CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open Emr
1Openemr
Jun 17, 2026
Sep 16, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
OpenEMR v5.0.1-6 allows code execution.
1Open Emr
1Openemr
Jun 17, 2026
Sep 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
OpenEMR v5.0.1-6 allows XSS.
1Verydows
1Verydows
Jun 17, 2026
Feb 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Verydows 2.0 has XSS via the index.php?c=main a parameter, as demonstrated by an a=index[XSS] value.
1Dedecms
1Dedecms
Jun 17, 2026
Feb 16, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1...Show more
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a dede/album_edit.php?dopost=save&formzip=1 request with a ZIP archive that contains a file such as "1.jpg.php" (because input validation only checks that .jpg, .png, or .gif is present as a substring, and does not otherwise check the file name or content).Show less
1Responsive Video News Script Project
1Responsive Video News Script
Jun 17, 2026
Feb 16, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
PHP Scripts Mall Responsive Video News Script has XSS via the Search Bar. This might, for example, be leveraged for HTML injection or URL redirection.
1Themerig
1Find A Place Cms Directory
Jun 17, 2026
Feb 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.
1Hiawatha Webserver
1Hiawatha
Jun 17, 2026
Feb 16, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled.
1Sound Exchange Project
1Sound Exchange
Jun 17, 2026
Feb 15, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c allows a NULL pointer dereference.
1Sound Exchange Project
1Sound Exchange
Jun 17, 2026
Feb 15, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow.
1Sound Exchange Project
1Sound Exchange
Jun 17, 2026
Feb 15, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in SoX 14.4.2. In xmalloc.h, there is an integer overflow on the result of multiplication fed into the lsx_valloc macro that wraps malloc. When the buffer is allocated, it is smaller than expected...Show more
An issue was discovered in SoX 14.4.2. In xmalloc.h, there is an integer overflow on the result of multiplication fed into the lsx_valloc macro that wraps malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow in channels_start in remix.c.Show less
3Canonical
DebianSound Exchange Project
3Debian Linux
Sound ExchangeUbuntu Linux
Jun 17, 2026
Feb 15, 2019
N/A· v4
5.0 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-...Show more
An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow.Show less
1Bmc
1Patrol Agent
Jun 17, 2026
May 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this networ...Show more
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these credentials and use them to execute code or escalate privileges on the network.Show less
1Heimdalsecurity
1Thor
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
1Simple
1Better Banking
Jun 17, 2026
May 13, 2019
N/A· v4
6.8 MEDIUM· v3
2.1 LOW· v2
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password to the keyboard autocomplete functionali...Show more
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an information disclosure vulnerability that leaked the user's password to the keyboard autocomplete functionality. Third-party Android keyboards that capture the password may store this password in cleartext, or transmit the password to third-party services for keyboard customization purposes. A compromise of any datastore that contains keyboard autocompletion caches would result in the disclosure of the user's Simple Bank password.Show less
1Htmly
1Htmly
Jun 17, 2026
May 8, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit...Show more
Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script or HTML via the (1) destination parameter to delete feature; the (2) destination parameter to edit feature; (3) content parameter in the profile feature.Show less
1Beescms
1Beescms
Jun 17, 2026
Feb 15, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=user URI.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
May 24, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form paramete...Show more
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD self-service password reset and MFA token.Show less
1Estrongs
1Es File Explorer File Manager
Jun 17, 2026
Feb 15, 2019
N/A· v4
4.2 MEDIUM· v3
4.3 MEDIUM· v2
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site...Show more
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.Show less
1Nasm
1Netwide Assembler
Jun 17, 2026
Feb 15, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.
1Foxitsoftware
1Foxit Reader
Jun 17, 2026
May 13, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorrect permission set.
2Opensuse
Pocoo
2Jinja2
Leap
Jun 17, 2026
Feb 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker...Show more
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxingShow less
1Falco
1Falco
Jun 17, 2026
May 17, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to bypass the detection engine.
1Gpg Pgp Project
1Gpg Pgp
Jun 17, 2026
May 16, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by cra...Show more
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by crafting a signed email with an invalid signature. Also, it does not verify the validity of the signing key, which allows remote attackers to spoof arbitrary email signatures by crafting a key with a fake user ID (email address) and injecting it into the user's keyring.Show less
1Marlam
2Mpop
Msmtp
Jun 17, 2026
Feb 13, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
1Hashicorp
1Consul
Jun 17, 2026
Mar 5, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with...Show more
HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and obtain the privileges of one other arbitrary token within secondary datacenters, because a token with literally "<hidden>" as its secret is used in unusual circumstances.Show less