CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2019-25588

    Last Modified: 26 Mar 2026

    BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

    Published: 22 Mar 2026
    6.9
    Medium

    CVE-2019-25587

    Last Modified: 26 Mar 2026

    BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessively long string value. Attackers can enable the Override Storage-Path setting and paste a buffer of 500 bytes or more to trigger an application crash when saving the configuration.

    Published: 22 Mar 2026
    6.9
    Medium

    CVE-2019-25586

    Last Modified: 25 Mar 2026

    Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From URL' field during torrent addition to trigger an application crash.

    Published: 22 Mar 2026
    6.9
    Medium

    CVE-2019-25585

    Last Modified: 25 Mar 2026

    Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into the Webseeds field during torrent creation to trigger an application crash.

    Published: 22 Mar 2026
    6.9
    Medium

    CVE-2019-25584

    Last Modified: 25 Mar 2026

    RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a malicious payload exceeding 4000 bytes into the Server field via the Settings menu to trigger an application crash.

    Published: 22 Mar 2026
    6.9
    Medium

    CVE-2019-25583

    Last Modified: 25 Mar 2026

    RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username field via Settings > Network to trigger an application crash.

    Published: 22 Mar 2026
    1.9
    Low

    CVE-2026-4530

    Last Modified: 24 Apr 2026

    A security flaw has been discovered in apconw Aix-DB up to 1.2.3. This impacts an unknown function of the file agent/text2sql/rag/terminology_retriever.py. Performing a manipulation of the argument Description results in sql injection. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Mar 2026
    7.4
    High

    CVE-2026-4529

    Last Modified: 30 Apr 2026

    A vulnerability was identified in D-Link DHP-1320 1.00WWB04. This affects the function redirect_count_down_page of the component SOAP Handler. Such manipulation leads to stack-based buffer overflow. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 21 Mar 2026
    8.1
    High

    CVE-2026-3629

    Last Modified: 24 Apr 2026

    The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' method does not include sensitive meta keys such as 'wp_capabilities'. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator by submitting a crafted registration request that sets the 'wp_capabilities' meta key. The vulnerability can only be exploited if the "Show fields in profile" setting is enabled and a CSV with a wp_capabilities column header has been previously imported.

    Published: 21 Mar 2026
    5.5
    Medium

    CVE-2026-4528

    Last Modified: 24 Apr 2026

    A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component URL Validation Handler. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

    Published: 21 Mar 2026
    2.3
    Low

    CVE-2026-2756

    Last Modified: 24 Apr 2026

    A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The exploitability is reported as difficult. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Mar 2026
    7.1
    High

    CVE-2019-25582

    Last Modified: 25 Mar 2026

    i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating the file parameter in index.php. Attackers can send GET requests to index.php with file_manager=image and supply arbitrary file paths like src/config.inc.php to retrieve configuration files and sensitive system data.

    Published: 21 Mar 2026
    8.8
    High

    CVE-2019-25581

    Last Modified: 25 Mar 2026

    i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the objGroupID parameter. Attackers can send GET requests with crafted SQL payloads in the objGroupID parameter to extract sensitive database information including usernames, database names, and version details.

    Published: 21 Mar 2026
    8.8
    High

    CVE-2019-25580

    Last Modified: 15 Apr 2026

    ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the IMG parameter to extract sensitive database information including version and database names.

    Published: 21 Mar 2026
    8.7
    High

    CVE-2019-25579

    Last Modified: 22 Apr 2026

    phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.

    Published: 21 Mar 2026
    8.8
    High

    CVE-2019-25578

    Last Modified: 27 Mar 2026

    phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the idnews parameter. Attackers can send crafted GET requests to GeneratePDF.php with SQL payloads in the idnews parameter to extract sensitive database information or manipulate queries.

    Published: 21 Mar 2026
    6.8
    Medium

    CVE-2019-25577

    Last Modified: 15 Apr 2026

    SeoToaster Ecommerce 3.0.0 contains a local file inclusion vulnerability that allows authenticated attackers to read arbitrary files by manipulating path parameters in backend theme endpoints. Attackers can send POST requests to /backend/backend_theme/editcss/ or /backend/backend_theme/editjs/ with directory traversal sequences in the getcss or getjs parameters to retrieve file contents.

