CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2020-37008

    Last Modified: 12 May 2026

    EasyPMS 1.0.0 contains an authentication bypass vulnerability that allows unprivileged users to manipulate SQL queries in JSON requests to access admin user information. Attackers can exploit weak input validation by injecting single quotes in ID parameters and modify admin user passwords without proper token authentication.

    Published: 29 Jan 2026
    5.1
    Medium

    CVE-2020-37007

    Last Modified: 5 Mar 2026

    Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests.

    Published: 29 Jan 2026
    7.1
    High

    CVE-2020-37006

    Last Modified: 12 May 2026

    berliCRM 1.0.24 contains a SQL injection vulnerability in the 'src_record' parameter that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through a crafted POST request to the index.php endpoint to potentially extract or modify database information.

    Published: 29 Jan 2026
    7.1
    High

    CVE-2020-37005

    Last Modified: 15 Apr 2026

    TimeClock Software 1.01 contains an authenticated time-based SQL injection vulnerability that allows attackers to enumerate valid usernames by manipulating the 'notes' parameter. Attackers can inject conditional time delays in the add_entry.php endpoint to determine user existence by measuring response time differences.

    Published: 29 Jan 2026
    7.1
    High

    CVE-2020-37004

    Last Modified: 15 Jul 2026

    The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively guess and retrieve user credentials through boolean-based inference techniques.

    Published: 29 Jan 2026
    8.7
    High

    CVE-2020-37002

    Last Modified: 25 May 2026

    Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execute arbitrary commands after successful login. Attackers can leverage the /api/terminal/create endpoint to send a netcat reverse shell payload targeting a specified IP and port.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-37001

    Last Modified: 12 May 2026

    Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-37000

    Last Modified: 12 May 2026

    Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting a malicious WAV file with oversized payload. Attackers can leverage a specially crafted exploit file with shellcode, SEH bypass, and egghunter technique to achieve remote code execution on vulnerable Windows systems.

    Published: 29 Jan 2026
    8.8
    High

    CVE-2020-36999

    Last Modified: 15 Apr 2026

    Elaniin CMS 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard by manipulating the login page with SQL injection. Attackers can bypass authentication by sending crafted email and password parameters with '=''or' payload to login.php, granting unauthorized access to the system.

    Published: 29 Jan 2026
    8.4
    High

    CVE-2020-36997

    Last Modified: 12 May 2026

    BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Handler (SEH) chain through malicious file import. Attackers can craft a specially designed payload file to overwrite SEH addresses, potentially executing arbitrary code and gaining control of the application.

    Published: 29 Jan 2026
    4.6
    Medium

    CVE-2020-36995

    Last Modified: 12 May 2026

    Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the user configuration input. Attackers can overwrite the 'User' field with 350 bytes of repeated characters to trigger an application crash and prevent normal functionality.

    Published: 29 Jan 2026
    4.6
    Medium

    CVE-2020-36994

    Last Modified: 12 May 2026

    QlikView 12.50.20000.0 contains a denial of service vulnerability in the FTP server address input field that allows local attackers to crash the application. Attackers can paste a 300-character buffer into the FTP server address field to trigger an application crash and prevent normal functionality.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1590

    Last Modified: 18 Apr 2026

    A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/faculty/index.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1589

    Last Modified: 18 Apr 2026

    A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php. This manipulation of the argument txtsearch causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

    Published: 29 Jan 2026
    5.7
    Medium

    CVE-2025-7014

    Last Modified: 5 Jun 2026

    Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affects Menu Panel: through 29012026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2026
    5.7
    Medium

    CVE-2025-7013

    Last Modified: 5 Jun 2026

    Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Exploitation of Trusted Identifiers. This issue affects Menu Panel: through 29012026.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2026
    7.5
    High

    CVE-2026-1616

    Last Modified: 18 Apr 2026

    The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters.

    Published: 29 Jan 2026
    2
    Low

    CVE-2026-1588

    Last Modified: 18 Apr 2026

    A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1587

    Last Modified: 18 Apr 2026

    A vulnerability has been found in Open5GS up to 2.7.6. The affected element is the function sgwc_s11_handle_modify_bearer_request of the file /sgwc/s11-handler.c of the component SGWC. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Applying a patch is the recommended action to fix this issue. The issue report is flagged as already-fixed.

    Published: 29 Jan 2026
    5.5
    Medium

    CVE-2026-1586

    Last Modified: 18 Apr 2026

    A flaw has been found in Open5GS up to 2.7.5. Impacted is the function ogs_gtp2_f_teid_to_ip of the file /sgwc/s11-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack may be performed from remote. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed.

    Published: 29 Jan 2026
    8
    High

    CVE-2025-7016

    Last Modified: 5 Jun 2026

    Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Authentication Abuse. This issue affects QR Menu: before s1.05.12.

    Published: 29 Jan 2026
    5.7
    Medium

    CVE-2025-7015

    Last Modified: 5 Jun 2026

    Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fixation. This issue affects QR Menu: before s1.05.12.

