8.7

CVSS4.0

CVE-2020-37088 - School ERP Pro 1.0 - Arbitrary File Read

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credential…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

6.9

CVSS4.0

CVE-2020-37086 - Easy Transfer 1.7 for iOS - Directory Traversal

Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to access unauthorized file system paths without authentication. Attackers can exploit the vulnerability by manipulating path parameters in GET and POST requests to list or download se…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2020-37085 - VirtualTablet Server 3.0.2 - Denial of Service (PoC)

VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by sending oversized string payloads through the Thrift protocol. Attackers can exploit the vulnerability by sending a long string to the send_say() method, causing the server to become …

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2020-37083 - addressbook 9.0.0.1 - 'id' SQL Injection

PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through the 'id' parameter. Attackers can inject crafted SQL statements with time delays to extract information by observing response times in the photo.php en…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2020-37082 - webERP 4.15.1 - Unauthenticated Backup File Access

webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].sql.gz file.

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

7.1

CVSS4.0

CVE-2020-37081 - Fishing Reservation System 7.5 - 'uid' SQL Injection

Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calendar.php that allow attackers to inject malicious SQL commands. Attackers can exploit vulnerable parameters like uid, pid, type, m, y, and code to compromise the database management…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS4.0

CVE-2020-37080 - webTareas 2.0.p8 - Arbitrary File Deletion

webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on the server through a…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.2

CVSS4.0

CVE-2020-37078 - i-doit Open Source CMDB 1.14.1 - Arbitrary File Deletion

i-doit Open Source CMDB 1.14.1 contains a file deletion vulnerability in the import module that allows authenticated attackers to delete arbitrary files by manipulating the delete_import parameter. Attackers can send a POST request to the import module with a crafted filename to remove files from t…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2020-37077 - Booked Scheduler 2.7.7 - Authenticated Directory Traversal

Booked Scheduler 2.7.7 contains a directory traversal vulnerability in the manage_email_templates.php script that allows authenticated administrators to access unauthorized files. Attackers can exploit the vulnerable 'tn' parameter to read files outside the intended directory by manipulating direct…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2020-37076 - Victor CMS 1.0 - 'post' SQL Injection

Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, err…

πŸ“… Published: Feb. 3, 2026, 10:01 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 2:53 p.m.
Total resulsts: 346102
Page 1513 of 34,611
Β« previous page Β» next page
Filters