Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2018-25255 — 10-Strike LANState 8.8 Local Buffer Overflow SEH

10-Strike LANState 8.8 contains a local buffer overflow vulnerability in structured exception handling that allows local attackers to execute arbitrary code by crafting malicious LSM map files. Attac…

| Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
9.8 CRITICAL
CVE-2018-25254 — NICO-FTP 3.0.1.19 Buffer Overflow SEH

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect t…

Remote | Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25253 — Termite 3.4 Denial of Service via Settings Buffer Overflow

Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. At…

| Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25252 — FTP Voyager 16.2.0 Denial of Service via Malformed Site Profile

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can cre…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.6 HIGH
CVE-2018-25251 — Snes9K 0.0.9z Buffer Overflow SEH via Netplay Socket

Snes9K 0.0.9z contains a buffer overflow vulnerability in the Netplay Socket Port Number field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can cra…

| Memory Corruption
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.2 HIGH
CVE-2018-25250 — MyBB Last User's Threads in Profile Plugin 1.2 Persistent XSS

MyBB Last User's Threads in Profile Plugin 1.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by crafting thread subjects with script tags.…

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.4 MEDIUM
CVE-2018-25249 — MyBB My Arcade Plugin 1.3 Persistent XSS via Comment

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add cr…

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.2 HIGH
CVE-2018-25248 — MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a n…

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.1 MEDIUM
CVE-2018-25247 — MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles

MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can cra…

Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.7 HIGH
CVE-2018-25245 — Microsoft 7 Tik 1.0.1.0 Denial of Service via Search

Microsoft 7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers c…

Remote | Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25244 — Microsoft Eco Search 1.0.2.0 Denial of Service

Microsoft Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Atta…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25243 — Microsoft FastTube 1.0.1.0 Denial of Service via Search

Microsoft FastTube 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attack…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25242 — Microsoft One Search 1.1.0.0 Denial of Service

Microsoft One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. …

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.7 HIGH
CVE-2018-25241 — Microsoft VPN Browser+ 1.1.0.0 Denial of Service

Microsoft VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality…

Remote | Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25240 — Microsoft Watchr 1.1.0.0 Denial of Service via Search

Microsoft Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attacker…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25239 — Microsoft Smart VPN 1.1.3.0 Denial of Service via Search

Microsoft Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can p…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25238 — Microsoft VSCO 1.1.1.0 Denial of Service via Search

Microsoft VSCO 1.1.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string through the search functionality. Attac…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.5 HIGH
CVE-2016-20061 — sheed AntiVirus 2.3 Unquoted Service Path Privilege Escalation

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can ins…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.5 HIGH
CVE-2016-20060 — Hotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can p…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.5 HIGH
CVE-2016-20059 — IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a mal…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
Showing 20 of 6111 Results