6.9

CVSS4.0

CVE-2019-25622 - Paint Studio 2.17 Denial of Service via Malformed Input

Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a text file with a large buffer of characters and trigger the application to read it, causing the appl…

πŸ“… Published: March 23, 2026, 1:48 p.m. πŸ”„ Last Modified: March 25, 2026, 2:48 p.m.

6.9

CVSS4.0

CVE-2019-25621 - Pixel Studio 2.17 Denial of Service via Malformed Input

Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters, causing the application to become unresponsive or …

πŸ“… Published: March 23, 2026, 1:48 p.m. πŸ”„ Last Modified: March 25, 2026, 2:49 p.m.

6.9

CVSS4.0

CVE-2019-25620 - Tree Studio 2.17 Denial of Service via Malformed Input

Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application …

πŸ“… Published: March 23, 2026, 1:48 p.m. πŸ”„ Last Modified: March 25, 2026, 2:49 p.m.

5.1

CVSS4.0

CVE-2026-33297 - AVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.php

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password value is processed, any password containing non-numer…

πŸ“… Published: March 23, 2026, 1:46 p.m. πŸ”„ Last Modified: March 25, 2026, 2:49 p.m.

5.3

CVSS4.0

CVE-2026-4589 - kalcaddle kodbox fileGet Endpoint editor.class.php PathDriverUrl server-side request forgery

A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side request forgery. The…

πŸ“… Published: March 23, 2026, 1:32 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

9.3

CVSS4.0

CVE-2025-41008 - SQL Injection in Sinturno

SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'client' parameter in the '/_adm/scripts/modalReport_data.php' endpoint.

πŸ“… Published: March 23, 2026, 12:59 p.m. πŸ”„ Last Modified: March 25, 2026, 2:49 p.m.

6.3

CVSS4.0

CVE-2026-4588 - kalcaddle kodbox Site-level API key shareOut.class.php shareSafeGroup hard-coded key

A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-level API key Handler. This manipulation of the argument sk causes use of hard-coded cryptographic key…

πŸ“… Published: March 23, 2026, 12:46 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

6.3

CVSS4.0

CVE-2026-4587 - HybridAuth SSL Curl.php certificate validation

A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument curlOptions results in improper certificate validation. The attack can be launched remotely. This attac…

πŸ“… Published: March 23, 2026, 12:46 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

8.7

CVSS4.0

CVE-2026-1958 - Hard-coded passwords in KlinikaXP

Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious up…

πŸ“… Published: March 23, 2026, 12:40 p.m. πŸ”„ Last Modified: March 25, 2026, 2:49 p.m.

7.7

CVSS4.0

CVE-2026-31851 - Lack of Rate Limiting Enables Brute-Force Attacks in Nexxt Nebula 300+

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks …

πŸ“… Published: March 23, 2026, 12:21 p.m. πŸ”„ Last Modified: April 29, 2026, 5:37 p.m.
Total resulsts: 349182
Page 972 of 34,919
Β« previous page Β» next page
Filters