Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2018-25312 — LifeSize ClearSea 3.1.4 Directory Traversal Remote Code Execution

LifeSize ClearSea 3.1.4 contains directory traversal vulnerabilities that allow authenticated attackers to download and upload arbitrary files by manipulating path parameters in the smartgui interfac…

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.1 HIGH
CVE-2018-25311 — VideoFlow Digital Video Protection DVP 10 Authenticated Directory Traversal 2.10 (X-Proto…

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated directory traversal vulnerability that allows authenticated attackers to disclose arbitrary files by injecting path traversal seq…

Remote | Path Traversal
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
5.3 MEDIUM
CVE-2018-25310 — VideoFlow Digital Video Protection DVP 10 Authenticated Remote Code Execution

VideoFlow Digital Video Protection DVP 2.10 contains an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary system commands by exploiting a cros…

Remote | Cross-Site Request Forgery
Apr 29, 2026 Apr 30, 2026
Apr 29, 2026
Apr 30, 2026
7.2 HIGH
CVE-2018-25309 — MyBB Recent threads 17.0 Persistent Cross-Site Scripting

MyBB Recent threads 17.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts by creating threads with crafted subject lines. Attackers can creat…

mybb | Remote | Cross-Site Scripting
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.8 HIGH
CVE-2018-25308 — BuddyPress Xprofile Custom Fields Type 2.6.3 Remote Code Execution

BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remote code execution vulnerability that allows authenticated users to delete arbitrary files by manipulating unescaped POST parameters. Attack…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.6 HIGH
CVE-2018-25307 — SysGauge Pro 4.6.12 Local Buffer Overflow SEH

SysGauge Pro 4.6.12 contains a local buffer overflow vulnerability in the Register function that allows local attackers to overwrite the structured exception handler by supplying a crafted unlock key…

| Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
6.9 MEDIUM
CVE-2018-25306 — PDFunite 0.41.0 Buffer Overflow via Malformed PDF

PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmen…

| Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
6.9 MEDIUM
CVE-2018-25305 — librsvg2-bin 2.40.13 Buffer Overflow via Malformed SVG

librsvg2-bin 2.40.13 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service by processing malformed SVG files. Attackers can supply crafted SVG input to the…

| Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.6 HIGH
CVE-2018-25304 — Free Download Manager 2.0 Built 417 Local Buffer Overflow SEH

Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploita…

free_download_manager | Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.6 HIGH
CVE-2018-25303 — Allok Video to DVD Burner 2.6.1217 Buffer Overflow SEH

Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exce…

| Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.5 HIGH
CVE-2018-25302 — Allok AVI to DVD SVCD VCD Converter 4.0.1217 Buffer Overflow SEH

Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a ma…

wmv_to_avi_mpeg_dvd_wmv_convertor | Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.6 HIGH
CVE-2018-25301 — Easy MPEG to DVD Burner 1.7.11 SEH Local Buffer Overflow

Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious userna…

easy_mpeg_to_dvd_burner | Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.8 HIGH
CVE-2018-25300 — XATABoost CMS 1.0.0 SQL Injection via news.php

XATABoost CMS 1.0.0 contains a union-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the id parameter. Attackers c…

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.6 HIGH
CVE-2018-25299 — Prime95 29.4b8 Local Buffer Overflow via SEH

Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malici…

prime95 | Memory Corruption
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
6.9 MEDIUM
CVE-2018-25298 — Merge PACS 7.0 Cross-Site Request Forgery via merge-viewer

Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attacker…

Remote | Cross-Site Request Forgery
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.8 HIGH
CVE-2026-7466 — AgentFlow Arbitrary Python Pipeline Execution via pipeline_path

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs …

Remote | Injection
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
4.8 MEDIUM
CVE-2026-7439 — AgentFlow Local Web API Content-Type Validation Bypass

AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boun…

| Misconfiguration
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
8.1 HIGH
CVE-2026-7424 — Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, an…

freertos-plus-tcp | Denial of Service
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
6.0 MEDIUM
CVE-2026-7423 — Integer Underflow in ICMP Echo Reply Processing in FreeRTOS-Plus-TCP

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing pi…

freertos-plus-tcp | Denial of Service
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
7.1 HIGH
CVE-2026-7422 — MAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet Processing

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC ad…

freertos-plus-tcp | Misconfiguration
Apr 29, 2026 Apr 29, 2026
Apr 29, 2026
Apr 29, 2026
Showing 20 of 5910 Results