6.9

CVSS4.0

CVE-2019-25546 - NetAware 1.20 Share Name Denial of Service

NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by pasting a 1000-byte buffer into the Share Name parameter when adding a new share …

πŸ“… Published: March 21, 2026, 12:46 p.m. πŸ”„ Last Modified: March 23, 2026, 5:32 p.m.

6.9

CVSS4.0

CVE-2019-25545 - Terminal Services Manager 3.2.1 Local Buffer Overflow Denial of Service

Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during comput…

πŸ“… Published: March 21, 2026, 12:46 p.m. πŸ”„ Last Modified: March 23, 2026, 8:22 p.m.

6.9

CVSS4.0

CVE-2019-25544 - Pidgin 2.13.0 Denial of Service via Malformed Username

Pidgin 2.13.0 contains a denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation. Attackers can input a buffer of 1000 characters in the username field and trigger a crash when joining a chat, caus…

πŸ“… Published: March 21, 2026, 12:46 p.m. πŸ”„ Last Modified: March 23, 2026, 2:31 p.m.

5.3

CVSS4.0

CVE-2026-4515 - Foundation Agents MetaGPT operator.py code_generate code injection

A vulnerability has been found in Foundation Agents MetaGPT up to 0.8.1. This affects the function code_generate of the file metagpt/ext/aflow/scripts/operator.py. The manipulation leads to code injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public …

πŸ“… Published: March 21, 2026, 11:32 a.m. πŸ”„ Last Modified: March 24, 2026, 2:09 p.m.

5.3

CVSS4.0

CVE-2026-4514 - PbootCMS Backend UserController.php access control

A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The attack may be performed…

πŸ“… Published: March 21, 2026, 10:32 a.m. πŸ”„ Last Modified: March 23, 2026, 9:49 a.m.

5.3

CVSS4.0

CVE-2026-4513 - vanna-ai vanna base.py ask sql injection

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The…

πŸ“… Published: March 21, 2026, 10:02 a.m. πŸ”„ Last Modified: March 23, 2026, 9:49 a.m.

5.3

CVSS4.0

CVE-2026-4511 - vanna-ai vanna legacy exec injection

A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early a…

πŸ“… Published: March 21, 2026, 8:32 a.m. πŸ”„ Last Modified: March 23, 2026, 9:49 a.m.

5.3

CVSS4.0

CVE-2026-4510 - PbootCMS Parameter MemberController.php alert_location cross site scripting

A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the argument backurl causes cross site scripting. Remote exploitation of the attack is pos…

πŸ“… Published: March 21, 2026, 7:02 a.m. πŸ”„ Last Modified: March 23, 2026, 9:49 a.m.

7.5

CVSS3.1

CVE-2026-4373 - JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field

The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating tha…

πŸ“… Published: March 21, 2026, 6:45 a.m. πŸ”„ Last Modified: March 24, 2026, 2:05 p.m.

5.3

CVSS4.0

CVE-2026-4509 - PbootCMS File Upload file.php incomplete blacklist

A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The exploit has been released …

πŸ“… Published: March 21, 2026, 6:02 a.m. πŸ”„ Last Modified: March 24, 2026, 2:04 p.m.
Total resulsts: 339922
Page 70 of 33,993
Β« previous page Β» next page
Filters