|
141
|
8.4 |
HIGH
Local
|
-
|
-
|
Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploita…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25304
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
142
|
8.4 |
HIGH
Local
|
-
|
-
|
SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25307
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
143
|
8.8 |
HIGH
Network
|
-
|
-
|
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attack…
New
|
CWE-22
Path Traversal
|
CVE-2018-25308
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
144
|
6.2 |
MEDIUM
Local
|
-
|
-
|
SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can in…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25313
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
145
|
7.8 |
HIGH
Local
|
-
|
-
|
An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers.
The bug may be exploitable by…
New
|
CWE-783
Operator Precedence Logic Error
|
CVE-2026-7270
|
2026-05-1 00:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
146
|
7.5 |
HIGH
Network
|
-
|
-
|
Starman versions before 0.4018 for Perl allows HTTP Request Smuggling via Improper Header Precedence.
Starman incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both hea…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-40560
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
147
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Dell Disk Library for Mainframe, version(s) DLm 8700/2700 contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vu…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-23773
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
148
|
- |
|
-
|
-
|
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
New
|
-
|
CVE-2026-21023
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
149
|
7.1 |
HIGH
Network
|
-
|
-
|
Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privilege…
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-35155
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
150
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
New
|
CWE-601
Open Redirect
|
CVE-2026-42525
|
2026-05-1 00:13 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|