7.1

CVSS4.0

CVE-2021-47782 - Odine Solutions GateKeeper 1.0 - 'trafficCycle' SQL Injection

Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate Post…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:10 p.m.

8.5

CVSS4.0

CVE-2021-47780 - Macro Expert 4.7 - Unquoted Service Path

Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the improperly configured service path to inject malicious executables that will be run with LocalSystem permissions …

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 21, 2026, 10:24 p.m.

8.4

CVSS4.0

CVE-2021-47779 - Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the tex…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:13 p.m.

8.4

CVSS4.0

CVE-2021-47756 - Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)

Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root permissions without additional authentication.

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 4:15 p.m.

8.5

CVSS4.0

CVE-2020-36930 - SysGauge 7.9.18 - ' SysGauge Server' Unquoted Service Path

SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGauge Server\bin\sysgaus.exe' to inject malicious executables an…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 10:16 p.m.

8.5

CVSS4.0

CVE-2020-36929 - Brother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service Path

Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted file paths in BrAuSvc and BRPA_Agent services to inject malicious executables and…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:15 p.m.

8.5

CVSS4.0

CVE-2020-36928 - Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path

Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:15 p.m.

8.5

CVSS4.0

CVE-2020-36927 - DiskPulse 13.6.14 - Unquoted Service Path

DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse Enterprise\bin\diskpls.exe' to inject maliciou…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 5:15 p.m.

6.9

CVSS4.0

CVE-2020-36926 - SmarterTools SmarterTrack 7922 -Information Disclosure

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifi…

πŸ“… Published: Jan. 15, 2026, 11:25 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 5:15 p.m.

6.1

CVSS3.1

CVE-2026-1011 - Stored Cross-Site Scripting in Altium Live Support Center Comment Endpoint

A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interface applies HTML escaping, the backend accepts and stores arbitrary HTML and JavaScript supplied via modified POST reque…

πŸ“… Published: Jan. 15, 2026, 11:08 p.m. πŸ”„ Last Modified: Jan. 23, 2026, 8:26 p.m.
Total resulsts: 329548
Page 160 of 32,955
Β« previous page Β» next page
Filters