6.9

CVSS4.0

CVE-2026-2073 - itsourcecode School Management System index.php sql injection

A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosedโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 3:32 a.m. ๐Ÿ”„ Last Modified: Feb. 7, 2026, 3:32 a.m.

6.8

CVSS3.1

CVE-2025-31990 - HCL DevOps Velocity is susceptible to a Denial of Service vulnerability

Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerabilitโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 3:26 a.m. ๐Ÿ”„ Last Modified: Feb. 7, 2026, 3:26 a.m.

8.7

CVSS4.0

CVE-2026-2071 - UTT ่ฟ›ๅ– 520W formP2PLimitConfig strcpy buffer overflow

A vulnerability was found in UTT ่ฟ›ๅ– 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formP2PLimitConfig. Performing a manipulation of the argument except results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made publicโ€ฆ

๐Ÿ“… Published: Feb. 7, 2026, 12:32 a.m. ๐Ÿ”„ Last Modified: Feb. 7, 2026, 12:32 a.m.

5.1

CVSS4.0

CVE-2020-37079 - Wing FTP Server < 6.2.7 - Cross-site Request Forgery

Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user acโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:16 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:16 p.m.

6.7

CVSS4.0

CVE-2020-37171 - TapinRadio 2.12.3 - 'username' Denial of Service

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and prevent normal prograโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

6.7

CVSS4.0

CVE-2020-37170 - TapinRadio 2.12.3 - 'address' Denial of Service

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy address configuration that allows local attackers to crash the application. Attackers can overwrite the address field with 3000 bytes of arbitrary data to trigger an application crash and prevent normal program fuโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

6.9

CVSS4.0

CVE-2020-37166 - AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service

AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attackers to crash the application. Attackers can overwrite the username field with a 1000-byte buffer, causing the application to become unresponsive and terminate.

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

6.7

CVSS4.0

CVE-2020-37165 - AbsoluteTelnet 11.12 - "license name" Denial of Service

AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license name field to trigger an application crash.

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

6.7

CVSS4.0

CVE-2020-37164 - AbsoluteTelnet 11.12 - "license entry" Denial of Service

AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash.

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

8.8

CVSS4.0

CVE-2020-37163 - QuickDate 1.3.2 - SQL Injection

QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries through the '_located' parameter in the find_matches endpoint. Attackers can inject UNION-based SQL statements to extract database information including user credentials, database nameโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.
Total resulsts: 331478
Page 1 of 33,148
ยป next page
Filters