Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2020-37180 — GTalk Password Finder 2.2.1 - 'Key' Denial of Service

GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-charact…

Remote | Denial of Service
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.5 HIGH
CVE-2020-37179 — APKF Product Key Finder 2.5.8.0 - 'Name' Denial of Service

APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-characte…

Remote | Denial of Service
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.5 HIGH
CVE-2020-37178 — KeePass 2.44 - Denial of Service (PoC)

KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTM…

password_safe | Remote | Denial of Service
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.5 HIGH
CVE-2020-37177 — BOOTP Turbo 2.0 - Denial of Service (SEH)

BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious pay…

Remote | Memory Corruption
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2020-37176 — Torrent 3GP Converter 1.51 - Stack Overflow (SEH)

Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a m…

Remote | Memory Corruption
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
7.5 HIGH
CVE-2020-37175 — P2PWIFICAM2 for iOS 10.4.1 - 'Camera ID' Denial of Service

P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the Camera ID input field. Attackers can paste a 257-character buf…

Remote | Denial of Service
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
8.7 HIGH
CVE-2020-37173 — AVideo Platform 8.1 - Information Disclosure (User Enumeration)

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive …

avideo | Remote | Information Disclosure
Feb 11, 2026 Feb 18, 2026
Feb 11, 2026
Feb 18, 2026
9.8 CRITICAL
CVE-2020-37172 — AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)

AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requ…

avideo | Remote | Cross-Site Request Forgery
Feb 11, 2026 Feb 18, 2026
Feb 11, 2026
Feb 18, 2026
8.8 HIGH
CVE-2020-37158 — AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)

AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requ…

avideo | Remote | Cross-Site Request Forgery
Feb 11, 2026 Feb 20, 2026
Feb 11, 2026
Feb 20, 2026
6.9 MEDIUM
CVE-2020-37156 — BloodX 1.0 - Authentication Bypass

BloodX 1.0 contains an authentication bypass vulnerability in login.php that allows attackers to access the dashboard without valid credentials. Attackers can exploit the vulnerability by sending a c…

bloodx | Remote | Authentication
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
9.8 CRITICAL
CVE-2020-37153 — ASTPP VoIP 4.0.1 - Remote Code Execution

ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to i…

astpp | Remote | Cross-Site Scripting
Feb 11, 2026 Feb 20, 2026
Feb 11, 2026
Feb 20, 2026
8.7 HIGH
CVE-2020-37104 — ASTPP 4.0.1 VoIP Billing - Database Backup Download

ASTPP 4.0.1 contains an information disclosure vulnerability that allows unauthenticated attackers to download database backup files by predicting backup filename patterns. Attackers can generate a l…

astpp | Remote | Information Disclosure
Feb 11, 2026 Feb 20, 2026
Feb 11, 2026
Feb 20, 2026
5.1 MEDIUM
CVE-2019-25313 — FlexNet Publisher 11.12.1 - Cross-Site Request Forgery (Add Local Admin)

FlexNet Publisher 11.12.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without authentication. Attackers can craft a malicious HTML…

flexnet_publisher flexnet_publisher | Remote | Cross-Site Request Forgery
Feb 11, 2026 Feb 12, 2026
Feb 11, 2026
Feb 12, 2026
4.3 MEDIUM
CVE-2024-50618 — CIPPlanner CIPAce Single-Factor Authentication Bypass Vulnerability

A Use of Single-factor Authentication vulnerability in the Authentication component of CIPPlanner CIPAce before 9.17 allows attackers to bypass a protection mechanism. When the system is configured t…

cipace | Remote | Authentication
Feb 11, 2026 Feb 17, 2026
Feb 11, 2026
Feb 17, 2026
7.5 HIGH
CVE-2024-26480 — Statping-ng Information Disclosure

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the admin parameter.

statping-ng | Remote | Information Disclosure
Feb 11, 2026 Feb 28, 2026
Feb 11, 2026
Feb 28, 2026
5.3 MEDIUM
CVE-2024-26479 — Statping-ng Command Execution Information Disclosure

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the Command execution function.

statping-ng | Remote | Information Disclosure
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
5.3 MEDIUM
CVE-2024-26478 — Statping-ng Information Disclosure

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the /api/users endpoint.

statping-ng | Remote | Information Disclosure
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
7.5 HIGH
CVE-2024-26477 — Statping-ng Information Disclosure

An issue in Statping-ng v.0.91.0 allows an attacker to obtain sensitive information via a crafted request to the api parameter of the oauth, amazon_sns, export endpoints.

statping-ng | Remote | Information Disclosure
Feb 11, 2026 Feb 26, 2026
Feb 11, 2026
Feb 26, 2026
5.4 MEDIUM
CVE-2026-2323 — Google Chrome UI Spoofing Vulnerability

Inappropriate implementation in Downloads in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
5.4 MEDIUM
CVE-2026-2322 — Google Chrome UI Spoofing Vulnerability

Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafte…

linux_kernel chrome macos windows edge_chromium | Remote | Misconfiguration
Feb 11, 2026 Feb 13, 2026
Feb 11, 2026
Feb 13, 2026
Showing 20 of 5070 Results