3w ago
2026-05-25 19:16Z
HIGH

CVE-2026-9482 — Such manipulation of the argument submit-url leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9482

A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-25 19:16Z
HIGH

CVE-2026-9481 — This manipulation of the argument submit-url causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9481

A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-25 19:16Z
HIGH

CVE-2026-9480 — Edimax: The manipulation of the argument submit-url results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9480

A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDEdimaxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-25 18:16Z
HIGH

CVE-2026-9479 — The manipulation of the argument submit-url leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9479

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
3w ago
2026-05-25 18:16Z
CRIT

CVE-2026-9478 — Executing a manipulation of the argument enable can lead to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9478

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
3w ago
2026-05-25 18:16Z
CRIT

CVE-2026-9477 — Performing a manipulation of the argument mac results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9477

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4w ago
2026-05-25 17:16Z
CRIT

CVE-2026-9476 — Totolink: Such manipulation of the argument admpass leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9476

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
4w ago
2026-05-25 17:16Z
CRIT

CVE-2026-9475 — Totolink: This manipulation of the argument Comment causes os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9475

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78VNDTotolinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2026-9463 — This manipulation of the argument submit-url causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9463

A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2026-9462 — Edimax: The manipulation of the argument submit-url results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9462

A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnable. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119VNDEdimaxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25379 — Collectric: CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25379

Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDCollectricTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25377 — Flash: Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25377

Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog to trigger a reverse shell with system privileges. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDFlashTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25376 — Socusoft: 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25376

Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft malicious input in the Registration Name and Registration Key fields to overwrite the SEH chain and execute shellcode for reverse shell access. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDSocusoftTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25375 — SocuSoft: iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25375

SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft malicious input in the Registration Name and Registration Key fields to trigger a stack-based buffer overflow and execute a reverse shell payload. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDSocusoftTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25373 — SocuSoft: DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25373

SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious text file with carefully constructed payload containing junk bytes, SEH chain overwrite, and shellcode, then paste the contents into the Registration Name field via Help > Register to trigger code execution. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDSocusoftTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25372 — MedDream: PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25372

MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Attackers can submit crafted POST requests to the userSignup.php endpoint with SQL payloads in the email field to extract sensitive database information from the backend MySQL database. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDMeddreamTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25371 — Store: mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25371

mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDStoreTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25366 — CuteFTP: 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25366

CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and launched. CVSSv3.1 8.4 (HIGH)

CWECWE 120VNDCuteftpTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25364 — Twitter: Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25364

Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the name parameter. Attackers can submit crafted payloads to the search.php endpoint to extract database information including usernames, credentials, and system data using error-based and union-based SQL injection techniques. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDTwitterTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25362 — Twitter: Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25362

Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames, passwords, and database credentials. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDTwitterTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25360 — AgataSoft: Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25360

AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and jump instructions that overwrite the SEH handler pointer to achieve code execution when the file contents are pasted into the application. CVSSv3.1 8.4 (HIGH)

CWECWE 121VNDAgatasoftTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
4w ago
2026-05-25 15:16Z
HIGH

CVE-2018-25359 — Splinterware: System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25359

Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered. CVSSv3.1 8.4 (HIGH)

CWECWE 276VNDSplinterwareTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
4w ago
2026-05-25 14:16Z
HIGH

CVE-2026-9461 — The manipulation of the argument submit-url leads to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9461

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-05-25 14:16Z
HIGH

CVE-2026-9460 — Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9460

A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
4w ago
2026-05-25 14:16Z
HIGH

CVE-2026-9459 — Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9459

A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 8.8 (HIGH)

CWECWE 121CWECWE 119TYPVulnerability
8.8
CVSS v3.1
94
Edit Score