CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-6016

    Last Modified: 23 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain conditions.

    Published: 22 Apr 2026
    2.7
    Low

    CVE-2025-9957

    Last Modified: 23 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to improper authorization checks.

    Published: 22 Apr 2026
    6.5
    Medium

    CVE-2026-1660

    Last Modified: 23 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service when importing issues due to improper input validation.

    Published: 22 Apr 2026
    8
    High

    CVE-2026-5262

    Last Modified: 23 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.

    Published: 22 Apr 2026
    4.3
    Medium

    CVE-2026-5377

    Last Modified: 23 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles of confidential or private issues in public projects due to improper access control in the issue description rendering process.

    Published: 22 Apr 2026
    8
    High

    CVE-2026-5816

    Last Modified: 23 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.

    Published: 22 Apr 2026
    5.4
    Medium

    CVE-2026-6515

    Last Modified: 23 Apr 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed a user to use invalidated or incorrectly scoped credentials to access Virtual Registries under certain conditions.

    Published: 22 Apr 2026
    4.3
    Medium

    CVE-2025-58922

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Avada allows Cross Site Request Forgery.This issue affects Avada: from n/a before 7.13.2.

    Published: 22 Apr 2026
    5.1
    Medium

    CVE-2024-58344

    Last Modified: 27 Apr 2026

    Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript code through the Forum Name field in dashboard settings. Attackers with admin privileges can store JavaScript payloads in the Forum Name field that execute in the browsers of all users visiting the forum, enabling session hijacking and data theft.

    Published: 22 Apr 2026
    9.3
    Critical

    CVE-2018-25272

    Last Modified: 27 Apr 2026

    ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to the database using default connector credentials, decrypt the DBA password, and execute commands via the xp_cmdshell stored procedure or add backdoor users to the BEDIENER table.

    Published: 22 Apr 2026
    6.9
    Medium

    CVE-2018-25271

    Last Modified: 27 Apr 2026

    Textpad 8.1.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long buffer string through the Run command interface. Attackers can paste a 5000-byte payload into the Command field via Tools > Run to trigger a buffer overflow that crashes the application.

    Published: 22 Apr 2026
    9.3
    Critical

    CVE-2018-25270

    Last Modified: 27 Apr 2026

    ThinkPHP 5.0.23 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by invoking functions through the routing parameter. Attackers can craft requests to the index.php endpoint with malicious function parameters to execute system commands with application privileges.

    Published: 22 Apr 2026
    5.1
    Medium

    CVE-2018-25269

    Last Modified: 25 May 2026

    ICEWARP 10.3.4 and 11.0.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML elements into emails by embedding base64-encoded payloads in object and embed tags. Attackers can craft emails containing data URIs with embedded scripts that execute in the client when the email is viewed, compromising user sessions and stealing sensitive information.

    Published: 22 Apr 2026
    8.6
    High

    CVE-2018-25268

    Last Modified: 27 Apr 2026

    LanSpy 2.0.1.159 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying oversized input to the scan field. Attackers can craft a payload with 688 bytes of padding followed by 4 bytes of controlled data to crash the application or potentially achieve code execution.

    Published: 22 Apr 2026
    6.9
    Medium

    CVE-2018-25267

    Last Modified: 29 Apr 2026

    UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attackers can craft a malicious filename string with 304 bytes of data followed by SEH record overwrite values and paste it into the Output FileName field to trigger a denial of service crash.

    Published: 22 Apr 2026
    6.9
    Medium

    CVE-2018-25266

    Last Modified: 27 Apr 2026

    Angry IP Scanner 3.5.3 contains a buffer overflow vulnerability in the preferences dialog that allows local attackers to crash the application by supplying an excessively large string. Attackers can generate a file containing a massive buffer of repeated characters and paste it into the unavailable value field in the display preferences to trigger a denial of service.

    Published: 22 Apr 2026
    8.6
    High

    CVE-2018-25265

    Last Modified: 27 Apr 2026

    LanSpy 2.0.1.159 contains a local buffer overflow vulnerability in the scan section that allows local attackers to execute arbitrary code by exploiting structured exception handling mechanisms. Attackers can craft malicious payloads using egghunter techniques to locate and execute shellcode, triggering code execution through SEH chain manipulation and controlled jumps.

