8.5

CVSS4.0

CVE-2019-25274 - ProShow Producer 9.0.3797 - Unquoted Service Path

ProShow Producer 9.0.3797 contains an unquoted service path vulnerability in the ScsiAccess service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during s…

πŸ“… Published: Feb. 4, 2026, 11:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25273 - Easy-Hide-IP 5.0.0.3 - 'EasyRedirect' Unquoted Service Path

Easy-Hide-IP 5.0.0.3 contains an unquoted service path vulnerability in the EasyRedirect service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Easy-Hide-IP\rdr\EasyRedirect.exe' to inject malicious executables and esc…

πŸ“… Published: Feb. 4, 2026, 11:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25272 - TexasSoft CyberPlanet 6.4.131 - 'CCSrvProxy' Unquoted Service Path

TexasSoft CyberPlanet 6.4.131 contains an unquoted service path vulnerability in the CCSrvProxy service that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\TenaxSoft\CyberPlanet\SrvProxy.exe' to inject malicious executables and g…

πŸ“… Published: Feb. 4, 2026, 11:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25271 - NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path

NETGATE Data Backup 3.0.620 contains an unquoted service path vulnerability in its NGDatBckpSrv Windows service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with LocalSystem privileges by placing executable files in specific directory locations.

πŸ“… Published: Feb. 4, 2026, 11:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25269 - Amiti Antivirus 25.0.640 - Unquoted Service Path Vulnerability

Amiti Antivirus 25.0.640 contains an unquoted service path vulnerability in its Windows service configurations. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges by placing executable files in specific directory locations.

πŸ“… Published: Feb. 4, 2026, 11:15 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2019-25267 - Wing FTP Server 6.0.7 - Unquoted Service Path

Wing FTP Server 6.0.7 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the service configuration to inject malicious executables that will be launched …

πŸ“… Published: Feb. 4, 2026, 11:15 p.m. πŸ”„ Last Modified: March 5, 2026, 1:25 a.m.

3.8

CVSS3.1

CVE-2025-22873 - Improper access to parent directory of root in os

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained with…

πŸ“… Published: Feb. 4, 2026, 11:05 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 3:16 p.m.

5.3

CVSS4.0

CVE-2026-1895 - WeKan Attachment Storage lists.js applyWipLimit ListWIPBleed access control

A flaw has been found in WeKan up to 8.20. Affected is the function applyWipLimit of the file models/lists.js of the component Attachment Storage Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. Upgrading to version 8.21 is able to address…

πŸ“… Published: Feb. 4, 2026, 11:02 p.m. πŸ”„ Last Modified: April 18, 2026, 1:45 p.m.

5.3

CVSS4.0

CVE-2026-1894 - WeKan REST API checklistItems.js Checklist REST Bleed improper authorization

A vulnerability was detected in WeKan up to 8.20. This impacts an unknown function of the file models/checklistItems.js of the component REST API. Performing a manipulation of the argument item.cardId/item.checklistId/card.boardId results in improper authorization. Remote exploitation of the attack…

πŸ“… Published: Feb. 4, 2026, 10:32 p.m. πŸ”„ Last Modified: April 17, 2026, 11:15 p.m.

9.3

CVSS4.0

CVE-2025-62616 - AutoGPT has SSRF vulnerability in SendDiscordFileBlock

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.34, in SendDiscordFileBlock, the third-party library aiohttp.ClientSession().get is used directly to access the URL, b…

πŸ“… Published: Feb. 4, 2026, 10:28 p.m. πŸ”„ Last Modified: Feb. 17, 2026, 8:05 p.m.
Total resulsts: 349182
Page 1794 of 34,919
Β« previous page Β» next page
Filters