1
CVE-2026-1409 - Beetel 777VR1 UART excessive authentication
A security vulnerability has been detected in Beetel 777VR1 up to 01.00.09/01.00.09_55. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack on the physicaβ¦
1
CVE-2026-1408 - Beetel 777VR1 UART weak password
A weakness has been identified in Beetel 777VR1 up to 01.00.09/01.00.09_55. This vulnerability affects unknown code of the component UART Interface. Executing a manipulation can lead to weak password requirements. The physical device can be targeted for the attack. The attack requires a high level β¦
1
CVE-2026-1407 - Beetel 777VR1 UART information disclosure
A security flaw has been discovered in Beetel 777VR1 up to 01.00.09/01.00.09_55. This affects an unknown part of the component UART Interface. Performing a manipulation results in information disclosure. The attack may be carried out on the physical device. The attack is considered to have high comβ¦
8.5
CVE-2020-36937 - MEMU PLAY 3.7.0 - 'MEmusvc' Unquoted Service Path
Microvirt MEMU Play 3.7.0 contains an unquoted service path vulnerability in the MEmusvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with elevated LocalSystem priviβ¦
8.5
CVE-2020-36936 - Magic Mouse 2 utilities 2.20 - 'magicmouse2service' Unquoted Service Path
Magic Mouse 2 Utilities 2.20 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to inject malicious executables and gain elevated system privileges by placing a malicious file in the service path.
8.5
CVE-2020-36935 - KMSpico 17.1.0.0 - 'Service KMSELDI' Unquoted Service Path
KMSpico 17.1.0.0 contains an unquoted service path vulnerability in the Service KMSELDI configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\KMSpico\Service_KMS.exe to inject malicious executables and escβ¦
8.5
CVE-2020-36934 - Deep Instinct Windows Agent 1.2.24.0 - 'DeepNetworkService' Unquoted Service Path
Deep Instinct Windows Agent 1.2.24.0 contains an unquoted service path vulnerability in the DeepNetworkService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepNetworkService.exe to inject malβ¦
8.5
CVE-2020-36933 - IPTInstaller 4.0.9 - 'PassThru Service' Unquoted Service Path
HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges.
5.1
CVE-2020-36932 - Seacms 11.1 - 'checkuser' Stored XSS
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
5.1
CVE-2020-36931 - Click2Magic 1.1.5 - Stored Cross-Site Scripting
Click2Magic 1.1.5 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts in the chat name input. Attackers can craft a malicious payload in the chat name to capture administrator cookies when the admin processes user requests.