8.6

CVSS4.0

CVE-2018-25299 - Prime95 29.4b8 Local Buffer Overflow via SEH

Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger…

📅 Published: April 29, 2026, 7:24 p.m. 🔄 Last Modified: April 30, 2026, 1:59 p.m.

6.9

CVSS4.0

CVE-2018-25298 - Merge PACS 7.0 Cross-Site Request Forgery via merge-viewer

Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack…

📅 Published: April 29, 2026, 7:24 p.m. 🔄 Last Modified: April 30, 2026, 12:45 p.m.

5.3

CVSS4.0

CVE-2026-7401 - SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php reg…

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results …

📅 Published: April 29, 2026, 7:15 p.m. 🔄 Last Modified: April 30, 2026, 8:20 a.m.

6.9

CVSS4.0

CVE-2026-7400 - geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path trav…

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_tool. Such manipulation leads to path traversal. The attack can be launched remotely. The exploit ha…

📅 Published: April 29, 2026, 7 p.m. 🔄 Last Modified: April 30, 2026, 8:20 a.m.

6.1

CVSS4.0

CVE-2026-7426 - Out-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Pl…

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid lengt…

📅 Published: April 29, 2026, 6:53 p.m. 🔄 Last Modified: May 4, 2026, 1:12 p.m.

6

CVSS4.0

CVE-2026-7425 - Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is small…

📅 Published: April 29, 2026, 6:52 p.m. 🔄 Last Modified: May 4, 2026, 1:12 p.m.

7.2

CVSS4.0

CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) …

📅 Published: April 29, 2026, 6:51 p.m. 🔄 Last Modified: May 4, 2026, 1:22 p.m.

7.7

CVSS4.0

CVE-2026-7466 - AgentFlow Arbitrary Python Pipeline Execution via pipeline_path

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to l…

📅 Published: April 29, 2026, 6:44 p.m. 🔄 Last Modified: April 30, 2026, 1:05 p.m.

6

CVSS4.0

CVE-2026-7423 - Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without valida…

📅 Published: April 29, 2026, 6:36 p.m. 🔄 Last Modified: May 4, 2026, 1:35 p.m.

7.1

CVSS4.0

CVE-2026-7422 - MAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mechanis…

📅 Published: April 29, 2026, 6:35 p.m. 🔄 Last Modified: May 4, 2026, 1:43 p.m.
Total resulsts: 349182
Page 201 of 34,919
« previous page » next page
Filters