7.1

CVSS4.0

CVE-2018-25311 - VideoFlow Digital Video Protection DVP 10 Authenticated Directory Traversal 2.10 (X-Prototype-Versi…

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal sequences in the ID parameter. Attackers can submit requests to downloadsys.pl, download_xml.pl, downlo…

πŸ“… Published: April 29, 2026, 7:25 p.m. πŸ”„ Last Modified: April 30, 2026, 2:14 p.m.

5.3

CVSS4.0

CVE-2018-25310 - VideoFlow Digital Video Protection DVP 10 Authenticated Remote Code Execution

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cross-site request forgery flaw in the web management interface. Attackers with valid credentials can le…

πŸ“… Published: April 29, 2026, 7:25 p.m. πŸ”„ Last Modified: April 30, 2026, 12:26 p.m.

9.3

CVSS4.0

CVE-2018-25318 - Tenda FH303/A300 V5.07.68_EN Cookie Session Weakness DNS Change

Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted admin cookie to change DNS serv…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: May 4, 2026, 6:40 p.m.

9.3

CVSS4.0

CVE-2018-25317 - Tenda W3002R/A302/W309R V5.07.64_en Cookie Session Weakness DNS Change

Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the /goform/AdvSetDns endpoint with a crafted a…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: May 5, 2026, 2:46 a.m.

9.3

CVSS4.0

CVE-2018-25316 - Tenda W308R v2 V5.07.48 Cookie Session Weakness DNS Change

Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language cookie to change DNS se…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: May 4, 2026, 6:42 p.m.

8.6

CVSS4.0

CVE-2018-25315 - Alloksoft Video joiner 4.6.1217 Buffer Overflow via License Name

Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with structured exception handler (SEH) overwrite and shellcode to achieve code exe…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: April 30, 2026, 1:08 p.m.

8.6

CVSS4.0

CVE-2018-25314 - Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handl…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: April 30, 2026, 12:22 p.m.

6.9

CVSS4.0

CVE-2018-25313 - SysGauge 4.5.18 Local Denial of Service via Proxy Configuration

SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can inject a large payload through the Proxy Server Host Name field in the Options menu to crash the appli…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: May 1, 2026, 4:38 p.m.

7.1

CVSS4.0

CVE-2018-25312 - LifeSize ClearSea 3.1.4 Directory Traversal Remote Code Execution

LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interface. Attackers can exploit the upload endpoint with directory traversal sequences to write files to ar…

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: April 30, 2026, 3:22 p.m.

5.1

CVSS4.0

CVE-2018-25309 - MyBB Recent threads 17.0 Persistent Cross-Site Scripting

MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can create threads with script tags in the subject parameter to execute arbitrary JavaScript in the browsers …

πŸ“… Published: April 29, 2026, 7:24 p.m. πŸ”„ Last Modified: May 1, 2026, 7:15 p.m.
Total resulsts: 348147
Page 96 of 34,815
Β« previous page Β» next page
Filters