9.4

CVSS3.1

CVE-2026-24858 -

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager …

πŸ“… Published: Jan. 27, 2026, 7:18 p.m. πŸ”„ Last Modified: March 23, 2026, 5:23 p.m.

4.8

CVSS3.1

CVE-2026-24398 - Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, IP Restriction Middleware in Hono is vulnerable to an IP address validation bypass. The `IPV4_REGEX` pattern and `convertIPv4ToBinary` function in `src/utils/ipaddr.ts` do not properly val…

πŸ“… Published: Jan. 27, 2026, 7:06 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 3:34 p.m.

4.1

CVSS4.0

CVE-2026-24116 - Wasmtime segfault or unused out-of-sandbox load with f64.copysign operator on x86-64

Wasmtime is a runtime for WebAssembly. Starting in version 29.0.0 and prior to version 36.0.5, 40.0.3, and 41.0.1, on x86-64 platforms with AVX, Wasmtime's compilation of the `f64.copysign` WebAssembly instruction with Cranelift may load 8 more bytes than is necessary. When signals-based-traps are …

πŸ“… Published: Jan. 27, 2026, 6:58 p.m. πŸ”„ Last Modified: Feb. 12, 2026, 9:36 p.m.

8.5

CVSS4.0

CVE-2020-36983 - Quick 'n Easy FTP Service 3.2 - Unquoted Service Path

Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code during service startup. Attackers can exploit the misconfigured service binary path to inject malicious executables with elevated LocalSystem privileges during system …

πŸ“… Published: Jan. 27, 2026, 6:52 p.m. πŸ”„ Last Modified: April 7, 2026, 2:05 p.m.

8.5

CVSS4.0

CVE-2020-36982 - Motorola Device Manager 2.5.4 - 'MotoHelperService.exe' Unquoted Service Path

Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperService.exe service that allows local users to potentially inject malicious code. Attackers can exploit the unquoted path in the service configuration to execute arbitrary code with elevated system privil…

πŸ“… Published: Jan. 27, 2026, 6:51 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 4:31 p.m.

8.5

CVSS4.0

CVE-2020-36981 - Motorola Device Manager 2.4.5 - 'ForwardDaemon.exe ' Unquoted Service Path

Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in ForwardDaemon.exe to inject malicious code that will execute with elevated system privileges dur…

πŸ“… Published: Jan. 27, 2026, 6:51 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 4:31 p.m.

8.5

CVSS4.0

CVE-2020-36980 - SAntivirus IC 10.0.21.61 - 'SAntivirusIC' Unquoted Service Path

SAntivirus IC 10.0.21.61 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted executable path to inject malicious files in the service binary path, enabling privileg…

πŸ“… Published: Jan. 27, 2026, 6:51 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 4:31 p.m.

8.5

CVSS4.0

CVE-2020-36979 - Atheros Coex Service Application 8.0.0.255 -'ZAtheros Bt&Wlan Coex Agent' Unquoted Service Path

Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.

πŸ“… Published: Jan. 27, 2026, 6:51 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 5:16 p.m.

5.1

CVSS4.0

CVE-2020-36978 - Froxlor Froxlor Server Management Panel 0.10.16 - Persistent Cross-Site Scripting

Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules.

πŸ“… Published: Jan. 27, 2026, 6:51 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

8.5

CVSS4.0

CVE-2020-36977 - Wondershare Driver Install Service help 10.7.1.321 - 'ElevationService' Unquote Service Path

Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privile…

πŸ“… Published: Jan. 27, 2026, 6:51 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 5:16 p.m.
Total resulsts: 343968
Page 1405 of 34,397
Β« previous page Β» next page
Filters