|
1711
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attacker…
|
CWE-352
Origin Validation Error
|
CVE-2018-25298
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1712
|
8.4 |
HIGH
Local
|
-
|
-
|
Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malici…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25299
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1713
|
6.2 |
MEDIUM
Local
|
-
|
-
|
librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service by processing malformed SVG files. Attackers can supply crafted SVG input to the…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25305
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1714
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and e…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-50328
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1715
|
4.0 |
MEDIUM
Local
|
-
|
-
|
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-42798
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1716
|
4.4 |
MEDIUM
Local
|
-
|
-
|
AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boun…
|
CWE-346
Origin Validation Error
|
CVE-2026-7439
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1717
|
8.8 |
HIGH
Network
|
-
|
-
|
AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs …
|
CWE-94
Code Injection
|
CVE-2026-7466
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1718
|
8.2 |
HIGH
Network
|
-
|
-
|
XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers c…
|
CWE-89
SQL Injection
|
CVE-2018-25300
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1719
|
8.4 |
HIGH
Local
|
-
|
-
|
Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious userna…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25301
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1720
|
8.4 |
HIGH
Local
|
-
|
-
|
Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploita…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25304
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|