CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2025-36094

    Last Modified: 25 Feb 2026

    IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.

    Published: 3 Feb 2026
    8.7
    High

    CVE-2020-37097

    Last Modified: 5 Mar 2026

    Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.

    Published: 3 Feb 2026
    5.1
    Medium

    CVE-2020-37096

    Last Modified: 5 Mar 2026

    Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.

    Published: 3 Feb 2026
    8.6
    High

    CVE-2020-37094

    Last Modified: 10 Jul 2026

    EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authentication/Espo.php. Attackers can obtain an authentication token for a controlled account and replay it against any victim account sharing the same password, since tokens are bound to password hashes rather than unique per-user values, bypassing the victim's 2FA protections.

    Published: 3 Feb 2026
    8.7
    High

    CVE-2020-37093

    Last Modified: 15 Apr 2026

    Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve WiFi passwords through the netcore_get.cgi endpoint. Attackers can send a GET request to the endpoint to extract sensitive network credentials including SSID and WiFi passwords in plain text.

    Published: 3 Feb 2026
    9.3
    Critical

    CVE-2020-37092

    Last Modified: 15 Apr 2026

    Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefined credentials. Attackers can leverage the embedded root account with a crackable password to gain full administrative access to the network device.

    Published: 3 Feb 2026
    5.1
    Medium

    CVE-2020-37091

    Last Modified: 15 Apr 2026

    Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system.

    Published: 3 Feb 2026
    8.7
    High

    CVE-2020-37090

    Last Modified: 5 Mar 2026

    School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

    Published: 3 Feb 2026
    7.1
    High

    CVE-2020-37089

    Last Modified: 5 Mar 2026

    School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries through GET requests. Attackers can exploit the vulnerable parameter by injecting crafted SQL statements to potentially extract, modify, or delete database information.

    Published: 3 Feb 2026
    8.7
    High

    CVE-2020-37088

    Last Modified: 5 Mar 2026

    School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.

    Published: 3 Feb 2026
    6.9
    Medium

    CVE-2020-37086

    Last Modified: 15 Apr 2026

    Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to access unauthorized file system paths without authentication. Attackers can exploit the vulnerability by manipulating path parameters in GET and POST requests to list or download sensitive system files and inject malicious scripts into application parameters.

    Published: 3 Feb 2026
    8.7
    High

    CVE-2020-37085

    Last Modified: 15 Apr 2026

    VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by sending oversized string payloads through the Thrift protocol. Attackers can exploit the vulnerability by sending a long string to the send_say() method, causing the server to become unresponsive.

    Published: 3 Feb 2026
    8.8
    High

    CVE-2020-37083

    Last Modified: 15 Apr 2026

    PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through the 'id' parameter. Attackers can inject crafted SQL statements with time delays to extract information by observing response times in the photo.php endpoint.

    Published: 3 Feb 2026
    8.6
    High

    CVE-2020-37082

    Last Modified: 5 Mar 2026

    webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].sql.gz file.

    Published: 3 Feb 2026
    7.1
    High

    CVE-2020-37081

    Last Modified: 15 Apr 2026

    Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calendar.php that allow attackers to inject malicious SQL commands. Attackers can exploit vulnerable parameters like uid, pid, type, m, y, and code to compromise the database management system and web application without user interaction.

    Published: 3 Feb 2026
    7.2
    High

    CVE-2020-37080

    Last Modified: 15 Apr 2026

    webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on the server through an unauthenticated file deletion mechanism.

    Published: 3 Feb 2026
    7.2
    High

    CVE-2020-37078

    Last Modified: 15 Apr 2026

    i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete_import parameter. Attackers can send a POST request to the import module with a crafted filename to remove files from the server's filesystem.

    Published: 3 Feb 2026
    6.9
    Medium

    CVE-2020-37077

    Last Modified: 15 Apr 2026

    Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating directory path traversal techniques.

    Published: 3 Feb 2026
    8.8
    High

    CVE-2020-37076

    Last Modified: 10 Feb 2026

    Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.

    Published: 3 Feb 2026
    8.4
    High

    CVE-2020-37075

    Last Modified: 15 Apr 2026

    LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) overwrite and execute shellcode when importing computers from a file.

