Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2020-37234 — Internet Download Manager 6.38.12 Scheduler Buffer Overflow

Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can …

internet_download_manager | Denial of Service
May 16, 2026 May 18, 2026
May 16, 2026
May 18, 2026
6.4 MEDIUM
CVE-2020-37233 — WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the fi…

buddypress_docs | Remote | Cross-Site Scripting
May 16, 2026 May 18, 2026
May 16, 2026
May 18, 2026
8.5 HIGH
CVE-2020-37232 — Advanced System Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation

Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Atta…

advanced_system_care | Misconfiguration
May 16, 2026 May 18, 2026
May 16, 2026
May 18, 2026
8.5 HIGH
CVE-2020-37231 — Privacy Drive 3.17.0 Unquoted Service Path Privilege Escalation

Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta…

| Misconfiguration
May 16, 2026 May 18, 2026
May 16, 2026
May 18, 2026
8.5 HIGH
CVE-2020-37230 — Syncplify.me Server! 5.0.37 Unquoted Service Path Privilege Escalation

Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path…

| Misconfiguration
May 16, 2026 May 18, 2026
May 16, 2026
May 18, 2026
8.5 HIGH
CVE-2020-37229 — OKI sPSV Port Manager 1.0.41 Unquoted Service Path Privilege Escalation

OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu…

| Misconfiguration
May 16, 2026 May 18, 2026
May 16, 2026
May 18, 2026
9.8 CRITICAL
CVE-2020-37228 — iDS6 DSSPro Digital Signage System 6.2 CAPTCHA Security Bypass

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retr…

Remote | Authentication
May 16, 2026 May 18, 2026
May 16, 2026
May 18, 2026
8.8 HIGH
CVE-2020-37227 — WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can…

Remote | Misconfiguration
May 16, 2026 May 18, 2026
May 16, 2026
May 18, 2026
Showing 20 of 6588 Results