Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2025-31990 — HCL DevOps Velocity is susceptible to a Denial of Service vulnerability

Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, over…

Remote | Denial of Service
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
9.0 HIGH
CVE-2026-2071 — UTT 进取 520W formP2PLimitConfig strcpy buffer overflow

A vulnerability was found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formP2PLimitConfig. Performing a manipulation of the argument except results in …

520w_firmware 520w | Remote | Memory Corruption
Feb 07, 2026 Feb 13, 2026
Feb 07, 2026
Feb 13, 2026
6.7 MEDIUM
CVE-2020-37171 — TapinRadio 2.12.3 - 'username' Denial of Service

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username…

tapinradio | Denial of Service
Feb 07, 2026 Feb 19, 2026
Feb 07, 2026
Feb 19, 2026
6.7 MEDIUM
CVE-2020-37170 — TapinRadio 2.12.3 - 'address' Denial of Service

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy address configuration that allows local attackers to crash the application. Attackers can overwrite the address f…

tapinradio | Denial of Service
Feb 07, 2026 Feb 19, 2026
Feb 07, 2026
Feb 19, 2026
6.9 MEDIUM
CVE-2020-37166 — AbsoluteTelnet 11.12 - 'SSH2/username' Denial of Service

AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attackers to crash the application. Attackers can overwrite the username field with …

absolutetelnet | Denial of Service
Feb 07, 2026 Feb 19, 2026
Feb 07, 2026
Feb 19, 2026
6.7 MEDIUM
CVE-2020-37165 — AbsoluteTelnet 11.12 - "license name" Denial of Service

AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character pa…

absolutetelnet | Denial of Service
Feb 07, 2026 Feb 19, 2026
Feb 07, 2026
Feb 19, 2026
6.7 MEDIUM
CVE-2020-37164 — AbsoluteTelnet 11.12 - "license entry" Denial of Service

AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character pa…

absolutetelnet | Denial of Service
Feb 07, 2026 Feb 19, 2026
Feb 07, 2026
Feb 19, 2026
8.8 HIGH
CVE-2020-37163 — QuickDate 1.3.2 - SQL Injection

QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries through the '_located' parameter in the find_matches endpoint. Attackers can inject …

Remote | Injection
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
9.8 CRITICAL
CVE-2020-37162 — Wedding Slideshow Studio 1.36 - 'Key' Buffer Overflow

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration key input that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malic…

wedding_slideshow_studio | Remote | Memory Corruption
Feb 07, 2026 Feb 24, 2026
Feb 07, 2026
Feb 24, 2026
9.8 CRITICAL
CVE-2020-37161 — Wedding Slideshow Studio 1.36 - 'Name' Buffer Overflow

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the registration name field with malicious payload. Attackers can…

wedding_slideshow_studio | Remote | Memory Corruption
Feb 07, 2026 Feb 24, 2026
Feb 07, 2026
Feb 24, 2026
8.5 HIGH
CVE-2020-37160 — SprintWork 2.3.1 - Local Privilege Escalation

SprintWork 2.3.1 contains multiple local privilege escalation vulnerabilities through insecure file, service, and folder permissions on Windows systems. Local unprivileged users can exploit missing e…

| Authorization
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
9.8 CRITICAL
CVE-2020-37159 — Cuckoo Clock 5.0 - Buffer Overflow

Parallaxis Cuckoo Clock 5.0 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory registers in the alarm scheduling feature. Attackers can cra…

Remote | Memory Corruption
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
8.7 HIGH
CVE-2020-37157 — DBPower C300 HD Camera - Remote Configuration Disclosure

DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. …

Remote | Information Disclosure
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
7.5 HIGH
CVE-2020-37155 — Core FTP Lite 1.3 - Denial of Service (PoC)

Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte …

Remote | Memory Corruption
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
7.1 HIGH
CVE-2020-37154 — eLection 2.0 - 'id' SQL Injection

eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can …

Remote | Injection
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
7.1 HIGH
CVE-2020-37147 — ATutor 2.2.4 - 'id' SQL Injection

ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploi…

atutor | Remote | Injection
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
8.7 HIGH
CVE-2020-37146 — Aptina AR0130 960P 1.3MP Camera - Remote Configuration Disclosure

ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's c…

Remote | Information Disclosure
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
8.8 HIGH
CVE-2020-37141 — AMSS++ v 4.31 - 'id' SQL Injection

AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/mai…

Remote | Injection
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
9.3 CRITICAL
CVE-2020-37135 — AMSS++ 4.7 - Backdoor Admin Account

AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username an…

amss\+\+ | Remote | Authentication
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
7.5 HIGH
CVE-2020-37122 — SpotFTP-FTP Password Recover 2.4.8 - Denial of Service

SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file wi…

Remote | Denial of Service
Feb 07, 2026 Feb 09, 2026
Feb 07, 2026
Feb 09, 2026
Showing 20 of 5089 Results