6.9

CVSS4.0

CVE-2019-25645 - WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Service

WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by processing malformed AVI files. Attackers can create a specially crafted AVI file with an oversized buffer and load it through the Convert to iPhone function to…

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 25, 2026, 8:39 p.m.

6.9

CVSS4.0

CVE-2019-25644 - WinMPG Video Convert 9.3.5 Buffer Overflow Local Denial of Service

WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that allows local attackers to crash the application by supplying oversized input. Attackers can paste a large payload of 6000 bytes into the Name and Registration Code field to trigger …

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 26, 2026, 12:42 p.m.

8.8

CVSS4.0

CVE-2019-25643 - eNdonesia Portal v8.7 SQL Injection via banners.php

eNdonesia Portal v8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the bid parameter. Attackers can send GET requests to banners.php with crafted SQL payloads in the bid parameter to extract…

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 25, 2026, 8:39 p.m.

8.8

CVSS4.0

CVE-2019-25642 - Bootstrapy CMS Lastest Multiple SQL Injection via Forum and Contact Modules

Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can inject SQL payloads into the thread_id parameter of forum-thread.php, the subject parameter of cont…

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 25, 2026, 8:39 p.m.

8.8

CVSS4.0

CVE-2019-25641 - Netartmedia Vlog System Lastest SQL Injection via email Parameter

Netartmedia Vlog System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter. Attackers can send POST requests to index.php with malicious email values in the forgotten_password module to extra…

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 25, 2026, 8:39 p.m.

8.8

CVSS4.0

CVE-2019-25640 - Inout Article Base CMS Lastest SQL Injection via portalLogin.php

Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information o…

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 25, 2026, 8:39 p.m.

8.8

CVSS4.0

CVE-2019-25639 - Matrimony Website Script M-Plus Multiple SQL Injection

Matrimony Website Script M-Plus contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through various POST parameters. Attackers can inject malicious SQL payloads into parameters like txtGender, religion, Fage, and …

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 25, 2026, 8:39 p.m.

7.1

CVSS4.0

CVE-2019-25638 - Meeplace Business Review Script Lastest SQL Injection via addclick.php

Meeplace Business Review Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to the addclick.php endpoint with crafted SQL payloads in the 'id' p…

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 26, 2026, 12:39 p.m.

8.6

CVSS4.0

CVE-2019-25637 - X-NetStat Pro 5.63 Local Buffer Overflow via EggHunter

X-NetStat Pro 5.63 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the EIP register through a 264-byte buffer overflow. Attackers can inject shellcode into memory and use an egg hunter technique to locate and execute the payload wh…

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 25, 2026, 8:39 p.m.

8.8

CVSS4.0

CVE-2019-25636 - Zeeways Jobsite CMS Lastest SQL Injection via id Parameter

Zeeways Jobsite CMS contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' GET parameter. Attackers can send crafted requests to news_details.php, jobs_details.php, or job_cmp_details.php with malicious 'id…

πŸ“… Published: March 24, 2026, 11:27 a.m. πŸ”„ Last Modified: March 25, 2026, 8:39 p.m.
Total resulsts: 341090
Page 143 of 34,109
Β« previous page Β» next page
Filters