Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

760
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,001 - 1,020 of 27,228 CVEs
CVE-2020-37246 MEDIUM - 6.2

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers can modify the download parameter in admin.php requests with directory traversal sequences to access se...

Vendor: Supsystic
Product: Backup
Published: May 16, 2026
Source: NVD
CVE-2020-37245 HIGH - 7.5

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequences. Additionally, the plugin fails to sanitize input fields in publication settings, allowing stor...

Vendor: Supsystic
Product: Digital Publications
Published: May 16, 2026
Source: NVD
CVE-2020-37244 HIGH - 8.2

Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payl...

Vendor: Supsystic
Product: Membership
Published: May 16, 2026
Source: NVD
CVE-2020-37243 HIGH - 8.2

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also contains stored cross-site scripting vulnerabilities in the 'Edit ...

Vendor: Supsystic
Product: Pricing Table
Published: May 16, 2026
Source: NVD
CVE-2020-37242 HIGH - 8.2

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based bli...

Vendor: Supsystic
Product: Ultimate Maps
Published: May 16, 2026
Source: NVD
CVE-2020-37241 MEDIUM - 5.3

bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can craft hidden forms targeting the admin user creation endpoint to add new administrative accounts wit...

Vendor: Bloofox
Product: bloofoxCMS
Published: May 16, 2026
Source: NVD
CVE-2020-37240 MEDIUM - 6.4

Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can insert JavaScript payloads in the First Name, Last Name, and Email fields during user creation, which ex...

Vendor: Codekernel
Product: Queue Management System
Published: May 16, 2026
Source: NVD
CVE-2020-37239 CRITICAL - 9.8

libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without triggering detection, as libc's malloc metadata overwri...

Vendor: Gegl
Product: libbabl
Published: May 16, 2026
Source: NVD
CVE-2020-37238 MEDIUM - 6.4

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers can upload SVG files containing embedded JavaScript to the file manager, which executes when other a...

Vendor: Cmsmadesimple
Product: CMS Made Simple
Published: May 16, 2026
Source: NVD
CVE-2020-37237 MEDIUM - 6.4

Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers with admin credentials can inject XSS payloads in the Description field of the Add banner functionality...

Vendor: Compo
Product: Composr CMS
Published: May 16, 2026
Source: NVD
CVE-2020-37236 MEDIUM - 6.4

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news addition interface. Attackers can inject JavaScript payloads via the title field in the admin panel that exe...

Vendor: Netartmedia
Product: NewsLister
Published: May 16, 2026
Source: NVD
CVE-2020-37235 MEDIUM - 6.4

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parameter. Attackers with editor, administrator, contributor, or author privileges can inject base64-encode...

Vendor: themeftc
Product: Theme Wibar
Published: May 16, 2026
Source: NVD
CVE-2020-37234 MEDIUM - 6.2

Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' fiel...

Vendor: Internetdownloadmanager
Product: Internet Download Manager
Published: May 16, 2026
Source: NVD
CVE-2020-37233 MEDIUM - 6.4

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the figure parameter in wp:html blocks. Attackers can inject iframe elements with event handlers like onloa...

Vendor: Wordpress
Product: Buddypress
Published: May 16, 2026
Source: NVD
CVE-2020-37232 HIGH - 7.8

Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Attackers can place malicious executables in the system root path that will be executed with LocalSystem ...

Vendor: Iobit
Product: Advanced System Care Service
Published: May 16, 2026
Source: NVD
CVE-2020-37231 HIGH - 7.8

Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Attackers can place malicious executables in the unquoted path directories to execute arbitrary code with...

Vendor: Cybertronsoft
Product: Privacy Drive
Published: May 16, 2026
Source: NVD
CVE-2020-37230 HIGH - 7.8

Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path. Attackers can insert a malicious executable into the service path and execute it with LocalSystem p...

Vendor: Syncplify
Product: Syncplify.me Server!
Published: May 16, 2026
Source: NVD
CVE-2020-37229 HIGH - 7.8

OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unquoted path. Attackers can place a malicious executable in a directory within the service path that wil...

Vendor: Oki
Product: OKI sPSV Port Manager
Published: May 16, 2026
Source: NVD
CVE-2020-37228 CRITICAL - 9.8

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against u...

Vendor: Yerootech
Product: iDS6 DSSPro Digital Signage System
Published: May 16, 2026
Source: NVD
CVE-2020-37227 HIGH - 8.8

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to exe...

Vendor: Heliossolutions
Product: HS Brand Logo Slider
Published: May 16, 2026
Source: NVD