|
311
|
6.5 |
MEDIUM
Network
|
-
|
-
|
VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal seq…
New
|
CWE-22
Path Traversal
|
CVE-2018-25311
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312
|
6.5 |
MEDIUM
Network
|
-
|
-
|
LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interfac…
New
|
CWE-22
Path Traversal
|
CVE-2018-25312
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313
|
8.4 |
HIGH
Local
|
-
|
-
|
Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Na…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25314
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314
|
8.4 |
HIGH
Local
|
-
|
-
|
Alloksoft Video joiner 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25315
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315
|
8.8 |
HIGH
Network
|
-
|
-
|
Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privilege…
New
|
CWE-94
Code Injection
|
CVE-2026-34965
|
2026-04-30 06:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
316
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in …
New
|
CWE-22
Path Traversal
|
CVE-2026-7403
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317
|
7.3 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.p…
New
|
CWE-22 CWE-23
Path Traversal Relative Path Traversal
|
CVE-2026-7404
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
318
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7407
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation r…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7408
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320
|
4.4 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following.…
New
|
CWE-59 CWE-61
Link Following UNIX Symbolic Link (Symlink) Following
|
CVE-2026-7397
|
2026-04-30 06:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|