Wed, Jan 15 · 11:15 PM CSTCVE-2024-57726
9.9/10 · Must read/watchNVDvuln
Summary
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
CVECVE-2024-57726
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 15 · 11:15 PM CST
ModifiedFri, Apr 24 · 07:26 PM CDT
Mon, Feb 06 · 03:59 PM CSTCVE-2015-2794
9.8/10 · Must read/watchNVDvuln
Summary
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
CVECVE-2015-2794
SeverityCRITICAL
TypeUPDATED
PublishedMon, Feb 06 · 03:59 PM CST
ModifiedFri, Apr 24 · 05:34 PM CDT
Sun, Dec 08 · 03:15 AM CSTCVE-2019-19635
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.
CVECVE-2019-19635
SeverityCRITICAL
TypeUPDATED
PublishedSun, Dec 08 · 03:15 AM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Sun, Dec 08 · 03:15 AM CSTCVE-2019-19636
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.
CVECVE-2019-19636
SeverityCRITICAL
TypeUPDATED
PublishedSun, Dec 08 · 03:15 AM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Sun, Dec 08 · 03:15 AM CSTCVE-2019-19637
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.
CVECVE-2019-19637
SeverityCRITICAL
TypeUPDATED
PublishedSun, Dec 08 · 03:15 AM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Sun, Dec 08 · 03:15 AM CSTCVE-2019-19638
9.8/10 · Must read/watchNVDvuln
Summary
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.
CVECVE-2019-19638
SeverityCRITICAL
TypeUPDATED
PublishedSun, Dec 08 · 03:15 AM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Tue, Sep 09 · 02:15 PM CDTCVE-2025-54236
9.1/10 · Must read/watchNVDvuln
Summary
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue doe
CVECVE-2025-54236
SeverityCRITICAL
TypeUPDATED
PublishedTue, Sep 09 · 02:15 PM CDT
ModifiedWed, Apr 22 · 07:00 PM CDT
Tue, Jul 18 · 03:37 PM CDTCVE-2006-3601
10.0/10 · Must read/watchNVDvuln
Summary
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileges via unspecified vectors, as used in an attack against the Microsoft France web site. NOTE: due to the lack of details and uncertainty about which product is affected, t
CVECVE-2006-3601
SeverityHIGH
TypeUPDATED
PublishedTue, Jul 18 · 03:37 PM CDT
ModifiedFri, Apr 24 · 05:34 PM CDT
Fri, Dec 13 · 02:15 AM CSTCVE-2019-19777
8.8/10 · Worth your timeNVDvuln
Summary
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
CVECVE-2019-19777
SeverityHIGH
TypeUPDATED
PublishedFri, Dec 13 · 02:15 AM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Fri, Dec 13 · 02:15 AM CSTCVE-2019-19778
8.8/10 · Worth your timeNVDvuln
Summary
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
CVECVE-2019-19778
SeverityHIGH
TypeUPDATED
PublishedFri, Dec 13 · 02:15 AM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Mon, Dec 30 · 04:15 AM CSTCVE-2019-20094
8.8/10 · Worth your timeNVDvuln
Summary
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.
CVECVE-2019-20094
SeverityHIGH
TypeUPDATED
PublishedMon, Dec 30 · 04:15 AM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Mon, Dec 30 · 05:15 PM CSTCVE-2019-20140
8.8/10 · Worth your timeNVDvuln
Summary
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.
