|
1911
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Hand…
|
CWE-264 CWE-265
Permissions, Privileges, and Access Controls Privilege Issues
|
CVE-2026-9368
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1912
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboar…
|
CWE-697
Incorrect Comparison
|
CVE-2026-9369
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1913
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET …
|
CWE-89
SQL Injection
|
CVE-2018-25340
|
2026-05-27 04:47 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1914
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET …
|
CWE-89
SQL Injection
|
CVE-2018-25341
|
2026-05-27 04:47 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1915
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in sear…
|
CWE-89
SQL Injection
|
CVE-2018-25342
|
2026-05-27 04:47 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1916
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the usernam…
|
CWE-89
SQL Injection
|
CVE-2018-25351
|
2026-05-27 04:47 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1917
|
8.4 |
HIGH
Local
|
-
|
-
|
Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can …
|
CWE-276
Incorrect Default Permissions
|
CVE-2018-25359
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1918
|
8.4 |
HIGH
Local
|
-
|
-
|
AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured ex…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2018-25360
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1919
|
6.8 |
MEDIUM
Local
|
-
|
-
|
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption k…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2018-25361
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1920
|
8.2 |
HIGH
Network
|
-
|
-
|
Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit unio…
|
CWE-89
SQL Injection
|
CVE-2018-25362
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|