    Published: 3 Feb 2026
    8.4
    High

    CVE-2020-37074

    Last Modified: 15 Apr 2026

    Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when importing computer lists.

    Published: 3 Feb 2026
    8.6
    High

    CVE-2020-37073

    Last Modified: 10 Feb 2026

    Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter.

    Published: 3 Feb 2026
    5.1
    Medium

    CVE-2020-37072

    Last Modified: 10 Feb 2026

    Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.

    Published: 3 Feb 2026
    9.3
    Critical

    CVE-2020-37071

    Last Modified: 15 Jul 2026

    CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.

    Published: 3 Feb 2026
    8.6
    High

    CVE-2020-37070

    Last Modified: 15 Apr 2026

    CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling remote code execution.

    Published: 3 Feb 2026
    8.7
    High

    CVE-2020-37069

    Last Modified: 25 Feb 2026

    Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

    Published: 3 Feb 2026
    8.7
    High

    CVE-2020-37068

    Last Modified: 25 Feb 2026

    Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

    Published: 3 Feb 2026
    7.1
    High

    CVE-2020-37067

    Last Modified: 15 Apr 2026

    Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service.

    Published: 3 Feb 2026
    8.4
    High

    CVE-2020-37066

    Last Modified: 15 Apr 2026

    GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malicious input in the File Open URL dialog. Attackers can generate a specially crafted text file with Unicode-encoded shellcode to trigger a stack-based overflow and execute commands when the file is opened.

    Published: 3 Feb 2026
    8.4
    High

    CVE-2020-37065

    Last Modified: 15 Apr 2026

    StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to overwrite memory by manipulating the SongPattern input. Attackers can craft a malicious payload exceeding 256 bytes to potentially execute arbitrary code and compromise the application.

    Published: 3 Feb 2026
    8.8
    High

    CVE-2019-25260

    Last Modified: 15 Jul 2026

    OXID eShop versions 6.x prior to 6.3.4 contains a SQL injection vulnerability in the 'sorting' parameter that allows attackers to insert malicious database content. Attackers can exploit the vulnerability by manipulating the sorting parameter to inject PHP code into the database and execute arbitrary code through crafted URLs.

    Published: 3 Feb 2026
    2.1
    Low

    CVE-2026-1811

    Last Modified: 18 Apr 2026

    A flaw has been found in bolo-blog bolo-solo up to 2.6.4. This affects the function importFromMarkdown of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component Filename Handler. Executing a manipulation of the argument File can lead to path traversal. The attack may be performed from remote. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 3 Feb 2026
    9.3
    Critical

    CVE-2026-1341

    Last Modified: 4 Jun 2026

    Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

    Published: 3 Feb 2026
    7.5
    High

    CVE-2026-25223

    Last Modified: 18 Apr 2026

    Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.2, a validation bypass vulnerability exists in Fastify where request body validation schemas specified by Content-Type can be completely circumvented. By appending a tab character (\t) followed by arbitrary content to the Content-Type header, attackers can bypass body validation while the server still processes the body as the original content type. This issue has been patched in version 5.7.2.

    Published: 3 Feb 2026
    3.7
    Low

    CVE-2026-25224

    Last Modified: 18 Apr 2026

    Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams response handling can allow a remote client to exhaust server memory. Applications that return a ReadableStream (or Response with a Web Stream body) via reply.send() are impacted. A slow or non-reading client can trigger unbounded buffering when backpressure is ignored, leading to process crashes or severe degradation. This issue has been patched in version 5.7.3.

    Published: 3 Feb 2026
    9.9
    Critical

    CVE-2026-25510

    Last Modified: 18 Apr 2026

    CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated user with file editor permissions can achieve Remote Code Execution (RCE) by leveraging the file creation and save endpoints, an attacker can upload and execute arbitrary PHP code on the server. This issue has been patched in version 0.28.5.0.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-25509

    Last Modified: 18 Apr 2026

    CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, the authentication implementation in CI4MS is vulnerable to email enumeration. An unauthenticated attacker can determine whether an email address is registered in the system by analyzing the application's response during the password reset process. This issue has been patched in version 0.28.5.0.

