Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2020-37244 — WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx

Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' p…

Remote | Injection
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.8 HIGH
CVE-2020-37243 — WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl acti…

Remote | Injection
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.8 HIGH
CVE-2020-37242 — WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via sidx

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parame…

Remote | Injection
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.9 MEDIUM
CVE-2020-37241 — bloofoxCMS 0.5.2.1 Cross-Site Request Forgery via user add

bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can…

Remote | Cross-Site Request Forgery
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37240 — Queue Management System 4.0.0 Stored XSS via Add User

Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can ins…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
9.8 CRITICAL
CVE-2020-37239 — libbabl 0.1.62 Broken Double Free Detection Memory Safety

libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_…

Remote | Memory Corruption
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37238 — CMS Made Simple 2.2.15 Stored XSS via SVG File Upload

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37237 — Composr CMS 10.0.34 Persistent Cross-Site Scripting via banners

Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37236 — NewsLister Authenticated Persistent Cross-Site Scripting via Admin Panel

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news additio…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37235 — WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parame…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.9 MEDIUM
CVE-2020-37234 — Internet Download Manager 6.38.12 Scheduler Buffer Overflow

Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can …

| Denial of Service
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37233 — WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the fi…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37232 — Advanced System Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation

Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Atta…

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37231 — Privacy Drive 3.17.0 Unquoted Service Path Privilege Escalation

Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta…

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37230 — Syncplify.me Server! 5.0.37 Unquoted Service Path Privilege Escalation

Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path…

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37229 — OKI sPSV Port Manager 1.0.41 Unquoted Service Path Privilege Escalation

OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu…

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
9.8 CRITICAL
CVE-2020-37228 — iDS6 DSSPro Digital Signage System 6.2 CAPTCHA Security Bypass

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retr…

Remote | Authentication
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.8 HIGH
CVE-2020-37227 — WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can…

Remote | Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
0.0 NA
CVE-2026-46719 — Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections

Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject add…

| Injection
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
4.3 MEDIUM
CVE-2025-4202 — Multicollab: Content Team Collaboration and Editorial Workflow <= 5.2 - Missing Authoriza…

The Multicollab: Content Team Collaboration and Editorial Workflow plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf_add_comment' fu…

Remote | Authorization
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
Showing 20 of 6215 Results