CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2020-37205

    Last Modified: 20 Feb 2026

    RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' registration field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37204

    Last Modified: 20 Feb 2026

    RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37203

    Last Modified: 15 Apr 2026

    Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37202

    Last Modified: 15 Apr 2026

    NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37201

    Last Modified: 17 Feb 2026

    NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37200

    Last Modified: 17 Feb 2026

    NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to crash the application by supplying oversized input. Attackers can generate a 1000-character payload and paste it into the registration key field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37199

    Last Modified: 5 Mar 2026

    NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

    Published: 11 Feb 2026
    6.7
    Medium

    CVE-2020-37198

    Last Modified: 15 Apr 2026

    Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability that allows attackers to crash the application by injecting an oversized buffer into the license key field. Attackers can generate a 6000-byte payload and paste it into the license activation field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37197

    Last Modified: 26 Feb 2026

    Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37196

    Last Modified: 27 Feb 2026

    Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by providing an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37195

    Last Modified: 15 Apr 2026

    BlueAuditor 1.7.2.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37194

    Last Modified: 15 Apr 2026

    Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by supplying an overly long registration key. Attackers can generate a 1000-character payload file and paste it into the registration key field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37193

    Last Modified: 15 Apr 2026

    ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when selecting a ZIP file.

    Published: 11 Feb 2026
    6.7
    Medium

    CVE-2020-37192

    Last Modified: 15 Apr 2026

    MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37191

    Last Modified: 15 Apr 2026

    Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and Registration Code input fields.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37190

    Last Modified: 15 Apr 2026

    Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting 5000 characters into the User Name or Registration Code input fields.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37189

    Last Modified: 15 Apr 2026

    TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37188

    Last Modified: 15 Apr 2026

    SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37187

    Last Modified: 15 Apr 2026

    SpotDialup 1.6.7 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

    Published: 11 Feb 2026
    9.3
    Critical

    CVE-2020-37186

    Last Modified: 15 Apr 2026

    Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system commands through a crafted POST request.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37185

    Last Modified: 15 Apr 2026

    Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.

    Published: 11 Feb 2026
    8.4
    High

    CVE-2020-37184

    Last Modified: 15 Apr 2026

    Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite SEH handlers and execute system commands by injecting malicious bytecode into the input field.

    Published: 11 Feb 2026
    8.4
    High

    CVE-2020-37183

    Last Modified: 15 Apr 2026

    Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload in the License Name input field to trigger a buffer overflow and execute system commands like calc.exe.

    Published: 11 Feb 2026
    8.7
    High

    CVE-2020-37182

    Last Modified: 15 Apr 2026

    Redir 3.3 contains a stack overflow vulnerability in the doproxyconnect() function that allows attackers to crash the application by sending oversized input. Attackers can exploit the sprintf() buffer without proper length checking to overwrite memory and cause a segmentation fault, resulting in program termination.

    Published: 11 Feb 2026
    6.7
    Medium

    CVE-2020-37181

    Last Modified: 15 Apr 2026

    Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) through a malicious registration code input. Attackers can craft a payload with specific offsets and partial SEH overwrite techniques to potentially execute arbitrary code on vulnerable Windows 32-bit systems.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37180

    Last Modified: 15 Apr 2026

    GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37179

    Last Modified: 15 Apr 2026

    APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.

    Published: 11 Feb 2026
    6.7
    Medium

    CVE-2020-37177

    Last Modified: 15 Apr 2026

    BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37178

    Last Modified: 15 Apr 2026

    KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.

    Published: 11 Feb 2026
    8.4
    High

    CVE-2020-37176

    Last Modified: 15 Apr 2026

    Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the application's registration dialog to trigger code execution and open the calculator through carefully constructed buffer overflow techniques.

    Published: 11 Feb 2026
    4.6
    Medium

    CVE-2020-37175

    Last Modified: 15 Apr 2026

    P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the Camera ID input field. Attackers can paste a 257-character buffer into the Camera ID field to trigger an application crash on iOS devices.

    Published: 11 Feb 2026
    8.7
    High

    CVE-2020-37173

    Last Modified: 18 Feb 2026

    AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.

    Published: 11 Feb 2026
    4.3
    Medium

    CVE-2026-25633

    Last Modified: 17 Apr 2026

    Statamic is a, Laravel + Git powered CMS designed for building websites. Prior to 5.73.6 and 6.2.5, users without permission to view assets are able are able to download them and view their metadata. Logged-out users and users without permission to access the control panel are unable to take advantage of this. This has been fixed in 5.73.6 and 6.2.5.

    Published: 11 Feb 2026
    8.5
    High

    CVE-2020-37172

    Last Modified: 18 Feb 2026

    AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.

    Published: 11 Feb 2026
    6.9
    Medium

    CVE-2025-68663

    Last Modified: 20 Feb 2026

    Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a vulnerability was found in Outline's WebSocket authentication mechanism that allows suspended users to maintain or establish real-time WebSocket connections and continue receiving sensitive operational updates after their account has been suspended. This vulnerability is fixed in 1.1.0.

    Published: 11 Feb 2026
    7.6
    High

    CVE-2025-64487

    Last Modified: 20 Feb 2026

    Outline is a service that allows for collaborative documentation. Prior to 1.1.0, a privilege escalation vulnerability exists in the Outline document management system due to inconsistent authorization checks between user and group membership management endpoints. This vulnerability is fixed in 1.1.0.

