Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2021-47934 — MyBB Timeline Plugin 1.0 Cross-Site Scripting and CSRF

MyBB Timeline Plugin 1.0 contains cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through thread titles, post content, and user profile fields like Location and …

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37247 — Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation

Kite 4.2.0.1 U1 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to escalate privileges by exploiting the service binary path. Attackers …

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.9 MEDIUM
CVE-2020-37246 — WordPress Plugin Supsystic Backup 2.3.9 Local File Inclusion

Supsystic Backup 2.3.9 contains a local file inclusion vulnerability that allows unauthenticated attackers to read and delete arbitrary files by manipulating the download path parameter. Attackers ca…

| Path Traversal
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.7 HIGH
CVE-2020-37245 — WordPress Plugin Supsystic Digital Publications 1.6.9 Path Traversal XSS

Supsystic Digital Publications 1.6.9 contains a path traversal vulnerability in the Folder input field that allows attackers to access files outside the web root by injecting directory traversal sequ…

Remote | Path Traversal
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.8 HIGH
CVE-2020-37244 — WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx

Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' p…

Remote | Injection
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.8 HIGH
CVE-2020-37243 — WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl acti…

Remote | Injection
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.8 HIGH
CVE-2020-37242 — WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via sidx

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parame…

Remote | Injection
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.9 MEDIUM
CVE-2020-37241 — bloofoxCMS 0.5.2.1 Cross-Site Request Forgery via user add

bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malicious pages. Attackers can…

Remote | Cross-Site Request Forgery
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37240 — Queue Management System 4.0.0 Stored XSS via Add User

Queue Management System 4.0.0 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through user creation fields. Attackers can ins…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
9.8 CRITICAL
CVE-2020-37239 — libbabl 0.1.62 Broken Double Free Detection Memory Safety

libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_…

Remote | Memory Corruption
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37238 — CMS Made Simple 2.2.15 Stored XSS via SVG File Upload

CMS Made Simple 2.2.15 contains a stored cross-site scripting vulnerability that allows authenticated users with Content Manager access to inject malicious scripts through SVG file uploads. Attackers…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37237 — Composr CMS 10.0.34 Persistent Cross-Site Scripting via banners

Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers wi…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37236 — NewsLister Authenticated Persistent Cross-Site Scripting via Admin Panel

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news additio…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37235 — WordPress Theme Wibar 1.1.8 Stored Cross-Site Scripting via Brand Component

WordPress Theme Wibar 1.1.8 contains a stored cross-site scripting vulnerability in the Brand component that allows authenticated users to inject malicious scripts by manipulating the Logo URL parame…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.9 MEDIUM
CVE-2020-37234 — Internet Download Manager 6.38.12 Scheduler Buffer Overflow

Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can …

| Denial of Service
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
6.4 MEDIUM
CVE-2020-37233 — WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting

WordPress Plugin Buddypress 6.2.0 contains a persistent cross-site scripting vulnerability that allows authenticated attackers with moderator privileges to inject malicious script code through the fi…

Remote | Cross-Site Scripting
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37232 — Advanced System Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation

Advanced System Care Service 13.0.0.157 contains an unquoted service path vulnerability in the AdvancedSystemCareService13 service binary path that allows local attackers to escalate privileges. Atta…

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37231 — Privacy Drive 3.17.0 Unquoted Service Path Privilege Escalation

Privacy Drive 3.17.0 contains an unquoted service path vulnerability in the pdsvc.exe service binary that allows local attackers to escalate privileges by exploiting the service startup process. Atta…

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37230 — Syncplify.me Server! 5.0.37 Unquoted Service Path Privilege Escalation

Syncplify.me Server! 5.0.37 contains an unquoted service path vulnerability in the SMWebRestServicev5 service that allows local attackers to escalate privileges by exploiting the unquoted binary path…

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
8.5 HIGH
CVE-2020-37229 — OKI sPSV Port Manager 1.0.41 Unquoted Service Path Privilege Escalation

OKI sPSV Port Manager 1.0.41 contains an unquoted service path vulnerability in the sPSVOpLclSrv service that allows local attackers to escalate privileges by inserting executable files into the unqu…

| Misconfiguration
May 16, 2026 May 16, 2026
May 16, 2026
May 16, 2026
Showing 20 of 6252 Results