|
2371
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability in B1 Free Archiver v1.5.86 allows files extracted from downloaded archives to bypass Windows Mark of the Web (MotW) protections. When an archive is downloaded from the internet and e…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-50328
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2372
|
4.0 |
MEDIUM
Local
|
-
|
-
|
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-42798
|
2026-05-1 00:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2373
|
4.4 |
MEDIUM
Local
|
-
|
-
|
AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boun…
|
CWE-346
Origin Validation Error
|
CVE-2026-7439
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2374
|
8.8 |
HIGH
Network
|
-
|
-
|
AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs …
|
CWE-94
Code Injection
|
CVE-2026-7466
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2375
|
8.2 |
HIGH
Network
|
-
|
-
|
XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers c…
|
CWE-89
SQL Injection
|
CVE-2018-25300
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2376
|
8.4 |
HIGH
Local
|
-
|
-
|
Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious userna…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25301
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2377
|
8.4 |
HIGH
Local
|
-
|
-
|
Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploita…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25304
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2378
|
8.4 |
HIGH
Local
|
-
|
-
|
SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25307
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2379
|
8.8 |
HIGH
Network
|
-
|
-
|
BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attack…
|
CWE-22
Path Traversal
|
CVE-2018-25308
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2380
|
6.2 |
MEDIUM
Local
|
-
|
-
|
SysGauge 4.5.18 contains a buffer overflow vulnerability in the proxy configuration handler that allows local attackers to cause a denial of service by supplying an oversized string. Attackers can in…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25313
|
2026-05-1 00:44 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|