8.5

CVSS4.0

CVE-2020-36930 - SysGauge 7.9.18 - ' SysGauge Server' Unquoted Service Path

SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGauge Server\bin\sysgaus.exe' to inject malicious executables an…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: Jan. 16, 2026, 10:16 p.m.

8.5

CVSS4.0

CVE-2020-36929 - Brother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service Path

Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted file paths in BrAuSvc and BRPA_Agent services to inject malicious executables and…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: Jan. 16, 2026, 5:15 p.m.

8.5

CVSS4.0

CVE-2020-36928 - Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path

Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: Jan. 16, 2026, 5:15 p.m.

8.5

CVSS4.0

CVE-2020-36927 - DiskPulse 13.6.14 - Unquoted Service Path

DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse Enterprise\bin\diskpls.exe' to inject maliciou…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: Jan. 16, 2026, 5:15 p.m.

6.9

CVSS4.0

CVE-2020-36926 - SmarterTools SmarterTrack 7922 -Information Disclosure

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifi…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: Jan. 20, 2026, 5:15 p.m.

6.1

CVSS3.1

CVE-2026-1011 - Stored Cross-Site Scripting in Altium Live Support Center Comment Endpoint

A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interface applies HTML escaping, the backend accepts and stores arbitrary HTML and JavaScript supplied via modified POST reque…

📅 Published: Jan. 15, 2026, 11:08 p.m. 🔄 Last Modified: Jan. 23, 2026, 8:26 p.m.

8

CVSS3.1

CVE-2026-1010 - Stored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege Escalation

A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow,…

📅 Published: Jan. 15, 2026, 11 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:31 p.m.

8.1

CVSS3.1

CVE-2026-22864 - Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension…

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefo…

📅 Published: Jan. 15, 2026, 10:58 p.m. 🔄 Last Modified: Jan. 21, 2026, 2:32 p.m.

9.2

CVSS4.0

CVE-2026-22863 - Deno node:crypto doesn't finalize cipher

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.6.0, node:crypto doesn't finalize cipher. The vulnerability allows an attacker to have infinite encryptions. This can lead to naive attempts at brute forcing, as well as more refined attacks with the goal to learn the server secret…

📅 Published: Jan. 15, 2026, 10:53 p.m. 🔄 Last Modified: Jan. 21, 2026, 2:35 p.m.

9

CVSS3.1

CVE-2026-1009 - Stored Cross-Site Scripting in Altium Live Forum Leading to Cross-Customer Data Exposure

A stored cross-site scripting (XSS) vulnerability exists in the Altium Forum due to missing server-side input sanitization in forum post content. An authenticated attacker can inject arbitrary JavaScript into forum posts, which is stored and executed when other users view the affected post. Success…

📅 Published: Jan. 15, 2026, 10:51 p.m. 🔄 Last Modified: Jan. 23, 2026, 7:32 p.m.
Total resulsts: 329514
Page 157 of 32,952
« previous page » next page
Filters