    Published: 29 Jan 2026
    6.9
    Medium

    CVE-2026-1469

    Last Modified: 18 Apr 2026

    Stored Cross-Site Scripting (XSS) in RLE NOVA's PlanManager. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting malicious payload through the ‘comment’ and ‘brand’ parameters in ‘/index.php’. The payload is stored by the application and subsequently displayed without proper sanitization when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

    Published: 29 Jan 2026
    4.3
    Medium

    CVE-2026-22764

    Last Modified: 18 Apr 2026

    Dell OpenManage Network Integration, versions prior to 3.9, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25097

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25091

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25092

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25093

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25094

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25095

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25096

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    Unknown

    CVE-2026-25090

    Last Modified: 30 Jan 2026

    Not used

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23570

    Last Modified: 18 Apr 2026

    A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical datetime prefixes and compromising log integrity and forensic correlation.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23569

    Last Modified: 18 Apr 2026

    An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR remotely and facilitate exploitation of other vulnerabilities on the affected system.

    Published: 29 Jan 2026
    5.4
    Medium

    CVE-2026-23568

    Last Modified: 18 Apr 2026

    An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause information disclosure or denial-of-service via a special crafted packet. The leaked memory could be used to bypass ASLR and facilitate further exploitation.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23567

    Last Modified: 18 Apr 2026

    An integer underflow in the UDP command handler of the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to trigger a heap-based buffer overflow and cause a denial-of-service (service crash) via specially crafted UDP packets.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23566

    Last Modified: 18 Apr 2026

    A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log integrity and nonrepudiation.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23565

    Last Modified: 18 Apr 2026

    A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause the NomadBranch.exe process to terminate via crafted requests. This can result in a denial-of-service condition of the Content Distribution Service.

    Published: 29 Jan 2026
    6.5
    Medium

    CVE-2026-23564

    Last Modified: 18 Apr 2026

    A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to cause normally encrypted UDP traffic to be sent in cleartext. This can result in disclosure of sensitive information.

    Published: 29 Jan 2026
    6.8
    Medium

    CVE-2026-23571

    Last Modified: 18 Apr 2026

    A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected into the instruction’s input field. Users of 1E Client version 24.5 or higher are not affected.

    Published: 29 Jan 2026
    5.7
    Medium

    CVE-2026-23563

    Last Modified: 18 Apr 2026

    Improper Link Resolution Before File Access (invoked by 1E‑Explorer‑TachyonCore‑DeleteFileByPath instruction) in TeamViewer DEX - 1E Client before version 26.1 on Windows allows a low‑privileged local attacker to delete protected system files via a crafted RPC control junction or symlink that is followed when the delete instruction executes.

    Published: 29 Jan 2026
    6.9
    Medium

    CVE-2026-1188

    Last Modified: 18 Apr 2026

    In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.

    Published: 29 Jan 2026
    8.1
    High

    CVE-2025-14975

    Last Modified: 15 Apr 2026

    The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account

    Published: 29 Jan 2026
    6.9
    Medium

    CVE-2026-25067

    Last Modified: 18 Apr 2026

    SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The application base64-decodes attacker-supplied input and uses it as a filesystem path without validation. On Windows systems, this allows UNC paths to be resolved, causing the SmarterMail service to initiate outbound SMB authentication attempts to attacker-controlled hosts. This can be abused for credential coercion, NTLM relay attacks, and unauthorized network authentication.

    Published: 29 Jan 2026
    6.9
    Medium

    CVE-2025-55704

    Last Modified: 15 Apr 2026

    Hidden functionality issue exists in multiple MFPs provided by Brother Industries, Ltd., which may allow an attacker to obtain the logs of the affected product and obtain sensitive information within the logs.

    Published: 29 Jan 2026
    6.3
    Medium

    CVE-2025-53869

    Last Modified: 15 Apr 2026

    Multiple MFPs provided by Brother Industries, Ltd. does not properly validate server certificates, which may allow a man-in-the-middle attacker to replace the set of root certificates used by the product with a set of arbitrary certificates.

    Published: 29 Jan 2026
    2.1
    Low

    CVE-2026-1552

    Last Modified: 18 Apr 2026

    A security vulnerability has been detected in SEMCMS 5.0. This vulnerability affects unknown code of the file /SEMCMS_Info.php. The manipulation of the argument searchml leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 29 Jan 2026
    9.8
    Critical

    CVE-2025-69929

    Last Modified: 27 Feb 2026

    An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format

    Published: 29 Jan 2026
    7.5
    High

    CVE-2025-63651

    Last Modified: 19 Feb 2026

    A use-after-free in the mk_string_char_search function (mk_core/mk_string.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.

    Published: 29 Jan 2026
    7.8
    High

    CVE-2025-69604

    Last Modified: 13 Feb 2026

    An issue in Shirt Pocket's SuperDuper! 3.11 and earlier allow a local attacker to modify the default task template to install an arbitrary package that can run shell scripts with root privileges and Full Disk Access, thus bypassing macOS privacy controls.

    Published: 29 Jan 2026