9.3

CVSS4.0

CVE-2009-20010 - Dogfood CRM spell.php RCE

Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail subsystem. The vulnerability arises from unsanitized user input passed via a POST request to the data parameter, which is processed by the underlying shell without adequate escaping…

πŸ“… Published: Aug. 30, 2025, 1:47 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

10

CVSS4.0

CVE-2009-20011 - ContentKeeper Web Appliance < 125.10 RCE via mimencode

ContentKeeper Web Appliance (now maintained by Impero Software)Β versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as t…

πŸ“… Published: Aug. 30, 2025, 1:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2005-10004 - Cacti graph_view.php RCE via graph_start Parameter Injection

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute comma…

πŸ“… Published: Aug. 30, 2025, 1:45 p.m. πŸ”„ Last Modified: April 7, 2026, 2:01 p.m.

10

CVSS4.0

CVE-2010-10016 - BS.Player 2.57 Buffer Overflow via M3U Playlist Import

BS.Player version 2.57 (build 1051) contains a vulnerability in its playlist import functionality. When processing .m3u files, the application fails to properly validate the length of playlist entries, resulting in a buffer overflow condition. This flaw occurs during parsing of long URLs embedded i…

πŸ“… Published: Aug. 30, 2025, 1:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2009-20009 - Belkin Bulldog Plus Web Service Buffer Overflow

Belkin Bulldog Plus version 4.0.2 build 1219 contains a stack-based buffer overflow vulnerability in its web service authentication handler. When a specially crafted HTTP request is sent with an oversized Authorization header, the application fails to properly validate the input length before copyi…

πŸ“… Published: Aug. 30, 2025, 1:43 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS4.0

CVE-2008-20001 - activePDF WebGrabber ActiveX Control Buffer Overflow

activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long string to this method, a remote attacker can execute arbitrary code in the context of the vulnerable process. Although t…

πŸ“… Published: Aug. 30, 2025, 1:42 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-9690 - SourceCodester Advanced School Management System vendordetails sql injection

A flaw has been found in SourceCodester Advanced School Management System 1.0. This affects an unknown function of the file /index.php/stock/vendordetails. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: Aug. 30, 2025, 1:32 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 4:49 p.m.

5.3

CVSS4.0

CVE-2025-9689 - SourceCodester Advanced School Management System item_select sql injection

A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown function of the file /index.php/stock/item_select. The manipulation of the argument q results in sql injection. It is possible to launch the attack remotely. The exploit is now p…

πŸ“… Published: Aug. 30, 2025, 1:02 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 4:50 p.m.

7.6

CVSS3.1

CVE-2025-0165 - IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data SQL injection

IBM watsonx Orchestrate Cartridge for IBM Cloud Pak for Data 4.8.4, 4.8.5, and 5.0.0 through 5.2.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

πŸ“… Published: Aug. 30, 2025, 12:47 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 5:50 p.m.

2.3

CVSS4.0

CVE-2025-9688 - Mupen64Plus is_viewer.c write_is_viewer integer overflow

A security vulnerability has been detected in Mupen64Plus up to 2.6.0. The affected element is the function write_is_viewer of the file src/device/cart/is_viewer.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. The attack is considered to have high comp…

πŸ“… Published: Aug. 30, 2025, 12:32 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4076 of 34,919
Β« previous page Β» next page
Filters