8.5

CVSS4.0

CVE-2020-37160 - SprintWork 2.3.1 - Local Privilege Escalation

SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing executable files and weak service configurations to create a new administrative user and gain completโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

8.4

CVSS4.0

CVE-2020-37159 - Cuckoo Clock 5.0 - Buffer Overflow

Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers in the alarm scheduling feature. Attackers can craft a malicious payload exceeding 260 bytes to overwrite EIP and EBP, enabling shellcode execution wiโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

8.7

CVSS4.0

CVE-2020-37157 - DBPower C300 HD Camera - Remote Configuration Disclosure

DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and password by accessiโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

6.7

CVSS4.0

CVE-2020-37155 - Core FTP Lite 1.3 - Denial of Service (PoC)

Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional inteโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

7.1

CVSS4.0

CVE-2020-37154 - eLection 2.0 - 'id' SQL Injection

eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can leverage SQLMap to exploit the vulnerability, potentially gaining remote code execution by uploadingโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

7

CVSS4.0

CVE-2020-37147 - ATutor 2.2.4 - 'id' SQL Injection

ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'id' parameter of the admin_delete.php โ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

8.7

CVSS4.0

CVE-2020-37146 - Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure

ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentialโ€ฆ

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

8.8

CVSS4.0

CVE-2020-37141 - AMSS++ v 4.31 - 'id' SQL Injection

AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify database contents.

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

9.3

CVSS4.0

CVE-2020-37135 - AMSS++ 4.7 - Backdoor Admin Account

AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.

6.7

CVSS4.0

CVE-2020-37122 - SpotFTP-FTP Password Recover 2.4.8 - Denial of Service

SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a registration code to trigger the application crash.

๐Ÿ“… Published: Feb. 6, 2026, 11:14 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 11:14 p.m.
Total resulsts: 331467
Page 2 of 33,147
ยซ previous page ยป next page
Filters