 2026 |
| CVE-2018-25315 | HIGH | 8.4 | Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License … | Apr 29, 2026 |
| CVE-2018-25314 | HIGH | 8.4 | Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying … | Apr 29, 2026 |
| CVE-2018-25313 | MEDIUM | 6.2 | SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an … | Apr 29, 2026 |
| CVE-2018-25312 | MEDIUM | 6.5 | LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. … | Apr 29, 2026 |
| CVE-2018-25311 | MEDIUM | 6.5 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal sequences … | Apr 29, 2026 |
| CVE-2018-25310 | MEDIUM | 4.3 | VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a … | Apr 29, 2026 |
| CVE-2018-25309 | HIGH | 7.2 | MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers … | Apr 29, 2026 |
| CVE-2018-25308 | HIGH | 8.8 | BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. … | Apr 29, 2026 |
| CVE-2018-25307 | HIGH | 8.4 | SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying … | Apr 29, 2026 |
| CVE-2018-25306 | MEDIUM | 6.2 | PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can … | Apr 29, 2026 |
| CVE-2018-25305 | MEDIUM | 6.2 | librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service by processing malformed SVG files. Attackers can supply … | Apr 29, 2026 |
| CVE-2018-25304 | HIGH | 8.4 | Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception … | Apr 29, 2026 |
| CVE-2018-25303 | HIGH | 8.4 | Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code … | Apr 29, 2026 |
| CVE-2018-25302 | HIGH | 7.8 | Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary … | Apr 29, 2026 |
| CVE-2018-25301 | HIGH | 8.4 | Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by … | Apr 29, 2026 |
| CVE-2018-25300 | HIGH | 8.2 | XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. … | Apr 29, 2026 |
| CVE-2018-25299 | HIGH | 8.4 | Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject … | Apr 29, 2026 |
| CVE-2018-25298 | MEDIUM | 5.3 | Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. … | Apr 29, 2026 |
| CVE-2026-7466 | HIGH | 8.8 | AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST … | Apr 29, 2026 |
| CVE-2026-7439 | MEDIUM | 4.4 | AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boundary enforcement … | Apr 29, 2026 |
| CVE-2026-7424 | HIGH | 8.1 | Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, … | Apr 29, 2026 |
| CVE-2026-7423 | MEDIUM | 5.3 | Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial … | Apr 29, 2026 |
| CVE-2026-7422 | MEDIUM | 6.5 | Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet … | Apr 29, 2026 |