CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-25692

    Last Modified: 8 Apr 2026

    Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the 'id_to_modify' parameter. Attackers can send crafted requests with malicious SQL statements in the id_to_modify field to extract sensitive database information or modify data.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25690

    Last Modified: 8 Apr 2026

    Kados R10 GreenBee contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the mng_profile_id parameter. Attackers can send crafted requests with malicious SQL payloads in the mng_profile_id parameter to extract sensitive database information.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25688

    Last Modified: 8 Apr 2026

    Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the menu_lev1 parameter. Attackers can send crafted requests with malicious SQL payloads in the menu_lev1 parameter to extract sensitive database information or modify database contents.

    Published: 5 Apr 2026
    9.3
    Critical

    CVE-2019-25687

    Last Modified: 24 Apr 2026

    Pegasus CMS 1.0 contains a remote code execution vulnerability in the extra_fields.php plugin that allows unauthenticated attackers to execute arbitrary commands by exploiting unsafe eval functionality. Attackers can send POST requests to the submit.php endpoint with malicious PHP code in the action parameter to achieve code execution and obtain an interactive shell.

    Published: 5 Apr 2026
    8.7
    High

    CVE-2019-25686

    Last Modified: 9 Apr 2026

    Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP server process.

    Published: 5 Apr 2026
    Unknown

    CVE-2019-25685

    Last Modified: 19 Apr 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25684

    Last Modified: 10 Apr 2026

    OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information.

    Published: 5 Apr 2026
    6.9
    Medium

    CVE-2019-25683

    Last Modified: 10 Apr 2026

    FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.

    Published: 5 Apr 2026
    5.3
    Medium

    CVE-2019-25682

    Last Modified: 10 Apr 2026

    CMSsite 1.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious HTML forms. Attackers can trick authenticated administrators into visiting crafted pages that submit POST requests to the users.php endpoint with parameters like source=add_user, source=edit_user, or del=1 to create, modify, or delete admin accounts.

    Published: 5 Apr 2026
    8.6
    High

    CVE-2019-25681

    Last Modified: 10 Apr 2026

    Xlight FTP Server 3.9.1 contains a structured exception handler (SEH) overwrite vulnerability that allows local attackers to crash the application and overwrite SEH pointers by supplying a crafted buffer string. Attackers can inject a 428-byte payload through the program execution field in virtual server configuration to trigger a buffer overflow that corrupts the SEH chain and enables potential code execution.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25680

    Last Modified: 24 Apr 2026

    Advance Gift Shop Pro Script 2.0.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can submit crafted SQL payloads in the 's' parameter of search requests to extract sensitive database information including version details and other data.

    Published: 5 Apr 2026
    8.5
    High

    CVE-2019-25679

    Last Modified: 20 Apr 2026

    RealTerm Serial Terminal 2.0.0.70 contains a structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a buffer overflow payload with a POP POP RET gadget chain and shellcode that triggers code execution when pasted into the Port field and the Change button is clicked.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25678

    Last Modified: 21 Apr 2026

    C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the site parameter. Attackers can send GET requests to the users_select.php endpoint with crafted SQL payloads to extract sensitive database information including patient records and system credentials.

    Published: 5 Apr 2026
    6.9
    Medium

    CVE-2019-25677

    Last Modified: 15 Jul 2026

    WinRAR 5.61 contains a denial of service vulnerability that allows local attackers to crash the application by placing a malformed winrar.lng language file in the installation directory. Attackers can trigger the crash by opening an archive and pressing the test button, causing an access violation at memory address 004F1DB8 when the application attempts to read invalid data.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25676

    Last Modified: 21 Apr 2026

    Ask Expert Script 3.0.5 contains cross-site scripting and SQL injection vulnerabilities that allow unauthenticated attackers to inject malicious code by manipulating URL parameters. Attackers can inject script tags through the cateid parameter in categorysearch.php or SQL code through the view parameter in list-details.php to execute arbitrary code or extract database information.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25674

    Last Modified: 10 Apr 2026

    CMSsite 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send GET requests to post.php with malicious 'post' values to extract sensitive database information or perform time-based blind SQL injection attacks.

    Published: 5 Apr 2026
    8.7
    High

    CVE-2019-25673

    Last Modified: 28 Jul 2026

    UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25672

    Last Modified: 9 Apr 2026

    PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information.

    Published: 5 Apr 2026
    8.7
    High

    CVE-2019-25671

    Last Modified: 16 Apr 2026

    VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter. Attackers can send POST requests to the changeip.php endpoint with malicious payload in the mtu_eth0 field to execute commands as the apache user.

