5.1

CVSS4.0

CVE-2026-1700 - projectworlds House Rental and Property Listing sms.php cross site scripting

A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.php. This manipulation of the argument Message causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made a…

πŸ“… Published: Jan. 30, 2026, 5:02 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:10 a.m.

5.3

CVSS4.0

CVE-2026-1691 - bolo-solo SnakeYAML BackupService.java importMarkdownsSync deserialization

A vulnerability has been found in bolo-solo up to 2.6.4. This impacts the function importMarkdownsSync of the file src/main/java/org/b3log/solo/bolo/prop/BackupService.java of the component SnakeYAML. Such manipulation leads to deserialization. The attack may be launched remotely. The exploit has b…

πŸ“… Published: Jan. 30, 2026, 5:02 p.m. πŸ”„ Last Modified: March 3, 2026, 1:09 a.m.

5.1

CVSS4.0

CVE-2026-1690 - Tenda HG10 formSysCmd system command injection

A flaw has been found in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. This affects the function system of the file /boaform/formSysCmd. This manipulation of the argument sysCmd causes command injection. The attack may be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: Jan. 30, 2026, 4:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:10 a.m.

6.9

CVSS4.0

CVE-2026-1689 - Tenda HG10 Login formLogin checkUserFromLanOrWan command injection

A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the file /boaform/admin/formLogin of the component Login Interface. The manipulation of the argument Host results in command injection. The attack can be lau…

πŸ“… Published: Jan. 30, 2026, 4:32 p.m. πŸ”„ Last Modified: Feb. 23, 2026, 9:09 a.m.

8.5

CVSS4.0

CVE-2020-37060 - Atomic Alarm Clock x86 6.3 - 'AtomicAlarmClock' Unquoted Service Path

Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent sy…

πŸ“… Published: Jan. 30, 2026, 4:16 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 4:34 p.m.

8.5

CVSS4.0

CVE-2020-37059 - Popcorn Time 6.2 - 'Update service' Unquoted Service Path

Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level per…

πŸ“… Published: Jan. 30, 2026, 4:16 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

8.5

CVSS4.0

CVE-2020-37058 - Andrea ST Filters Service 1.0.64.7 - Unquoted service path

Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup.

πŸ“… Published: Jan. 30, 2026, 4:16 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 4:34 p.m.

8.5

CVSS4.0

CVE-2020-37030 - Outline Service 1.3.3 - 'Outline Service ' Unquoted Service Path

Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in C:\Program Files (x86)\Outline to inject malicious code that would execute with Loca…

πŸ“… Published: Jan. 30, 2026, 4:16 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

5.1

CVSS4.0

CVE-2020-37022 - OpenZ ERP 3.6.60 - Persistent Cross-Site Scripting

OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scripts through POST requests to , enabling session hijacking and manipulation of application modules.

πŸ“… Published: Jan. 30, 2026, 4:16 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

5.1

CVSS4.0

CVE-2020-37019 - Orchard Core RC1 - Persistent Cross-Site Scripting

Orchard Core RC1 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts through blog post creation. Attackers can create blog posts with embedded JavaScript in the MarkdownBodyPart.Source parameter to execute arbitrary scripts in victim bro…

πŸ“… Published: Jan. 30, 2026, 4:16 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.
Total resulsts: 344338
Page 1400 of 34,434
Β« previous page Β» next page
Filters