|
1381
|
7.5 |
HIGH
Network
|
-
|
-
|
Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can quer…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-37220
|
2026-05-14 02:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1382
|
7.2 |
HIGH
Network
|
-
|
-
|
Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-37222
|
2026-05-14 02:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1383
|
7.8 |
HIGH
Local
|
-
|
-
|
IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a maliciou…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-37223
|
2026-05-14 02:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1384
|
7.1 |
HIGH
Network
|
-
|
-
|
Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
|
CWE-89
SQL Injection
|
CVE-2020-37224
|
2026-05-14 02:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1385
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-37225
|
2026-05-14 02:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1386
|
7.1 |
HIGH
Network
|
-
|
-
|
Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' parameter. Att…
|
CWE-89
SQL Injection
|
CVE-2020-37226
|
2026-05-14 02:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1387
|
5.5 |
MEDIUM
Local
|
jqlang
|
jq
|
jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two
otherwise valid modules include each other.
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-44777
|
2026-05-14 02:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1388
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displays an overly descriptive error message, including database-related details. Thi…
|
CWE-200
Information Exposure
|
CVE-2026-42871
|
2026-05-14 02:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1389
|
- |
|
-
|
-
|
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw was identified at the following endpoint: funcionario/profile_funcionario.php?…
|
CWE-79
Cross-site Scripting
|
CVE-2026-42870
|
2026-05-14 02:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1390
|
6.1 |
MEDIUM
Network
|
-
|
-
|
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) vulnerability exists in lista_arquivos_etapa.php due to improper handling of use…
|
CWE-79
Cross-site Scripting
|
CVE-2026-42872
|
2026-05-14 02:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|