Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.4 MEDIUM
CVE-2018-25249 — MyBB My Arcade Plugin 1.3 Persistent XSS via Comment

MyBB My Arcade Plugin 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through arcade game score comments. Attackers can add cr…

mybb | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.2 HIGH
CVE-2018-25248 — MyBB Downloads Plugin 2.0.3 Persistent XSS via downloads.php

MyBB Downloads Plugin 2.0.3 contains a persistent cross-site scripting vulnerability that allows regular members to inject malicious scripts through the download title field. Attackers can submit a n…

mybb | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.1 MEDIUM
CVE-2018-25247 — MyBB Like Plugin 3.0.0 Cross-Site Scripting via User Profiles

MyBB Like Plugin 3.0.0 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating posts or threads with unvalidated subject content. Attackers can cra…

mybb | Remote | Cross-Site Scripting
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.7 HIGH
CVE-2018-25245 — 7 Tik 1.0.1.0 Denial of Service via Search

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a…

Remote | Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25244 — Eco Search 1.0.2.0 Denial of Service

Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can …

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25243 — FastTube 1.0.1.0 Denial of Service via Search

FastTube 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can pa…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25242 — One Search 1.1.0.0 Denial of Service

One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers …

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
8.7 HIGH
CVE-2018-25241 — VPN Browser+ 1.1.0.0 Denial of Service

VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attacker…

Remote | Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25240 — Watchr 1.1.0.0 Denial of Service via Search

Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can past…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25239 — Smart VPN 1.1.3.0 Denial of Service via Search

Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buf…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
6.9 MEDIUM
CVE-2018-25238 — VSCO 1.1.1.0 Denial of Service via Search

VSCO 1.1.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string through the search functionality. Attackers can p…

| Denial of Service
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.8 HIGH
CVE-2016-20061 — sheed AntiVirus 2.3 Unquoted Service Path Privilege Escalation

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can ins…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.8 HIGH
CVE-2016-20060 — Hotspot Shield 6.0.3 Unquoted Service Path Privilege Escalation

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can p…

hotspot_shield | Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.8 HIGH
CVE-2016-20059 — IObit Malware Fighter 4.3.1 Unquoted Service Path Privilege Escalation

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a mal…

malware_fighter | Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.8 HIGH
CVE-2016-20058 — Netgate AMITI Antivirus build 23.0.305 Unquoted Service Path Privilege Escalation

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attacker…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.8 HIGH
CVE-2016-20057 — NETGATE Registry Cleaner build 16.0.205 Unquoted Service Path Privilege Escalation

NETGATE Registry Cleaner build 16.0.205 contains an unquoted service path vulnerability in the NGRegClnSrv service that allows local attackers to escalate privileges by exploiting the service binary …

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.8 HIGH
CVE-2016-20056 — Spy Emergency build 23.0.205 Unquoted Service Path Privilege Escalation

Spy Emergency build 23.0.205 contains an unquoted service path vulnerability in the SpyEmrgHealth and SpyEmrgSrv services that allows local attackers to escalate privileges by inserting malicious exe…

| Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
7.8 HIGH
CVE-2016-20055 — IObit Advanced SystemCare 10.0.2 Unquoted Service Path Privilege Escalation

IObit Advanced SystemCare 10.0.2 contains an unquoted service path vulnerability in the AdvancedSystemCareService10 service that allows local attackers to escalate privileges. Attackers can place a m…

Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
5.3 MEDIUM
CVE-2016-20053 — Redaxo CMS 5.2 Cross-Site Request Forgery via users endpoint

Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tricking authenticated administrators into visiting …

redaxo_cms | Remote | Cross-Site Request Forgery
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
9.8 CRITICAL
CVE-2016-20052 — Snews CMS 1.7 Unrestricted File Upload via snews_files

Snews CMS 1.7 contains an unrestricted file upload vulnerability that allows unauthenticated attackers to upload arbitrary files including PHP executables to the snews_files directory. Attackers can …

snews | Remote | Misconfiguration
Apr 04, 2026 Apr 04, 2026
Apr 04, 2026
Apr 04, 2026
Showing 20 of 5883 Results