VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
18,947 CVE recordsPage 862 of 1264 · EPSS data 2026.08.10
ReviewHigh
CVE-2026-5567

Tenda M3, m3 firmware, m3

A flaw has been found in Tenda M3 1.0.0.10. This vulnerability affects the function setAdvPolicyData of the file /goform/setAdvPolicyData of the component Destination Handler. Executing a manipulation of the argument policyType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5566

UTT HiPER 1250GW

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBind results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5550

Tenda AC10, ac10 firmware, ac10

A vulnerability was identified in Tenda AC10 16.03.10.10_multi_TDE01. This affects the function fromSysToolChangePwd of the file /bin/httpd. The manipulation leads to stack-based buffer overflow. The attack may be initiated remotely. Multiple endpoints might be affected.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5548

Tenda AC10, ac10 firmware, ac10

A vulnerability was found in Tenda AC10 16.03.10.10_multi_TDE01. Affected by this vulnerability is the function fromSysToolChangePwd of the file /bin/httpd. Performing a manipulation of the argument sys.userpass results in stack-based buffer overflow. The attack can be initiated remotely.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5544

UTT HiPER 1250GW

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the argument Profile results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2018-25246

Wikipedia

Wikipedia 12.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of repeated characters into the search bar to trigger an application crash.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2018-25255

10-Strike Strike LANState

10-Strike LANState 8.8 contains a local buffer overflow vulnerability in structured exception handling that allows local attackers to execute arbitrary code by crafting malicious LSM map files. Attackers can create a specially formatted LSM file with a payload in the ObjCaption parameter that overflows the buffer, overwrites the SEH chain, and executes shellcode when the file is opened in the application.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2018-25254

nico-ftp NICO-FTP, nico-ftp

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2018-25251

Sourceforge Snes9K 0.0.9z

Snes9K 0.0.9z contains a buffer overflow vulnerability in the Netplay Socket Port Number field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Socket Port Number field via the Netplay Options menu to achieve code execution through SEH chain exploitation.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2018-25245

7Tik 7 Tik

7 Tik 1.0.1.0 contains a denial of service vulnerability that allows attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 7700 characters into the search bar to trigger an application crash.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2018-25241

VPNBrowser VPN Browser+

VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled exception that terminates the application.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20061

Sheedantivirus sheed AntiVirus

sheed AntiVirus 2.3 contains an unquoted service path vulnerability in the ShavProt service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers can insert a malicious executable in the unquoted path and trigger service restart or system reboot to execute code with LocalSystem privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20060

Hotspotshield Hotspot Shield

Hotspot Shield 6.0.3 contains an unquoted service path vulnerability in the hshld service binary that allows local attackers to escalate privileges by injecting malicious executables. Attackers can place executable files in the service path and upon service restart or system reboot, the malicious code executes with LocalSystem privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20059

Iobit IObit Malware Fighter, malware fighter

IObit Malware Fighter 4.3.1 contains an unquoted service path vulnerability in the IMFservice and LiveUpdateSvc services that allows local attackers to escalate privileges. Attackers can insert a malicious executable file in the unquoted service path and trigger privilege escalation when the service restarts or the system reboots, executing code with LocalSystem privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2016-20058

Netgate NETGATE AMITI Antivirus, amiti antivirus

Netgate AMITI Antivirus build 23.0.305 contains an unquoted service path vulnerability in the AmitiAvSrv and AmitiAntivirusHealth services that allows local attackers to escalate privileges. Attackers can place a malicious executable in the unquoted service path and trigger service restart or system reboot to execute code with LocalSystem privileges.

The CVSS severity warrants an early asset and exposure review.