|
491
|
8.8 |
HIGH
Local
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, SiYuan desktop renders notification messages as raw HTML inside an Electron renderer. The notification route POST /api/n…
New
|
CWE-78 CWE-79
OS Command Cross-site Scripting
|
CVE-2026-41421
|
2026-04-28 03:53 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
492
|
8.4 |
HIGH
Local
|
-
|
-
|
Faleemi Desktop Software 1.8.2 contains a local buffer overflow vulnerability in the Device alias field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attacker…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25263
|
2026-04-28 03:53 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
493
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Faleemi Plus 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can paste a 2000-byte payload into the…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25275
|
2026-04-28 03:53 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
494
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Bome Restorator 1793 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can create a ma…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25292
|
2026-04-28 03:53 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
495
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to crash the application by supplying an excessively long string in the optional …
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25293
|
2026-04-28 03:53 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
496
|
7.5 |
HIGH
Network
|
-
|
-
|
CEWE Photoshow 6.3.4 contains a buffer overflow vulnerability in the login dialog that allows attackers to crash the application by submitting oversized input. Attackers can inject 4000 bytes of data…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25294
|
2026-04-28 03:53 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
497
|
6.2 |
MEDIUM
Local
|
-
|
-
|
ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the IP input field. Attackers …
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2018-25295
|
2026-04-28 03:53 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
498
|
5.5 |
MEDIUM
Local
|
-
|
-
|
P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting an oversized input strin…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25296
|
2026-04-28 03:53 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
499
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in AgentDeskAI browser-tools-mcp up to 1.2.0. This issue affects some unknown processing of the file browser-tools-server/browser-connector.ts. Executing a manipulation can lead…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7064
|
2026-04-28 03:50 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
500
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeByLink.ts of the component getCodeByLink Endpoint. T…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7084
|
2026-04-28 03:50 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|