    Published: 5 Apr 2026
    8.6
    High

    CVE-2019-25670

    Last Modified: 27 Apr 2026

    River Past Video Cleaner 7.6.3 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll field. Attackers can craft a payload with 280 bytes of padding, a next structured exception handler override, and shellcode to trigger code execution when the application processes the input.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25669

    Last Modified: 10 Apr 2026

    qdPM 9.1 contains an SQL injection vulnerability that allows attackers to manipulate database queries by injecting SQL code through the search_by_extrafields[] parameter. Attackers can send POST requests to the users endpoint with malicious search_by_extrafields[] values to trigger SQL syntax errors and extract database information.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25668

    Last Modified: 20 Apr 2026

    News Website Script 2.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the news ID parameter. Attackers can send GET requests to index.php/show/news/ with malicious SQL statements to extract sensitive database information.

    Published: 5 Apr 2026
    6.9
    Medium

    CVE-2019-25667

    Last Modified: 20 Apr 2026

    TaskInfo 8.2.0.280 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to registration fields. Attackers can paste excessively long strings into the New User Name or New Serial Number textboxes in the Help menu's registration dialog to trigger a denial of service condition.

    Published: 5 Apr 2026
    6.9
    Medium

    CVE-2019-25666

    Last Modified: 20 Apr 2026

    SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.

    Published: 5 Apr 2026
    6.9
    Medium

    CVE-2019-25665

    Last Modified: 27 Apr 2026

    River Past Ringtone Converter 2.7.6.1601 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying oversized input to activation fields. Attackers can paste 300 bytes of data into the Email textbox and Activation code textarea via the Help menu's Activate dialog to trigger a denial of service condition.

    Published: 5 Apr 2026
    7.1
    High

    CVE-2019-25664

    Last Modified: 20 Apr 2026

    SuiteCRM 7.10.7 contains a time-based SQL injection vulnerability in the record parameter of the Users module DetailView action that allows authenticated attackers to manipulate database queries. Attackers can append SQL code to the record parameter in GET requests to the index.php endpoint to extract sensitive database information through time-based blind SQL injection techniques.

    Published: 5 Apr 2026
    7.1
    High

    CVE-2019-25663

    Last Modified: 20 Apr 2026

    SuiteCRM 7.10.7 contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the parentTab parameter. Attackers can send GET requests to the email module with malicious parentTab values using boolean-based SQL injection techniques to extract sensitive database information.

    Published: 5 Apr 2026
    8.8
    High

    CVE-2019-25662

    Last Modified: 15 Apr 2026

    ResourceSpace 8.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'ref' parameter. Attackers can send GET requests to the watched_searches.php endpoint with crafted SQL payloads to extract sensitive database information including usernames and credentials.

    Published: 5 Apr 2026
    6.9
    Medium

    CVE-2019-25661

    Last Modified: 16 Apr 2026

    Remote Process Explorer 1.0.0.16 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by sending a crafted payload to the Add Computer dialog. Attackers can paste a malicious string into the computer name textbox and trigger a crash by connecting to the added computer, overwriting the SEH chain and corrupting exception handlers.

    Published: 5 Apr 2026
    6.9
    Medium

    CVE-2019-25660

    Last Modified: 20 Apr 2026

    LanHelper 1.74 contains a local buffer overflow vulnerability that allows attackers to crash the application by sending excessively long input strings. Attackers can exploit the Form Send Message feature by pasting 6000 bytes of data into the Message text field to trigger a denial of service condition.

    Published: 5 Apr 2026
    6.9
    Medium

    CVE-2019-25659

    Last Modified: 16 Apr 2026

    ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash.

    Published: 5 Apr 2026
    6.8
    Medium

    CVE-2019-25658

    Last Modified: 16 Apr 2026

    a-Mac Address Change 5.4 contains a local buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input to registration form fields. Attackers can paste 212 bytes of data into the 'Your Name', 'Your Company', or 'Register Code' fields and click the Register button to trigger a denial of service crash.

    Published: 5 Apr 2026
    6.8
    Medium

    CVE-2019-25657

    Last Modified: 20 Apr 2026

    AnyBurn 4.3 x86 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the image conversion function. Attackers can paste a large buffer into the source or destination image file fields and click Convert Now to trigger a crash.