    Published: 11 Feb 2026
    5.5
    Medium

    CVE-2026-25062

    Last Modified: 17 Apr 2026

    Outline is a service that allows for collaborative documentation. Prior to 1.4.0, during the JSON import process, the value of attachments[].key from the imported JSON is passed directly to path.join(rootPath, node.key) and then read using fs.readFile without validation. By embedding path traversal sequences such as ../ or absolute paths, an attacker can read arbitrary files on the server and import them as attachments. This vulnerability is fixed in 1.4.0.

    Published: 11 Feb 2026
    Unknown

    CVE-2026-26229

    Last Modified: 10 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Feb 2026
    6.6
    Medium

    CVE-2026-0229

    Last Modified: 17 Apr 2026

    A denial-of-service (DoS) vulnerability in the Advanced DNS Security (ADNS) feature of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to initiate system reboots using a maliciously crafted packet. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. Cloud NGFW and Prisma Access® are not impacted by this vulnerability.

    Published: 11 Feb 2026
    1.3
    Low

    CVE-2026-0228

    Last Modified: 18 Apr 2026

    An improper certificate validation vulnerability in PAN-OS allows users to connect Terminal Server Agents on Windows to PAN-OS using expired certificates even if the PAN-OS configuration would not normally permit them to do so.

    Published: 11 Feb 2026
    8
    High

    CVE-2026-2361

    Last Modified: 18 Apr 2026

    PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a temporary view based on a function containing malicious code. When the anon.get_tablesample_ratio function is then called, the malicious code is executed with superuser privileges. This privilege elevation can be exploited by users having the CREATE privilege in PostgreSQL 15 and later. The risk is higher with PostgreSQL 14 or with instances upgraded from PostgreSQL 14 or a prior version because the creation permission on the public schema is granted by default. The problem is resolved in PostgreSQL Anonymizer 3.0.1 and further versions

    Published: 11 Feb 2026
    8
    High

    CVE-2026-2360

    Last Modified: 17 Apr 2026

    PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a custom operator in the public schema and place malicious code in that operator. This operator will later be executed with superuser privileges when the extension is created. The risk is higher with PostgreSQL 14 or with instances upgraded from PostgreSQL 14 or a prior version. With PostgreSQL 15 and later, the creation permission on the public schema is revoked by default and this exploit can only be achieved if a superuser adds a new schema in her/his own search_path and grants the CREATE privilege on that schema to untrusted users, both actions being clearly discouraged by the PostgreSQL documentation. The problem is resolved in PostgreSQL Anonymizer 3.0.1 and further versions

    Published: 11 Feb 2026
    5.8
    Medium

    CVE-2025-13391

    Last Modified: 22 Apr 2026

    The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'uni_cpo_remove_file' function in all versions up to, and including, 4.9.60. This makes it possible for unauthenticated attackers to delete arbitrary attachments or files stored in Dropbox if the file path is known. The vulnerability was partially patched in version 4.9.60.

    Published: 11 Feb 2026
    9.3
    Critical

    CVE-2026-24789

    Last Modified: 18 Apr 2026

    An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

    Published: 11 Feb 2026
    9.3
    Critical

    CVE-2026-25084

    Last Modified: 18 Apr 2026

    Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.

    Published: 11 Feb 2026
    6.9
    Medium

    CVE-2026-25869

    Last Modified: 17 Apr 2026

    MiniGal Nano versions 0.3.5 and prior contain a path traversal vulnerability in index.php via the dir parameter. The application appends user-controlled input to the photos directory and attempts to prevent traversal by removing dot-dot sequences, but this protection can be bypassed using crafted directory patterns. An attacker can exploit this behavior to cause the application to enumerate and display image files from unintended filesystem locations that are readable by the web server, resulting in unintended information disclosure.

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2026-25868

    Last Modified: 16 Apr 2026

    MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input and embeds it into an error message without output encoding, allowing an attacker to supply HTML/JavaScript that is reflected in the response. Successful exploitation can lead to execution of arbitrary script in a victim's browser in the context of the vulnerable application.

    Published: 11 Feb 2026
    2.3
    Low

    CVE-2025-12474

    Last Modified: 24 Apr 2026

    A specially-crafted file can cause libjxl's decoder to read pixel data from uninitialized (but allocated) memory. This can be done by causing the decoder to reference an outside-image-bound area in a subsequent patches. An incorrect optimization causes the decoder to omit populating those areas.

    Published: 11 Feb 2026
    8.7
    High

    CVE-2026-1837

    Last Modified: 17 Apr 2026

    A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is copied to pixel data. This can be done by requesting color transformation of grayscale images to another grayscale color space. Buffers allocated for 1-float-per-pixel are used as if they are allocated for 3-float-per-pixel. That happens only if LCMS2 is used as CMS engine. There is another CMS engine available (selected by build flags).

    Published: 11 Feb 2026
    5.1
    Medium

    CVE-2019-25317

    Last Modified: 5 Mar 2026

    Kimai 2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into timesheet descriptions. Attackers can insert SVG-based XSS payloads in the description field to execute arbitrary JavaScript when the page is loaded and viewed by other users.

    Published: 11 Feb 2026