7

CVSS4.0

CVE-2025-13905 -

CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.

πŸ“… Published: Jan. 29, 2026, 3:20 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2025-7714 - Time Based SQLi in Global Medya's PHP CMS

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows Command Line Execution through SQL Injection.This issue affects Content Management System (CMS): through 2107202…

πŸ“… Published: Jan. 29, 2026, 2:44 p.m. πŸ”„ Last Modified: March 10, 2026, 5:56 p.m.

7.5

CVSS3.1

CVE-2025-7713 - Reflected XSS in Global Medya's PHP CMS

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Interactive Design Media Software Inc. Content Management System (CMS) allows XSS Through HTTP Headers.This issue affects Content Management System (CMS): through 21072025.

πŸ“… Published: Jan. 29, 2026, 2:38 p.m. πŸ”„ Last Modified: March 10, 2026, 5:55 p.m.

6.9

CVSS4.0

CVE-2026-1594 - itsourcecode Society Management System add_expenses.php sql injection

A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_expenses.php. The manipulation of the argument detail leads to sql injection. Remote exploitation of the attack is possible. The expl…

πŸ“… Published: Jan. 29, 2026, 2:32 p.m. πŸ”„ Last Modified: April 18, 2026, 6:45 p.m.

6.9

CVSS4.0

CVE-2026-1593 - itsourcecode Society Management System edit_expenses_query.php sql injection

A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit_expenses_query.php. Executing a manipulation of the argument detail can lead to sql injection. The attack may be launched remotely. The ex…

πŸ“… Published: Jan. 29, 2026, 2:32 p.m. πŸ”„ Last Modified: April 18, 2026, 6:45 p.m.

8.5

CVSS4.0

CVE-2020-37021 - Bandwidth Monitor 3.9 - 'Svc10StrikeBandMontitor' Unquoted Service Path

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

πŸ“… Published: Jan. 29, 2026, 2:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2020-37020 - SonarQube 8.3.1 - Unquoted Service Path

SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges durin…

πŸ“… Published: Jan. 29, 2026, 2:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2020-37018 - GOautodial 4.0 - Persistent Cross-Site Scripting

GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing sessio…

πŸ“… Published: Jan. 29, 2026, 2:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2020-37017 - CodeMeter 6.60 - 'CodeMeter.exe' Unquoted Service Path

CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CodeMeter Runtime Server service to inject malicious code that would execute with Local…

πŸ“… Published: Jan. 29, 2026, 2:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2020-37016 - BarcodeOCR 19.3.6 - 'BarcodeOCR' Unquoted Service Path

BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with elevated privileges during system startup. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will run with LocalSystem privilege…

πŸ“… Published: Jan. 29, 2026, 2:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1893 of 34,919
Β« previous page Β» next page
Filters