    Published: 5 Apr 2026
    8.6
    High

    CVE-2019-25656

    Last Modified: 16 Apr 2026

    R i386 3.5.0 contains a local buffer overflow vulnerability in the GUI Preferences dialog that allows local attackers to trigger a structured exception handler (SEH) overwrite by supplying malicious input. Attackers can craft a payload string in the 'Language for menus and messages' field to overwrite SEH records and achieve code execution with calculator or arbitrary shellcode.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5596

    Last Modified: 7 Apr 2026

    A vulnerability was detected in griptape-ai griptape 0.19.4. Affected by this issue is some unknown functionality of the file griptape/tools/sql/tool.py of the component SqlTool. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2026
    6.8
    Medium

    CVE-2018-25256

    Last Modified: 27 Apr 2026

    IP TOOLS 2.50 contains a local buffer overflow vulnerability in the SNMP Scanner component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data into the 'From Addr' and 'To Addr' fields and trigger the crash by clicking the Start button, causing denial of service and SEH overwrite.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5595

    Last Modified: 7 Apr 2026

    A security vulnerability has been detected in griptape-ai griptape 0.19.4. Affected by this vulnerability is the function load_files_from_disk/list_files_from_disk/save_content_to_file/save_memory_artifacts_to_disk of the component FileManagerTool. Such manipulation leads to path traversal. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5594

    Last Modified: 7 Apr 2026

    A weakness has been identified in premAI-io premsql up to 0.2.1. Affected is the function eval of the file premsql/agents/baseline/workers/followup.py. This manipulation of the argument result causes code injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5587

    Last Modified: 7 Apr 2026

    A vulnerability was identified in wbbeyourself MAC-SQL up to 31a9df5e0d520be4769be57a4b9022e5e34a14f4. This affects the function _execute_sql of the file core/agents.py of the component Refiner Agent. The manipulation leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5586

    Last Modified: 20 May 2026

    A vulnerability was determined in zhongyu09 openchatbi up to 0.2.1. The impacted element is an unknown function of the component Multi-stage Text2SQL Workflow. Executing a manipulation of the argument keywords can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 5 Apr 2026
    5.5
    Medium

    CVE-2026-5585

    Last Modified: 30 Apr 2026

    A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of the component Task Detail Endpoint. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2026
    5.5
    Medium

    CVE-2026-5584

    Last Modified: 30 Apr 2026

    A vulnerability has been found in Fosowl agenticSeek 0.1.0. Impacted is the function PyInterpreter.execute of the file sources/tools/PyInterpreter.py of the component query Endpoint. Such manipulation leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5583

    Last Modified: 7 Apr 2026

    A security vulnerability has been detected in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /my-profile.php of the component Parameter Handler. The manipulation of the argument fullname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5580

    Last Modified: 7 Apr 2026

    A vulnerability was identified in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/addvideos.php of the component Parameter Handler. The manipulation of the argument videotitle leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5579

    Last Modified: 7 Apr 2026

    A vulnerability was determined in CodeAstro Online Classroom 1.0. This issue affects some unknown processing of the file /OnlineClassroom/updatedetailsfromfaculty.php?myfid=108 of the component Parameter Handler. Executing a manipulation of the argument fname can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

    Published: 5 Apr 2026
    2.1
    Low

    CVE-2026-5578

    Last Modified: 7 Apr 2026

    A vulnerability was found in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /OnlineClassroom/addassessment.php of the component Parameter Handler. Performing a manipulation of the argument deleteid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

    Published: 5 Apr 2026
    5.5
    Medium

    CVE-2026-5577

    Last Modified: 30 Apr 2026

    A vulnerability has been found in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a. This affects an unknown part of the file flask/uniquemachine_app.py of the component details Endpoint. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2026
    2
    Low

    CVE-2026-5576

    Last Modified: 24 Apr 2026

    A flaw has been found in SourceCodester/jkev Record Management System 1.0. Affected by this issue is some unknown functionality of the file save_emp.php of the component Add Employee Page. This manipulation causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used.

    Published: 5 Apr 2026
    5.5
    Medium

    CVE-2026-5575

    Last Modified: 24 Apr 2026

    A vulnerability was detected in SourceCodester/jkev Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file index.php of the component Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

    Published: 5 Apr 2026
    5.5
    Medium

    CVE-2026-5574

    Last Modified: 1 May 2026

    A security vulnerability has been detected in Technostrobe HI-LED-WR120-G2 5.5.0.1R6.03.30. Affected is the function deletefile of the component FsBrowseClean. The manipulation of the argument dir/path leads to missing authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 5 Apr 2026