Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2019-25477 — RAR Password Recovery 1.80 Denial of Service Buffer Overflow

RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can cr…

| Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
6.9 MEDIUM
CVE-2019-25476 — Outlook Password Recovery 2.10 Denial of Service Buffer Overflow

Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text f…

| Denial of Service
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
6.9 MEDIUM
CVE-2019-25475 — SQL Server Password Changer 1.90 Denial of Service Buffer Overflow

SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of da…

| Denial of Service
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
6.9 MEDIUM
CVE-2019-25474 — Easy MP3 Downloader 4.7.8.8 Denial of Service Buffer Overflow

Easy MP3 Downloader 4.7.8.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long unlock code. Attackers can generate a file c…

| Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.7 HIGH
CVE-2019-25472 — IntelBras Telefone IP TIP200/200 LITE Arbitrary File Read via dumpConfigFile

IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET…

Remote | Information Disclosure
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
9.8 CRITICAL
CVE-2019-25471 — FileThingie 2.5.7 Arbitrary File Upload via ft2.php

FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files …

Remote | Path Traversal
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.7 HIGH
CVE-2019-25470 — eWON Firmware 12.2-13.0 Authentication Bypass via wsdReadForm

eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitive user data by exploiting the wsdReadForm endpoint…

Remote | Authentication
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
6.9 MEDIUM
CVE-2019-25469 — Folder Lock 7.7.9 Denial of Service via Serial Number Field

Folder Lock 7.7.9 contains a buffer overflow vulnerability in the serial number registration field that allows local attackers to crash the application by submitting an oversized payload. Attackers c…

| Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
9.8 CRITICAL
CVE-2019-25468 — NetGain EM Plus 10.1.68 Remote Code Execution via script_test.jsp

NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test…

Remote | Injection
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.6 HIGH
CVE-2019-25467 — Verypdf docPrint Pro 8.0 Local SEH Buffer Overflow

Verypdf docPrint Pro 8.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized alphanumeric encoded pa…

| Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.6 HIGH
CVE-2019-25466 — Easy File Sharing Web Server 7.2 Local SEH Overflow

Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. A…

| Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.7 HIGH
CVE-2019-25465 — Hisilicon HiIpcam V100R003 Information Disclosure via Directory Traversal

Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin di…

Remote | Path Traversal
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
6.7 MEDIUM
CVE-2019-25464 — InputMapper 1.6.10 Local Denial of Service via Username Field

InputMapper 1.6.10 contains a buffer overflow vulnerability in the username field that allows local attackers to crash the application by entering an excessively long string. Attackers can trigger a …

| Memory Corruption
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
6.9 MEDIUM
CVE-2019-25463 — SpotIE Internet Explorer Password Recovery 2.9.5 Key Field DoS

SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an ex…

| Denial of Service
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
9.8 CRITICAL
CVE-2018-25159 — Epross AVCON6 OGNL Remote Code Execution via login.action

Epross AVCON6 systems management platform contains an object-graph navigation language (OGNL) injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by injecting …

Remote | Injection
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.7 HIGH
CVE-2026-31975 — Cloud CLI WebSocket shell injection

Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1.25.0, OS Command Injection via WebSocket Shell. Both projectPath and initialCo…

Remote | Injection
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.2 HIGH
CVE-2026-31875 — Parse Server MFA recovery codes not consumed after use

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled f…

Remote | Authentication
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
8.7 HIGH
CVE-2026-31872 — Parse Server has a protected fields bypass via dot-notation in query and sort

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypa…

Remote | Authorization
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
9.3 CRITICAL
CVE-2026-31871 — Parse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation o…

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL stora…

Remote | Injection
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
7.5 HIGH
CVE-2026-31870 — cpp-httplib Affected by Remote Process Crash via Malformed Content-Length Response Header

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib client uses the streaming API (httplib::stream::Get, httplib::stream::Post, etc.)…

Remote | Denial of Service
Mar 11, 2026 Mar 12, 2026
Mar 11, 2026
Mar 12, 2026
Showing 20 of 5431 Results