    Published: 22 Apr 2026
    6.9
    Medium

    CVE-2018-25262

    Last Modified: 27 Apr 2026

    Angry IP Scanner for Linux 3.5.3 contains a denial of service vulnerability that allows local attackers to crash the application by supplying malformed input to the port selection field. Attackers can craft a malicious string containing buffer overflow patterns and paste it into the Preferences Ports tab to trigger an application crash.

    Published: 22 Apr 2026
    8.6
    High

    CVE-2018-25261

    Last Modified: 29 Apr 2026

    Iperius Backup 5.8.1 contains a local buffer overflow vulnerability in the structured exception handling (SEH) mechanism that allows local attackers to execute arbitrary code by supplying a malicious file path. Attackers can create a backup job with a crafted payload in the external file location field that triggers a buffer overflow when the backup job executes, enabling code execution with application privileges.

    Published: 22 Apr 2026
    8.6
    High

    CVE-2018-25260

    Last Modified: 29 Apr 2026

    MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload, paste it into the Server field via the CD menu's FreeDB Proxy Options, and trigger code execution when settings are accepted.

    Published: 22 Apr 2026
    8.6
    High

    CVE-2018-25259

    Last Modified: 29 Apr 2026

    Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH handler pointer to execute calc.exe or other payloads when imported through the add computers wizard.

    Published: 22 Apr 2026
    6.5
    Medium

    CVE-2026-33611

    Last Modified: 12 May 2026

    An operator allowed to use the REST API can cause the Authoritative server to produce invalid HTTPS or SVCB record data, which can in turn cause LMDB database corruption, if using the LMDB backend.

    Published: 22 Apr 2026
    5.9
    Medium

    CVE-2026-33610

    Last Modified: 24 Apr 2026

    A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS update request to it.

    Published: 22 Apr 2026
    5.3
    Medium

    CVE-2026-33609

    Last Modified: 24 Apr 2026

    Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.

    Published: 22 Apr 2026
    7.4
    High

    CVE-2026-33608

    Last Modified: 24 Apr 2026

    An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.

    Published: 22 Apr 2026
    7.5
    High

    CVE-2026-33593

    Last Modified: 24 Apr 2026

    A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.

    Published: 22 Apr 2026
    5.3
    Medium

    CVE-2026-33594

    Last Modified: 24 Apr 2026

    A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection.

    Published: 22 Apr 2026
    5.3
    Medium

    CVE-2026-33595

    Last Modified: 24 Apr 2026

    A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection.

    Published: 22 Apr 2026
    3.7
    Low

    CVE-2026-33597

    Last Modified: 24 Apr 2026

    PRSD detection denial of service

    Published: 22 Apr 2026
    3.1
    Low

    CVE-2026-33596

    Last Modified: 24 Apr 2026

    A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend.

    Published: 22 Apr 2026
    4.8
    Medium

    CVE-2026-33598

    Last Modified: 24 Apr 2026

    A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.

    Published: 22 Apr 2026
    3.1
    Low

    CVE-2026-33599

    Last Modified: 24 Apr 2026

    A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not enabled by default.

    Published: 22 Apr 2026
    6.5
    Medium

    CVE-2026-33602

    Last Modified: 24 Apr 2026

    A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service.

    Published: 22 Apr 2026
    5.3
    Medium

    CVE-2026-33254

    Last Modified: 27 Apr 2026

    An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default.

    Published: 22 Apr 2026
    7.6
    High

    CVE-2026-5750

    Last Modified: 22 Apr 2026

    An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated users to access data belonging to other registered users through various vulnerable authenticated resources in the application. The vulnerable endpoints result from: '/api/suppliers/v1/suppliers//false' to list user information; and '/#/supplier-registration/supplier-registration//2' to update your user information (personal details, documents, etc.).

    Published: 22 Apr 2026
    8.7
    High

    CVE-2026-5749

    Last Modified: 22 Apr 2026

    Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain a valid JWT token with which to interact with authenticated API resources. Successful exploitation of this vulnerability could allow an unauthenticated attacker to compromise the confidentiality of the affected resource, provided they have a valid token with which to interact with the API.

