|
1311
|
7.5 |
HIGH
Network
|
-
|
-
|
Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers …
New
|
CWE-22
Path Traversal
|
CVE-2018-25374
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1312
|
8.4 |
HIGH
Local
|
-
|
-
|
SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception ha…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2018-25375
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1313
|
8.4 |
HIGH
Local
|
-
|
-
|
Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25376
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1314
|
8.4 |
HIGH
Local
|
-
|
-
|
Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception ha…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25377
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1315
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can crea…
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2018-25378
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1316
|
8.2 |
HIGH
Network
|
-
|
-
|
Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attacke…
New
|
CWE-89
SQL Injection
|
CVE-2018-25379
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1317
|
7.1 |
HIGH
Network
|
-
|
-
|
Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_s…
New
|
CWE-89
SQL Injection
|
CVE-2018-25380
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1318
|
7.1 |
HIGH
Network
|
-
|
-
|
Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can injec…
New
|
CWE-89
SQL Injection
|
CVE-2018-25381
|
2026-05-27 04:47 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1319
|
8.6 |
HIGH
Network
|
powerdns
|
authoritative
|
Insufficient Validation of Names During AXFR
Update
|
CWE-77
Command Injection
|
CVE-2026-42000
|
2026-05-27 04:38 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1320
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Smartshop 1 contains a cross-site request forgery vulnerability that allows attackers to modify user profiles by tricking authenticated users into submitting malicious requests. Attackers can craft H…
New
|
CWE-352
Origin Validation Error
|
CVE-2018-25343
|
2026-05-27 04:37 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|