    Published: 21 Mar 2026
    8.8
    High

    CVE-2019-25576

    Last Modified: 15 Apr 2026

    Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Attackers can send GET requests to the category endpoint with URL-encoded SQL UNION statements to extract database information including usernames, database names, and MySQL version details.

    Published: 21 Mar 2026
    8.8
    High

    CVE-2019-25575

    Last Modified: 15 Apr 2026

    SimplePress CMS 1.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'p' and 's' parameters. Attackers can send GET requests with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.

    Published: 21 Mar 2026
    7.1
    High

    CVE-2019-25574

    Last Modified: 15 Jul 2026

    Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

    Published: 21 Mar 2026
    7.1
    High

    CVE-2019-25573

    Last Modified: 15 Jul 2026

    Green CMS 2.x contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cat parameter. Attackers can send GET requests to index.php with m=admin, c=posts, a=index parameters and inject SQL code in the cat parameter to manipulate database queries and extract sensitive information.

    Published: 21 Mar 2026
    2.1
    Low

    CVE-2026-4516

    Last Modified: 29 Apr 2026

    A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1. This vulnerability affects unknown code of the file metagpt/actions/di/write_analysis_code.py of the component DataInterpreter. The manipulation results in injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25572

    Last Modified: 15 Apr 2026

    NordVPN 6.19.6 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in the email input field. Attackers can paste a buffer of 100,000 characters into the email field during login to trigger an application crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25571

    Last Modified: 25 Mar 2026

    MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively long URL string. Attackers can create a malicious MP3 file with a buffer containing 4000 bytes of data appended to a URL, which causes the application to crash when the file is opened through the File > Open URL dialog.

    Published: 21 Mar 2026
    6.8
    Medium

    CVE-2019-25570

    Last Modified: 25 Mar 2026

    RealTerm Serial Terminal 2.0.0.70 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Port field. Attackers can paste a buffer of 1000 characters into the Port input field and click the open button to trigger a crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25569

    Last Modified: 25 Mar 2026

    RealTerm Serial Terminal 2.0.0.70 contains a stack-based buffer overflow vulnerability in the Echo Port field that allows local attackers to crash the application by triggering a structured exception handler (SEH) chain corruption. Attackers can craft a malicious input string with 268 bytes of padding followed by SEH overwrite values and paste it into the Port field to cause denial of service.

    Published: 21 Mar 2026
    9.3
    Critical

    CVE-2019-25568

    Last Modified: 21 Apr 2026

    Memu Play 6.0.7 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by replacing the MemuService.exe executable. Attackers can rename and overwrite MemuService.exe in the installation directory with a malicious executable, which executes with system-level privileges when the service restarts after a computer reboot.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25567

    Last Modified: 16 Apr 2026

    Valentina Studio 9.0.5 Linux contains a buffer overflow vulnerability in the Host field of the connection dialog that allows local attackers to crash the application by supplying an oversized input string. Attackers can trigger the vulnerability by pasting a crafted buffer exceeding 264 bytes into the Host field during server connection attempts, causing a denial of service.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25566

    Last Modified: 16 Apr 2026

    TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can create a malicious file with 1000 repeated characters, paste the content into the volume name field during disk image creation, and trigger an application crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25565

    Last Modified: 16 Apr 2026

    Magic Iso Maker 5.5 build 281 contains a buffer overflow vulnerability in the Serial Code registration field that allows local attackers to crash the application by submitting an oversized input. Attackers can generate a file containing 5000 bytes of data, paste it into the Serial Code field during registration, and trigger a denial of service condition that crashes the application.

    Published: 21 Mar 2026
    6.8
    Medium

    CVE-2019-25564

    Last Modified: 25 Mar 2026

    PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Group field. Attackers can paste a buffer overflow payload into the Group property field and click Ok to trigger an application crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25563

    Last Modified: 25 Mar 2026

    PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying a malformed image file. Attackers can trigger the vulnerability through the Create SC feature by selecting a crafted BMP file with an oversized buffer, causing the application to crash.

    Published: 21 Mar 2026
    6.8
    Medium

    CVE-2019-25562

    Last Modified: 25 Mar 2026

    jetAudio 8.1.7 contains a buffer overflow vulnerability in the video converter component that allows local attackers to crash the application by supplying an oversized string in the File Naming field. Attackers can paste a malicious buffer of 512 bytes into the File Naming parameter and trigger the crash by clicking the Preview button, causing a denial of service.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25561

    Last Modified: 16 Apr 2026

    Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Title field. Attackers can paste a 5000-byte buffer into the Title input field and save the file to trigger a denial of service condition.

