|
381
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting improper origin checking. Attackers can craft malicious H…
New
|
CWE-352
Origin Validation Error
|
CVE-2018-25370
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
382
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Visual Ping 0.8.0.0 contains a buffer overflow vulnerability in input field handling that allows local attackers to crash the application by supplying oversized data. Attackers can inject malicious p…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25369
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
383
|
7.5 |
HIGH
Network
|
-
|
-
|
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers ca…
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2018-25368
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
384
|
6.2 |
MEDIUM
Local
|
-
|
-
|
NASA openVSP 3.16.1 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the geometry name field. Attackers can tri…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25367
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
385
|
8.4 |
HIGH
Local
|
-
|
-
|
CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a p…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25366
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
386
|
7.5 |
HIGH
Network
|
-
|
-
|
PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative path sequences in GET requests. Attackers can use pat…
New
|
CWE-22
Path Traversal
|
CVE-2018-25365
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
387
|
8.2 |
HIGH
Network
|
-
|
-
|
Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the name parameter. Attackers can sub…
New
|
CWE-89
SQL Injection
|
CVE-2018-25364
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
388
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Twitter-Clone 1 contains a cross-site request forgery vulnerability that allows remote attackers to force victims to delete posts by crafting malicious HTML forms. Attackers can create hidden forms t…
New
|
CWE-352
Origin Validation Error
|
CVE-2018-25363
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
389
|
8.2 |
HIGH
Network
|
-
|
-
|
Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit unio…
New
|
CWE-89
SQL Injection
|
CVE-2018-25362
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
390
|
6.8 |
MEDIUM
Local
|
-
|
-
|
Soroush IM Desktop App 0.17.0 contains an authentication bypass vulnerability that allows local attackers to remove passcodes by injecting pre-encrypted database entries using a constant encryption k…
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2018-25361
|
2026-05-26 00:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|