    Published: 3 Feb 2026
    9.3
    Critical

    CVE-2026-25150

    Last Modified: 18 Apr 2026

    Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create nested objects, but fails to sanitize dangerous property names like __proto__, constructor, and prototype. This allows unauthenticated attackers to pollute Object.prototype by sending crafted HTTP POST requests, potentially leading to privilege escalation, authentication bypass, or denial of service. This issue has been patched in version 1.19.0.

    Published: 3 Feb 2026
    5.3
    Medium

    CVE-2026-25148

    Last Modified: 18 Apr 2026

    Qwik is a performance focused javascript framework. Prior to version 1.19.0, a Cross-Site Scripting vulnerability in Qwik.js' server-side rendering virtual attribute serialization allows a remote attacker to inject arbitrary web scripts into server-rendered pages via virtual attributes. Successful exploitation permits script execution in a victim's browser in the context of the affected origin. This issue has been patched in version 1.19.0.

    Published: 3 Feb 2026
    5.9
    Medium

    CVE-2026-25151

    Last Modified: 18 Apr 2026

    Qwik is a performance focused javascript framework. Prior to version 1.19.0, Qwik City’s server-side request handler inconsistently interprets HTTP request headers, which can be abused by a remote attacker to circumvent form submission CSRF protections using specially crafted or multi-valued Content-Type headers. This issue has been patched in version 1.19.0.

    Published: 3 Feb 2026
    5.9
    Medium

    CVE-2026-25155

    Last Modified: 18 Apr 2026

    Qwik is a performance focused javascript framework. Prior to version 1.12.0, a typo in the regular expression within isContentType causes incorrect parsing of certain Content-Type headers. This issue has been patched in version 1.12.0.

    Published: 3 Feb 2026
    2.7
    Low

    CVE-2026-25149

    Last Modified: 18 Apr 2026

    Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler middleware allows a remote attacker to redirect users to arbitrary protocol-relative URLs. Successful exploitation permits attackers to craft convincing phishing links that appear to originate from the trusted domain but redirect the victim to an attacker-controlled site. This issue has been patched in version 1.19.0.

    Published: 3 Feb 2026
    8.8
    High

    CVE-2026-1862

    Last Modified: 18 Apr 2026

    Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 3 Feb 2026
    8.8
    High

    CVE-2026-1861

    Last Modified: 18 Apr 2026

    Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 3 Feb 2026
    9.3
    Critical

    CVE-2025-65078

    Last Modified: 15 Apr 2026

    An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.

    Published: 3 Feb 2026
    7.7
    High

    CVE-2026-24887

    Last Modified: 18 Apr 2026

    Claude Code is an agentic coding tool. Prior to version 2.0.72, due to an error in command parsing, it was possible to bypass the Claude Code confirmation prompt to trigger execution of untrusted commands through the find command. Reliably exploiting this required the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.72.

    Published: 3 Feb 2026
    7.7
    High

    CVE-2026-24053

    Last Modified: 18 Apr 2026

    Claude Code is an agentic coding tool. Prior to version 2.0.74, due to a Bash command validation flaw in parsing ZSH clobber syntax, it was possible to bypass directory restrictions and write files outside the current working directory without user permission prompts. Exploiting this required the user to use ZSH and the ability to add untrusted content into a Claude Code context window. This issue has been patched in version 2.0.74.

    Published: 3 Feb 2026
    7.1
    High

    CVE-2026-24052

    Last Modified: 18 Apr 2026

    Claude Code is an agentic coding tool. Prior to version 1.0.111, Claude Code contained insufficient URL validation in its trusted domain verification mechanism for WebFetch requests. The application used a startsWith() function to validate trusted domains (e.g., docs.python.org, modelcontextprotocol.io), this could have enabled attackers to register domains like modelcontextprotocol.io.example.com that would pass validation. This could enable automatic requests to attacker-controlled domains without user consent, potentially leading to data exfiltration. This issue has been patched in version 1.0.111.

    Published: 3 Feb 2026
    8.8
    High

    CVE-2025-65077

    Last Modified: 15 Apr 2026

    A relative path traversal vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

    Published: 3 Feb 2026
    6.9
    Medium

    CVE-2025-65081

    Last Modified: 15 Apr 2026

    An out-of-bounds read vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

    Published: 3 Feb 2026