    Published: 22 Apr 2026
    9.6
    Critical

    CVE-2026-6356

    Last Modified: 12 May 2026

    A vulnerability in the web application allows standard users to escalate their privileges to those of a super administrator through parameter manipulation, enabling them to access and modify sensitive information.

    Published: 22 Apr 2026
    6.5
    Medium

    CVE-2026-6355

    Last Modified: 12 May 2026

    A vulnerability in the web application allows unauthorized users to access and manipulate sensitive data across different tenants by exploiting insecure direct object references. This could lead to unauthorized access to sensitive information and unauthorized changes to the tenant's configuration.

    Published: 22 Apr 2026
    8.8
    High

    CVE-2026-41651

    Last Modified: 5 May 2026

    PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5. A local unprivileged user can install arbitrary RPM packages as root, including executing RPM scriptlets, without authentication. The vulnerability is a TOCTOU race condition on `transaction->cached_transaction_flags` combined with a silent state-machine guard that discards illegal backward transitions while leaving corrupted flags in place. Three bugs exist in `src/pk-transaction.c`: 1. Unconditional flag overwrite (line 4036): `InstallFiles()` writes caller-supplied flags to `transaction->cached_transaction_flags` without checking whether the transaction has already been authorized/started. A second call blindly overwrites the flags even while the transaction is RUNNING. 2. Silent state-transition rejection (lines 873–882): `pk_transaction_set_state()` silently discards backward state transitions (e.g. `RUNNING` → `WAITING_FOR_AUTH`) but the flag overwrite at step 1 already happened. The transaction continues running with corrupted flags. 3. Late flag read at execution time (lines 2273–2277): The scheduler's idle callback reads cached_transaction_flags at dispatch time, not at authorization time. If flags were overwritten between authorization and execution, the backend sees the attacker's flags.

    Published: 22 Apr 2026
    8.5
    High

    CVE-2026-0539

    Last Modified: 27 Apr 2026

    Incorrect Default Permissions in pcvisit service binary on Windows allows a low-privileged local attacker to escalate their privileges by overwriting the service binary with arbitrary contents. This service binary is automatically launched with NT\SYSTEM privileges on boot. This issue affects all versions after 22.6.22.1329 and was fixed in 25.12.3.1745.

    Published: 22 Apr 2026
    5.9
    Medium

    CVE-2026-33262

    Last Modified: 27 Apr 2026

    An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Cookies are disabled by default.

    Published: 22 Apr 2026
    5.9
    Medium

    CVE-2026-33261

    Last Modified: 28 Apr 2026

    A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.

    Published: 22 Apr 2026
    5.3
    Medium

    CVE-2026-33260

    Last Modified: 28 Apr 2026

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

    Published: 22 Apr 2026
    5
    Medium

    CVE-2026-33259

    Last Modified: 27 Apr 2026

    Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurrent transfers of the same RPZ zone can only occur with a malfunctioning RPZ provider.

    Published: 22 Apr 2026
    5.3
    Medium

    CVE-2026-33258

    Last Modified: 28 Apr 2026

    By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.

    Published: 22 Apr 2026
    5.3
    Medium

    CVE-2026-33257

    Last Modified: 27 Apr 2026

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

    Published: 22 Apr 2026
    5.3
    Medium

    CVE-2026-33256

    Last Modified: 27 Apr 2026

    An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

    Published: 22 Apr 2026
    4.4
    Medium

    CVE-2026-33601

    Last Modified: 27 Apr 2026

    If you use the zoneToCache function with a malicious authoritative server, an attacker can send a zone that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

    Published: 22 Apr 2026
    4.4
    Medium

    CVE-2026-33600

    Last Modified: 27 Apr 2026

    An RPZ sent by a malicious authoritative server can result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service.

    Published: 22 Apr 2026
    6.4
    Medium

    CVE-2026-1913

    Last Modified: 23 Apr 2026

    The Gallagher Website Design plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's login_link shortcode in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping on the 'prefix' attribute. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 22 Apr 2026