8.4

CVSS4.0

CVE-2021-47779 - Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the tex…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: April 7, 2026, 2:06 p.m.

8.4

CVSS4.0

CVE-2021-47756 - Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)

Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root permissions without additional authentication.

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2020-36930 - SysGauge 7.9.18 - ' SysGauge Server' Unquoted Service Path

SysGauge Server 7.9.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\SysGauge Server\bin\sysgaus.exe' to inject malicious executables an…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: March 5, 2026, 1:26 a.m.

8.5

CVSS4.0

CVE-2020-36929 - Brother BRPrint Auditor 3.0.7 - 'Multiple' Unquoted Service Path

Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted file paths in BrAuSvc and BRPA_Agent services to inject malicious executables and…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: Feb. 9, 2026, 3:02 p.m.

8.5

CVSS4.0

CVE-2020-36928 - Brother BRAgent 1.38 - 'WBA_Agent_Client' Unquoted Service Path

Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: Feb. 9, 2026, 3:04 p.m.

8.5

CVSS4.0

CVE-2020-36927 - DiskPulse 13.6.14 - Unquoted Service Path

DiskPulse Enterprise 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Pulse Enterprise\bin\diskpls.exe' to inject maliciou…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: March 5, 2026, 1:26 a.m.

6.9

CVSS4.0

CVE-2020-36926 - SmarterTools SmarterTrack 7922 -Information Disclosure

SmarterTrack 7922 contains an information disclosure vulnerability in the Chat Management search form that reveals agent identification details. Attackers can access the vulnerable /Management/Chat/frmChatSearch.aspx endpoint to retrieve agents' first and last names along with their unique identifi…

📅 Published: Jan. 15, 2026, 11:25 p.m. 🔄 Last Modified: April 7, 2026, 2:05 p.m.

6.1

CVSS3.1

CVE-2026-1011 - Stored Cross-Site Scripting in Altium Live Support Center Comment Endpoint

A stored cross-site scripting (XSS) vulnerability exists in the Altium Support Center AddComment endpoint due to missing server-side input sanitization. Although the client interface applies HTML escaping, the backend accepts and stores arbitrary HTML and JavaScript supplied via modified POST reque…

📅 Published: Jan. 15, 2026, 11:08 p.m. 🔄 Last Modified: April 18, 2026, 7:15 p.m.

8

CVSS3.1

CVE-2026-1010 - Stored Cross-Site Scripting in Altium Enterprise Server Workflow Engine Allows Privilege Escalation

A stored cross-site scripting (XSS) vulnerability exists in the Altium Workflow Engine due to missing server-side input sanitization in workflow form submission APIs. A regular authenticated user can inject arbitrary JavaScript into workflow data. When an administrator views the affected workflow,…

📅 Published: Jan. 15, 2026, 11 p.m. 🔄 Last Modified: April 18, 2026, 6 a.m.

8.1

CVSS3.1

CVE-2026-22864 - Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension…

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefo…

📅 Published: Jan. 15, 2026, 10:58 p.m. 🔄 Last Modified: April 18, 2026, 6 a.m.
Total resulsts: 349182
Page 2108 of 34,919
« previous page » next page
Filters