|
1851
|
7.5 |
HIGH
Network
|
-
|
-
|
An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-30997
|
2026-04-18 00:34 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1852
|
7.5 |
HIGH
Network
|
-
|
-
|
An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-30998
|
2026-04-18 00:34 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1853
|
- |
|
-
|
-
|
ChurchCRM is an open-source church management system. Prior to 7.0.0, it was possible in many places across the ChurchCRM application to create a link that, when visited by an authenticated user, wou…
|
CWE-601
Open Redirect
|
CVE-2026-39940
|
2026-04-18 00:33 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1854
|
8.8 |
HIGH
Network
|
-
|
-
|
In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile picture upload functionality on the /my-profile.php page.
|
CWE-94
Code Injection
|
CVE-2025-51414
|
2026-04-18 00:33 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1855
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handling of user-controlled input in the _folder parameter allows a specially crafte…
|
CWE-79
Cross-site Scripting
|
CVE-2025-70936
|
2026-04-18 00:33 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1856
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (ge…
|
CWE-80
Basic XSS
|
CVE-2026-26460
|
2026-04-18 00:33 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1857
|
- |
|
-
|
-
|
An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause a Denial of Service (DoS) via supplying crafted RFCOMM frames.
|
-
|
CVE-2026-31280
|
2026-04-18 00:33 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1858
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, allows SQL injection via the sitem_name POST parameter.
|
CWE-89
SQL Injection
|
CVE-2025-63939
|
2026-04-18 00:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1859
|
6.1 |
MEDIUM
Network
|
-
|
-
|
alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which allows an attacker to inject and execute arbitrary JavaScript via the room_id GE…
|
CWE-79
Cross-site Scripting
|
CVE-2025-65132
|
2026-04-18 00:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1860
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated or authenticated remote attacker can supply a crafted HTTP request to the affec…
|
CWE-89
SQL Injection
|
CVE-2025-65133
|
2026-04-18 00:33 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|