5.4

CVSS3.1

CVE-2025-36094 - Multiple security vulnerabilities are addressed with IBM Cloud Pak for Business Automation iFixes f…

IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.

πŸ“… Published: Feb. 3, 2026, 10:06 p.m. πŸ”„ Last Modified: Feb. 25, 2026, 6:52 p.m.

8.7

CVSS4.0

CVE-2020-37097 - Edimax EW-7438RPn 1.13 - Information Disclosure (WiFi Password)

Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configura…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

5.1

CVSS4.0

CVE-2020-37096 - Edimax EW-7438RPn - Cross-Site Request Forgery (MAC Filtering)

Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

8.7

CVSS4.0

CVE-2020-37094 - EspoCRM 5.8.5 - Privilege Escalation

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and priv…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 7, 2026, 2:05 p.m.

8.7

CVSS4.0

CVE-2020-37093 - Netis E1+ 1.2.32533 - Unauthenticated WiFi Password Leak

Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve WiFi passwords through the netcore_get.cgi endpoint. Attackers can send a GET request to the endpoint to extract sensitive network credentials including SSID and WiFi passwords in …

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2020-37092 - Netis E1+ 1.2.32533 - Backdoor Account (root)

Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefined credentials. Attackers can leverage the embedded root account with a crackable password to gain full administrative access to the network device.

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2020-37091 - Maian Support Helpdesk 4.3 - Cross-Site Request Forgery (Add Admin)

Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ …

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2020-37090 - School ERP Pro 1.0 - Remote Code Execution

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

7.1

CVSS4.0

CVE-2020-37089 - School ERP Pro 1.0 - 'es_messagesid' SQL Injection

School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries through GET requests. Attackers can exploit the vulnerable parameter by injecting crafted SQL statements to potentially extract, modify, or delete database…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

8.7

CVSS4.0

CVE-2020-37088 - School ERP Pro 1.0 - Arbitrary File Read

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credential…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.
Total resulsts: 347837
Page 1685 of 34,784
Β« previous page Β» next page
Filters