ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

11 results for “CVE-2020-3705”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37055
Published
2026-02-01
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations to gain elevated access during service startup.
CVE:
CVE-2020-37057
Published
2026-01-30
CVSS:
8.8
ShadowTrackr CVSS:
6.7
Summary:
Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information.
CVE:
CVE-2020-37053
Published
2026-01-30
CVSS:
7.1
ShadowTrackr CVSS:
5.0
Summary:
Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability that allows attackers to leak database information by manipulating the 'sidx' parameter in comments. Attackers can exploit the vulnerability to extract user activation keys by using time-based blind SQL injection techniques, potentially enabling password reset for administrative accounts.
CVE:
CVE-2020-37056
Published
2026-01-30
CVSS:
6.9
ShadowTrackr CVSS:
2.7
Summary:
Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized access.
CVE:
CVE-2020-37054
Published
2026-01-30
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML page. Attackers can trick authenticated administrators into executing arbitrary file uploads by leveraging the extension upload functionality without additional validation.
CVE:
CVE-2020-37052
Published
2026-01-30
CVSS:
9.3
ShadowTrackr CVSS:
8.1
Summary:
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to run commands with the application's system privileges.
CVE:
CVE-2020-37051
Published
2026-01-30
CVSS:
8.8
ShadowTrackr CVSS:
6.7
Summary:
Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.
CVE:
CVE-2020-37050
Published
2026-01-30
CVSS:
8.4
ShadowTrackr CVSS:
5.7
Summary:
Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with carefully constructed payload. Attackers can trigger the vulnerability by loading a specially crafted file through the application's file loading mechanism, potentially enabling remote code execution.
CVE:
CVE-2020-37059
Published
2026-01-30
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed with SYSTEM-level permissions during service startup.
CVE:
CVE-2020-37058
Published
2026-01-30
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup.
CVE:
CVE-2020-3705
Published
2021-12-20
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary: