8.4

CVSS4.0

CVE-2020-37119 - Nsauditor 3.2.1.0 - Buffer Overflow (SEH+ASLR bypass (3 bytes overwrite))

Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute shellcode through a caref…

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: April 7, 2026, 2:05 p.m.

5.1

CVSS4.0

CVE-2020-37118 - P5 FNIP-8x16A FNIP-4xSH 1.0.20 - Cross-Site Request Forgery (Add Admin)

P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user interaction. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authent…

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2020-37117 - jizhiCMS 1.6.7 - Arbitrary File Download

jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url parameters to trigger un…

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: March 5, 2026, 1:28 a.m.

8.8

CVSS4.0

CVE-2020-37151 - phpMyChat Plus 1.98 'deluser.php' SQL Injection

phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to extract sensitive database i…

📅 Published: Feb. 5, 2026, 3:25 p.m. 🔄 Last Modified: Feb. 20, 2026, 3:41 p.m.

6.5

CVSS3.1

CVE-2025-14150 - IBM webMethods Integration Sever is affected by

IBM webMethods Integration (on prem) - Integration Server 10.15 through IS_10.15_Core_Fix2411.1 to IS_11.1_Core_Fix8 IBM webMethods Integration could disclose sensitive user information in server responses.

📅 Published: Feb. 5, 2026, 2:01 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS3.1

CVE-2025-13491 - IBM App Connect Enterprise Certified Container Information Disclosure

IBM App Connect Enterprise Certified Container CD: 11.2.0 through 11.6.0, 12.1.0 through 12.19.0 and 12.0 LTS: 12.0.0 through 12.0.19 could allow an attacker to access sensitive files or modify configurations due to an untrusted search path.

📅 Published: Feb. 5, 2026, 1:55 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-13379 - A SQL Injection vulnerability has been addressed in IBM Aspera Console

IBM Aspera Console 3.4.0 through 3.4.8 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

📅 Published: Feb. 5, 2026, 1:30 p.m. 🔄 Last Modified: Feb. 26, 2026, 3:04 p.m.

5.4

CVSS3.1

CVE-2026-1927 - GreenShift - Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Su…

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the greenshift_app_pass_validation() function in all versions up to, and including, 12.6. This makes it possible for authenticated attackers, wit…

📅 Published: Feb. 5, 2026, 1:27 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2026-1523 - Path Traversal in Digitek from Grupo Azkoyen

Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vulnerability allows an attacker to access arbitrary files in the server's file system, thet is, 'http://<host>/..%2F..% 2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd'. By manipul…

📅 Published: Feb. 5, 2026, 1:16 p.m. 🔄 Last Modified: April 18, 2026, 1:45 p.m.

5.1

CVSS4.0

CVE-2026-1517 - iomad Company Admin Block sql injection

A vulnerability was identified in iomad up to 5.0. Affected is an unknown function of the component Company Admin Block. Such manipulation leads to sql injection. The attack can be executed remotely. It is best practice to apply a patch to resolve this issue.

📅 Published: Feb. 5, 2026, 12:02 p.m. 🔄 Last Modified: April 18, 2026, 6:30 p.m.
Total resulsts: 345232
Page 1395 of 34,524
« previous page » next page
Filters