|
641
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A security vulnerability has been detected in Tenda F456 1.0.0.5. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component httpd. The manipulation of the argumen…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7055
|
2026-04-30 07:24 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
642
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A vulnerability was detected in Tenda F456 1.0.0.5. Impacted is the function fromSafeUrlFilter of the file /goform/SafeUrlFilter of the component httpd. The manipulation of the argument page results …
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7056
|
2026-04-30 07:18 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
643
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A flaw has been found in Tenda F456 1.0.0.5. The affected element is an unknown function of the file /goform/setcfm of the component httpd. This manipulation of the argument funcname/funcpara1 causes…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7057
|
2026-04-30 07:18 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
644
|
7.8 |
HIGH
Local
|
-
|
-
|
Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a ma…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25302
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
645
|
8.4 |
HIGH
Local
|
-
|
-
|
Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exce…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2018-25303
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
646
|
6.5 |
MEDIUM
Network
|
-
|
-
|
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal seq…
New
|
CWE-22
Path Traversal
|
CVE-2018-25311
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
647
|
6.5 |
MEDIUM
Network
|
-
|
-
|
LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interfac…
New
|
CWE-22
Path Traversal
|
CVE-2018-25312
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
648
|
8.4 |
HIGH
Local
|
-
|
-
|
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Na…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25314
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
649
|
8.4 |
HIGH
Local
|
-
|
-
|
Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25315
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
650
|
8.8 |
HIGH
Network
|
-
|
-
|
Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privilege…
New
|
CWE-94
Code Injection
|
CVE-2026-34965
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|