8.7

CVSS4.0

CVE-2026-4553 - Tenda F453 Parameters Natlimit fromNatlimit stack-based overflow

A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is puโ€ฆ

๐Ÿ“… Published: March 22, 2026, 3:24 p.m. ๐Ÿ”„ Last Modified: March 22, 2026, 3:24 p.m.

8.7

CVSS4.0

CVE-2026-4552 - Tenda F453 Parameters VirtualSer fromVirtualSer memory corruption

A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. Thโ€ฆ

๐Ÿ“… Published: March 22, 2026, 2:31 p.m. ๐Ÿ”„ Last Modified: March 22, 2026, 2:31 p.m.

8.7

CVSS4.0

CVE-2026-4551 - Tenda F453 Parameters SafeClientFilter fromSafeClientFilter memory corruption

A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the argument menufacturer/Go results in stack-based buffer overflow. The attack is posโ€ฆ

๐Ÿ“… Published: March 22, 2026, 2:31 p.m. ๐Ÿ”„ Last Modified: March 22, 2026, 2:31 p.m.

5.1

CVSS4.0

CVE-2026-4550 - code-projects Simple Gym Management System func.php sql injection

A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the publiโ€ฆ

๐Ÿ“… Published: March 22, 2026, 1:47 p.m. ๐Ÿ”„ Last Modified: March 22, 2026, 1:47 p.m.

2.3

CVSS4.0

CVE-2026-4549 - mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorizatiโ€ฆ

A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The compโ€ฆ

๐Ÿ“… Published: March 22, 2026, 1:47 p.m. ๐Ÿ”„ Last Modified: March 22, 2026, 1:47 p.m.

8.6

CVSS4.0

CVE-2019-25619 - FTP Shell Server 6.83 Buffer Overflow via Account Name

FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to overwrite theโ€ฆ

๐Ÿ“… Published: March 22, 2026, 1:38 p.m. ๐Ÿ”„ Last Modified: March 22, 2026, 1:38 p.m.

6.9

CVSS4.0

CVE-2019-25618 - AdminExpress 1.2.5 Denial of Service via System Compare

AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can paste a large buffer of characters into the Folder Path field and trigger the comparison function to cauโ€ฆ

๐Ÿ“… Published: March 22, 2026, 1:38 p.m. ๐Ÿ”„ Last Modified: March 24, 2026, 3:14 p.m.

6.9

CVSS4.0

CVE-2019-25617 - Ease Audio Converter 5.30 Denial of Service via Audio Cutter

Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local attackers to crash the application by processing malformed MP4 files. Attackers can create a crafted MP4 file containing an oversized buffer and load it through the Audio Cutter interโ€ฆ

๐Ÿ“… Published: March 22, 2026, 1:38 p.m. ๐Ÿ”„ Last Modified: March 23, 2026, 7:03 p.m.

6.9

CVSS4.0

CVE-2019-25616 - AnMing MP3 CD Burner 2.0 Local Denial of Service

AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized string. Attackers can paste a 6000-byte payload into the registration name field to trigger a denial of service condition.

๐Ÿ“… Published: March 22, 2026, 1:38 p.m. ๐Ÿ”„ Last Modified: March 22, 2026, 1:38 p.m.

8.6

CVSS4.0

CVE-2019-25615 - Lavavo CD Ripper 4.20 Local SEH Buffer Overflow

Lavavo CD Ripper 4.20 contains a structured exception handling (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Activation Name field. Attackers can craft a payload with controlled buffer data, NSEH jump instrucโ€ฆ

๐Ÿ“… Published: March 22, 2026, 1:38 p.m. ๐Ÿ”„ Last Modified: March 22, 2026, 1:38 p.m.
Total resulsts: 340040
Page 71 of 34,004
ยซ previous page ยป next page
Filters