|
2261
|
8.4 |
HIGH
Local
|
-
|
-
|
NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25733
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2262
|
4.0 |
MEDIUM
Local
|
-
|
-
|
Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanit…
|
CWE-22
Path Traversal
|
CVE-2019-25734
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2263
|
8.4 |
HIGH
Local
|
-
|
-
|
AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Att…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25735
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2264
|
8.4 |
HIGH
Local
|
-
|
-
|
LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25736
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2265
|
9.8 |
CRITICAL
Network
|
-
|
-
|
WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option actio…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-25738
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2266
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requ…
|
CWE-22
Path Traversal
|
CVE-2019-25740
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2267
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25741
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2268
|
8.2 |
HIGH
Network
|
-
|
-
|
WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through th…
|
CWE-89
SQL Injection
|
CVE-2019-25745
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2269
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrat…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10704
|
2026-06-4 23:58 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2270
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10607
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|