8.7

CVSS4.0

CVE-2026-4551 - Tenda F453 Parameters SafeClientFilter fromSafeClientFilter memory corruption

A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the argument menufacturer/Go results in stack-based buffer overflow. The attack is pos…

📅 Published: March 22, 2026, 2:31 p.m. 🔄 Last Modified: March 22, 2026, 2:31 p.m.

5.1

CVSS4.0

CVE-2026-4550 - code-projects Simple Gym Management System func.php sql injection

A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the publi…

📅 Published: March 22, 2026, 1:47 p.m. 🔄 Last Modified: March 22, 2026, 1:47 p.m.

2.3

CVSS4.0

CVE-2026-4549 - mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorizati…

A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The comp…

📅 Published: March 22, 2026, 1:47 p.m. 🔄 Last Modified: March 25, 2026, 1:45 p.m.

8.6

CVSS4.0

CVE-2019-25619 - FTP Shell Server 6.83 Buffer Overflow via Account Name

FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to overwrite the…

📅 Published: March 22, 2026, 1:38 p.m. 🔄 Last Modified: March 22, 2026, 1:38 p.m.

6.9

CVSS4.0

CVE-2019-25618 - AdminExpress 1.2.5 Denial of Service via System Compare

AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can paste a large buffer of characters into the Folder Path field and trigger the comparison function to cau…

📅 Published: March 22, 2026, 1:38 p.m. 🔄 Last Modified: March 24, 2026, 3:14 p.m.

6.9

CVSS4.0

CVE-2019-25617 - Ease Audio Converter 5.30 Denial of Service via Audio Cutter

Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local attackers to crash the application by processing malformed MP4 files. Attackers can create a crafted MP4 file containing an oversized buffer and load it through the Audio Cutter inter…

📅 Published: March 22, 2026, 1:38 p.m. 🔄 Last Modified: March 23, 2026, 7:03 p.m.

6.9

CVSS4.0

CVE-2019-25616 - AnMing MP3 CD Burner 2.0 Local Denial of Service

AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized string. Attackers can paste a 6000-byte payload into the registration name field to trigger a denial of service condition.

📅 Published: March 22, 2026, 1:38 p.m. 🔄 Last Modified: March 22, 2026, 1:38 p.m.

8.6

CVSS4.0

CVE-2019-25615 - Lavavo CD Ripper 4.20 Local SEH Buffer Overflow

Lavavo CD Ripper 4.20 contains a structured exception handling (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Activation Name field. Attackers can craft a payload with controlled buffer data, NSEH jump instruc…

📅 Published: March 22, 2026, 1:38 p.m. 🔄 Last Modified: March 25, 2026, 1:43 p.m.

9.3

CVSS4.0

CVE-2019-25614 - Free Float FTP 1.0 STOR Command Remote Buffer Overflow

Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command contain…

📅 Published: March 22, 2026, 1:38 p.m. 🔄 Last Modified: March 23, 2026, 7:42 p.m.

8.7

CVSS4.0

CVE-2019-25613 - Easy Chat Server 3.1 Denial of Service via message Parameter

Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large m…

📅 Published: March 22, 2026, 1:38 p.m. 🔄 Last Modified: March 22, 2026, 1:38 p.m.
Total resulsts: 340058
Page 73 of 34,006
« previous page » next page
Filters