7.3

CVSS3.1

CVE-2026-25156 - HotCRP vulnerable to stored XSS via comment attachments

HotCRP is conference review software. HotCRP versions from October 2025 through January 2026 delivered documents of all types with inline Content-Disposition, causing them to be rendered in the user’s browser rather than downloaded. (The intended behavior was for only `text/plain`, `application/pdf…

πŸ“… Published: Jan. 30, 2026, 10:11 p.m. πŸ”„ Last Modified: April 18, 2026, 2:30 p.m.

8.8

CVSS4.0

CVE-2020-37057 - Online-Exam-System 2015 - 'fid' SQL Injection

Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information.

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: March 12, 2026, 6:50 p.m.

6.9

CVSS4.0

CVE-2020-37056 - Crystal Shard http-protection 0.2.0 - IP Spoofing Bypass

Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and g…

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2020-37054 - Navigate CMS 2.8.7 - Cross-Site Request Forgery

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without ad…

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

7.1

CVSS4.0

CVE-2020-37053 - Navigate CMS 2.8.7 - ''sidx' SQL Injection

Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, p…

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: March 5, 2026, 1:27 a.m.

9.3

CVSS4.0

CVE-2020-37052 - AirControl 1.4.2 - PreAuth Remote Code Execution

AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded …

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS4.0

CVE-2020-37051 - Online-Exam-System 2015 - 'feedback' SQL Injection

Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user …

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: March 12, 2026, 6:49 p.m.

8.4

CVSS4.0

CVE-2020-37050 - Quick Player 1.3 - '.m3l' Buffer Overflow

Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with carefully constructed payload. Attackers can trigger the vulnerability by loading a specially crafted file through the application's file loading mechanis…

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2020-37049 - Frigate 3.36.0.9 - 'Command Line' Local Buffer Overflow

Frigate 3.36.0.9 contains a local buffer overflow vulnerability in the Command Line input field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload to overflow the buffer, bypass DEP, and execute commands like launching calc.exe through a specially crafted input…

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2020-37046 - Sistem Informasi Pengumuman Kelulusan Online 1.0 - Cross-Site Request Forgery

Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin users through the tambahuser.php endpoint. Attackers can craft a malicious HTML form to submit admin credentials and create new administrative account…

πŸ“… Published: Jan. 30, 2026, 10:07 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 1876 of 34,919
Β« previous page Β» next page
Filters