4

CVSS3.1

CVE-2026-40386 -

In libexif through 0.6.25, an integer underflow in size checking for Fuji and Olympus MakerNote decoding could be used by attackers to crash or leak information out of libexif-using programs.

📅 Published: April 12, 2026, 6:19 p.m. 🔄 Last Modified: April 12, 2026, 6:22 p.m.

4

CVSS3.1

CVE-2026-40385 -

In libexif through 0.6.25, an unsigned 32bit integer overflow in Nikon MakerNote handling could be used by local attackers to cause crashes or information leaks. This only affects 32bit systems.

📅 Published: April 12, 2026, 6:16 p.m. 🔄 Last Modified: April 12, 2026, 6:22 p.m.

7.1

CVSS4.0

CVE-2019-25713 - MyT-PM 1.5.1 SQL Injection via Charge[group_total] Parameter

MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the Charge[group_total] parameter. Attackers can submit crafted POST requests to the /charge/admin endpoint with error-based, time-based blin…

📅 Published: April 12, 2026, 12:28 p.m. 🔄 Last Modified: April 12, 2026, 12:28 p.m.

6.9

CVSS4.0

CVE-2019-25712 - BlueAuditor 1.7.2.0 Buffer Overflow Denial of Service via Registration Key

BlueAuditor 1.7.2.0 contains a buffer overflow vulnerability in the registration key field that allows local attackers to crash the application by submitting an oversized key value. Attackers can trigger a denial of service by entering a 256-byte buffer of repeated characters in the Key registratio…

📅 Published: April 12, 2026, 12:28 p.m. 🔄 Last Modified: April 12, 2026, 12:28 p.m.

6.9

CVSS4.0

CVE-2019-25711 - SpotFTP Password Recover 2.4.2 Denial of Service via Name Field

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field, and trigger a crash w…

📅 Published: April 12, 2026, 12:28 p.m. 🔄 Last Modified: April 12, 2026, 12:28 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here