|
71
|
8.2 |
HIGH
Network
|
-
|
-
|
MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter.…
New
|
CWE-89
SQL Injection
|
CVE-2018-25411
|
2026-05-31 01:17 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
72
|
7.1 |
HIGH
Network
|
-
|
-
|
SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send G…
New
|
CWE-89
SQL Injection
|
CVE-2018-25410
|
2026-05-31 01:17 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
73
|
8.8 |
HIGH
Network
|
-
|
-
|
SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload …
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-25409
|
2026-05-31 01:17 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
74
|
7.5 |
HIGH
Network
|
-
|
-
|
The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the filename pa…
New
|
CWE-22
Path Traversal
|
CVE-2018-25408
|
2026-05-31 01:17 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
75
|
8.2 |
HIGH
Network
|
-
|
-
|
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A…
New
|
CWE-89
SQL Injection
|
CVE-2018-25407
|
2026-05-31 01:17 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
76
|
8.2 |
HIGH
Network
|
-
|
-
|
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A…
New
|
CWE-89
SQL Injection
|
CVE-2018-25406
|
2026-05-31 01:17 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
77
|
8.2 |
HIGH
Network
|
-
|
-
|
eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. A…
New
|
CWE-89
SQL Injection
|
CVE-2018-25405
|
2026-05-31 01:16 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
78
|
8.8 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewal…
New
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10120
|
2026-05-31 00:16 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
79
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-70116
|
2026-05-31 00:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
80
|
8.8 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name…
New
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10119
|
2026-05-30 23:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|