
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-36951 | Published 2026-01-27 | CVSS: 8.8 | ShadowTrackr CVSS: 6.7 | Summary: Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vulnerability in the admin interface that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit this vulnerability by crafting malicious payloads that trigger time delays, enabling them to extract sensitive database information through conditional sleep techniques. |
CVE: CVE-2020-36950 | Published 2026-01-27 | CVSS: 8.7 | ShadowTrackr CVSS: 6.6 | Summary: Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server. |
CVE: CVE-2020-36959 | Published 2026-01-26 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: IDT PC Audio 1.0.6499.0 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the STacSV service to inject malicious code that would execute with LocalSystem account permissions during service startup. |
CVE: CVE-2020-36958 | Published 2026-01-26 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: Kite 1.2020.1119.0 contains an unquoted service path vulnerability in the KiteService Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Kite\KiteService.exe' to inject malicious executables and escalate privileges on the system. |
CVE: CVE-2020-36957 | Published 2026-01-26 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: PDF Complete 3.5.310.2002 contains an unquoted service path vulnerability in its pdfsvc.exe service configuration. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges. |
CVE: CVE-2020-36956 | Published 2026-01-26 | CVSS: 5.1 | ShadowTrackr CVSS: 1.2 | Summary: Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration page. |
CVE: CVE-2020-36955 | Published 2026-01-26 | CVSS: 5.1 | ShadowTrackr CVSS: 1.2 | Summary: Grav CMS 1.6.30 with Admin Plugin 1.9.18 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the page title field. Attackers can create a new page with a malicious script in the title, which will be executed when the page is viewed in the admin panel or on the site. |
CVE: CVE-2020-36954 | Published 2026-01-26 | CVSS: 5.1 | ShadowTrackr CVSS: 1.2 | Summary: Xeroneit Library Management System 3.1 contains a stored cross-site scripting vulnerability in the Book Category feature that allows administrators to inject malicious scripts. Attackers can insert a payload in the Category Name field to execute arbitrary JavaScript code when the page is loaded. |
CVE: CVE-2020-36953 | Published 2026-01-26 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: MiniTool ShadowMaker 3.2 contains an unquoted service path vulnerability in the MTAgentService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\MiniTool ShadowMaker\AgentService.exe' to inject malicious executables and escalate privileges. |
CVE: CVE-2020-36952 | Published 2026-01-26 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during service startup. |
CVE: CVE-2020-3695 | Published 2021-12-20 | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |