7.1

CVSS4.0

CVE-2020-36968 - M/Monit 3.7.4 - Password Disclosure

M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5 password hashes for all …

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

8.4

CVSS4.0

CVE-2020-36967 - Zortam Mp3 Media Studio 27.60 - Remote Code Execution (SEH)

Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process that allows remote code execution. Attackers can craft a malicious text file with shellcode to trigger a structured exception handler (SEH) overwrite and execute arbitrary commands …

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2020-36965 - docPrint Pro 8.0 - 'Add URL' Buffer Overflow (SEH Egghunter)

docPrint Pro 8.0 contains a local buffer overflow vulnerability in the 'Add URL' input field that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload that triggers a structured exception handler (SEH) overwrite to execute shellcode and gain remo…

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2020-36964 - YATinyWinFTP - Denial of Service

YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service crash.

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2020-36963 - Intelbras Router RF 301K 1.1.2 - Authentication Bypass

Intelbras Router RF 301K firmware version 1.1.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to download router configuration files. Attackers can send a specific HTTP GET request to /cgi-bin/DownloadCfg/RouterCfm.cfg to retrieve sensitive router configurati…

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2020-36962 - Tendenci 12.3.1 - CSV/ Formula Injection

Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary command execution when t…

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

8.4

CVSS4.0

CVE-2020-36961 - 10-Strike Network Inventory Explorer 8.65 - Buffer Overflow (SEH)

10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception Handler to trigger code ex…

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2020-36945 - WebDamn User Registration & Login System with User Panel - SQLi Auth Bypass

WebDamn User Registration Login System contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login authentication by manipulating email credentials. Attackers can inject the payload '<email>' OR '1'='1' in both username and password fields to gain unauthorized acces…

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2020-36944 - ILIAS Learning Management System 4.3 - SSRF

ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local file contents when the portfolio is exported to PD…

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

6.7

CVSS4.0

CVE-2020-36943 - aSc TimeTables 2021.6.2 - Denial of Service

aSc TimeTables 2021.6.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting subject title fields with excessive data. Attackers can generate a 10,000-character buffer and paste it into the subject title to trigger application instability and pote…

πŸ“… Published: Jan. 28, 2026, 5:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1908 of 34,919
Β« previous page Β» next page
Filters