CVECVE-2019-20140
SeverityHIGH
TypeUPDATED
PublishedMon, Dec 30 · 05:15 PM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Thu, Jan 02 · 02:16 PM CSTCVE-2019-20205
8.8/10 · Worth your timeNVDvuln
Summary
libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
CVECVE-2019-20205
SeverityHIGH
TypeUPDATED
PublishedThu, Jan 02 · 02:16 PM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Fri, Sep 17 · 09:15 PM CDTCVE-2020-21547
8.8/10 · Worth your timeNVDvuln
Summary
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
CVECVE-2020-21547
SeverityHIGH
TypeUPDATED
PublishedFri, Sep 17 · 09:15 PM CDT
ModifiedFri, Apr 24 · 12:56 PM CDT
Fri, Sep 17 · 09:15 PM CDTCVE-2020-21548
8.8/10 · Worth your timeNVDvuln
Summary
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
CVECVE-2020-21548
SeverityHIGH
TypeUPDATED
PublishedFri, Sep 17 · 09:15 PM CDT
ModifiedFri, Apr 24 · 12:56 PM CDT
Fri, Apr 08 · 04:15 PM CDTCVE-2021-40656
8.8/10 · Worth your timeNVDvuln
Summary
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
CVECVE-2021-40656
SeverityHIGH
TypeUPDATED
PublishedFri, Apr 08 · 04:15 PM CDT
ModifiedFri, Apr 24 · 01:34 PM CDT
Fri, Apr 08 · 03:15 PM CDTCVE-2022-27044
8.8/10 · Worth your timeNVDvuln
Summary
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
CVECVE-2022-27044
SeverityHIGH
TypeUPDATED
PublishedFri, Apr 08 · 03:15 PM CDT
ModifiedFri, Apr 24 · 12:56 PM CDT
Fri, Apr 08 · 03:15 PM CDTCVE-2022-27046
8.8/10 · Worth your timeNVDvuln
Summary
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
CVECVE-2022-27046
SeverityHIGH
TypeUPDATED
PublishedFri, Apr 08 · 03:15 PM CDT
ModifiedFri, Apr 24 · 12:56 PM CDT
Mon, Aug 12 · 01:38 PM CDTCVE-2024-7399
8.8/10 · Worth your timeNVDvuln
Summary
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
CVECVE-2024-7399
SeverityHIGH
TypeUPDATED
PublishedMon, Aug 12 · 01:38 PM CDT
ModifiedFri, Apr 24 · 08:23 PM CDT
Sat, Mar 21 · 04:17 AM CDTCVE-2026-2941
8.8/10 · Worth your timeNVDvuln
Summary
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1.0.4. This makes it possible for authenticated attackers, with subscriber-level access a
CVECVE-2026-2941
SeverityHIGH
TypeUPDATED
PublishedSat, Mar 21 · 04:17 AM CDT
ModifiedFri, Apr 24 · 04:27 PM CDT
Sat, Mar 21 · 04:17 AM CDTCVE-2026-3334
8.8/10 · Worth your timeNVDvuln
Summary
The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescription', and 'or_admin_email' parameters in all versions up to, and including, 2.288. This is due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL quer
CVECVE-2026-3334
SeverityHIGH
TypeUPDATED
PublishedSat, Mar 21 · 04:17 AM CDT
ModifiedFri, Apr 24 · 04:27 PM CDT
Tue, Dec 16 · 09:16 AM CSTCVE-2025-68055
8.5/10 · Worth your timeNVDvuln
Summary
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from n/a through <= 1.1.32.
CVECVE-2025-68055
SeverityHIGH
TypeUPDATED
PublishedTue, Dec 16 · 09:16 AM CST
ModifiedFri, Apr 24 · 08:16 PM CDT
Fri, Nov 30 · 03:29 AM CSTCVE-2018-19762
7.8/10 · Worth your timeNVDvuln
Summary
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of service or possibly unspecified other impact.
CVECVE-2018-19762
SeverityHIGH
TypeUPDATED
PublishedFri, Nov 30 · 03:29 AM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Wed, Jan 02 · 03:29 PM CSTCVE-2019-3574
7.8/10 · Worth your timeNVDvuln
Summary
In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.
CVECVE-2019-3574
SeverityHIGH
TypeUPDATED
PublishedWed, Jan 02 · 03:29 PM CST
ModifiedFri, Apr 24 · 12:56 PM CDT
Fri, Dec 31 · 05:00 AM CSTCVE-2004-2324
7.5/10 · Worth your timeNVDvuln
Summary
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx.
CVECVE-2004-2324
SeverityHIGH
TypeUPDATED
PublishedFri, Dec 31 · 05:00 AM CST
ModifiedFri, Apr 24 · 05:34 PM CDT