|
911
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the com…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9367
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Hand…
New
|
CWE-264 CWE-265
Permissions, Privileges, and Access Controls Privilege Issues
|
CVE-2026-9368
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboar…
New
|
CWE-697
Incorrect Comparison
|
CVE-2026-9369
|
2026-05-27 04:50 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET …
New
|
CWE-89
SQL Injection
|
CVE-2018-25340
|
2026-05-27 04:47 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET …
New
|
CWE-89
SQL Injection
|
CVE-2018-25341
|
2026-05-27 04:47 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
8.2 |
HIGH
Network
|
-
|
-
|
Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in sear…
New
|
CWE-89
SQL Injection
|
CVE-2018-25342
|
2026-05-27 04:47 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla! Component EkRishta 2.10 contains an error-based SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the usernam…
New
|
CWE-89
SQL Injection
|
CVE-2018-25351
|
2026-05-27 04:47 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
8.4 |
HIGH
Local
|
-
|
-
|
Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can …
New
|
CWE-276
Incorrect Default Permissions
|
CVE-2018-25359
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
8.4 |
HIGH
Local
|
-
|
-
|
AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured ex…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2018-25360
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
6.8 |
MEDIUM
Local
|
-
|
-
|
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption k…
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2018-25361
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|