    Published: 21 Mar 2026
    8.7
    High

    CVE-2019-25560

    Last Modified: 16 Apr 2026

    Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.

    Published: 21 Mar 2026
    6.8
    Medium

    CVE-2019-25559

    Last Modified: 16 Apr 2026

    SpotPaltalk 1.1.5 contains a denial of service vulnerability in the registration code input field that allows local attackers to crash the application by submitting an excessively long string. Attackers can paste a buffer of 1000 characters into the Name/Key field during registration to trigger a crash when the OK button is clicked.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25558

    Last Modified: 16 Apr 2026

    Selfie Studio 2.17 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a large string of characters into the New Width or New Height field to trigger a buffer overflow that crashes the application.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25557

    Last Modified: 25 Mar 2026

    TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability that allows local attackers to crash the application by importing a malformed .srp script file. Attackers can create a .srp file containing an excessively large buffer and import it through the Script Player interface to trigger an application crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25556

    Last Modified: 25 Mar 2026

    TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Resize Image function that allows local attackers to crash the application by supplying an excessively long buffer. Attackers can paste a malicious string into the New Width or New Height field to trigger a buffer overflow that causes the application to crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25555

    Last Modified: 25 Mar 2026

    TwistedBrush Pro Studio 24.06 contains a denial of service vulnerability in the Script Recorder component that allows local attackers to crash the application by supplying an excessively large buffer. Attackers can paste a malicious string containing 500,000 characters into the Description field of the Script Recorder dialog to trigger an application crash.

    Published: 21 Mar 2026
    6.8
    Medium

    CVE-2019-25554

    Last Modified: 16 Apr 2026

    Tomabo MP4 Converter 3.25.22 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can trigger a buffer overflow by pasting a large payload into the Name parameter when adding a preset in the Video/Audio Formats options, causing the application to crash when Reset All is clicked.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25553

    Last Modified: 10 Apr 2026

    CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can create a malformed JPG file with an oversized buffer and trigger the crash through the import functionality during the image processing workflow.

    Published: 21 Mar 2026
    8.7
    High

    CVE-2019-25552

    Last Modified: 10 Apr 2026

    CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submitting an excessively long buffer to the password field. Attackers can paste a large string of repeated characters into the password input during the upload process to trigger an application crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25551

    Last Modified: 25 Mar 2026

    Sandboxie 5.30 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Program Alerts configuration field. Attackers can paste a buffer of 5000 characters into the 'Select or enter a program' field during program alert configuration to trigger an application crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25550

    Last Modified: 16 Apr 2026

    Encrypt PDF 2.3 contains a buffer overflow vulnerability that allows local attackers to crash the application by inputting excessively long strings into password fields. Attackers can paste a 1000-byte buffer into the User Password or Master Password field in the Settings dialog to trigger an application crash when importing PDF files.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25549

    Last Modified: 16 Apr 2026

    VeryPDF PCL Converter 2.7 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long password string. Attackers can trigger a buffer overflow by entering a 3000-byte password in the PDF Security encryption fields, causing the application to crash when processing PCL files.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25548

    Last Modified: 16 Apr 2026

    BlueStacks 4.80.0.1060 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to the search field. Attackers can paste a buffer of 100,000 'A' characters into the search field and trigger a search operation to cause the application to crash.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25547

    Last Modified: 25 Mar 2026

    NetAware 1.20 contains a buffer overflow vulnerability in the User Blocking feature that allows local attackers to crash the application by supplying oversized input. Attackers can paste a malicious buffer of 512 bytes into the 'Add a website or keyword to be filtered' field and trigger a crash when removing the created block.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25546

    Last Modified: 25 Mar 2026

    NetAware 1.20 contains a buffer overflow vulnerability in the Share Name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can trigger a denial of service by pasting a 1000-byte buffer into the Share Name parameter when adding a new share through the Manage Shares interface.

    Published: 21 Mar 2026
    6.9
    Medium

    CVE-2019-25545

    Last Modified: 16 Apr 2026

    Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed.

    Published: 21 Mar 2026