8.8

CVSS4.0

CVE-2018-25300 - XATABoost CMS 1.0.0 SQL Injection via news.php

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers can send GET requests to news.php with malicious id values to extract sensitive database information.

๐Ÿ“… Published: April 29, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 7:24 p.m.

8.6

CVSS4.0

CVE-2018-25299 - Prime95 29.4b8 Local Buffer Overflow via SEH

Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to triggerโ€ฆ

๐Ÿ“… Published: April 29, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 7:24 p.m.

6.9

CVSS4.0

CVE-2018-25298 - Merge PACS 7.0 Cross-Site Request Forgery via merge-viewer

Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijackโ€ฆ

๐Ÿ“… Published: April 29, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 7:24 p.m.

5.3

CVSS4.0

CVE-2026-7401 - SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php regโ€ฆ

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results โ€ฆ

๐Ÿ“… Published: April 29, 2026, 7:15 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 7:15 p.m.

6.9

CVSS4.0

CVE-2026-7400 - geekgod382 filesystem-mcp-server read_file_tool/write_file_tool server.py is_path_allowed path travโ€ฆ

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_tool. Such manipulation leads to path traversal. The attack can be launched remotely. The exploit haโ€ฆ

๐Ÿ“… Published: April 29, 2026, 7 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 7 p.m.

6.1

CVSS4.0

CVE-2026-7426 - Out-of-Bounds Write via Unsanitized Prefix Length in Router Advertisement Processing in FreeRTOS-Plโ€ฆ

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid lengtโ€ฆ

๐Ÿ“… Published: April 29, 2026, 6:53 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 6:53 p.m.

6

CVSS4.0

CVE-2026-7425 - Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smallโ€ฆ

๐Ÿ“… Published: April 29, 2026, 6:52 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 6:52 p.m.

7.2

CVSS4.0

CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) โ€ฆ

๐Ÿ“… Published: April 29, 2026, 6:51 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 6:51 p.m.

7.7

CVSS4.0

CVE-2026-7466 - AgentFlow Arbitrary Python Pipeline Execution via pipeline_path

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to lโ€ฆ

๐Ÿ“… Published: April 29, 2026, 6:44 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 6:44 p.m.

6

CVSS4.0

CVE-2026-7423 - Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validaโ€ฆ

๐Ÿ“… Published: April 29, 2026, 6:36 p.m. ๐Ÿ”„ Last Modified: April 29, 2026, 6:50 p.m.
Total resulsts: 347736
Page 57 of 34,774
ยซ previous page ยป next page
Filters