ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

11 results for “CVE-2020-3709”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-37095
Published
2026-02-06
CVSS:
8.4
ShadowTrackr CVSS:
5.7
Summary:
Cyberoam Authentication Client 2.1.2.7 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) memory. Attackers can craft a malicious input in the 'Cyberoam Server Address' field to trigger a bind TCP shell on port 1337 with system-level access.
CVE:
CVE-2020-37097
Published
2026-02-03
CVSS:
8.7
ShadowTrackr CVSS:
6.6
Summary:
Edimax EW-7438RPn 1.13 contains an information disclosure vulnerability that exposes WiFi network configuration details through the wlencrypt_wiz.asp file. Attackers can access the script to retrieve sensitive information including WiFi network name and plaintext password stored in device configuration variables.
CVE:
CVE-2020-37096
Published
2026-02-03
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Edimax EW-7438RPn 1.13 contains a cross-site request forgery vulnerability in the MAC filtering configuration interface. Attackers can craft malicious web pages to trick users into adding unauthorized MAC addresses to the device's filtering rules without their consent.
CVE:
CVE-2020-37093
Published
2026-02-03
CVSS:
8.7
ShadowTrackr CVSS:
6.6
Summary:
Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve WiFi passwords through the netcore_get.cgi endpoint. Attackers can send a GET request to the endpoint to extract sensitive network credentials including SSID and WiFi passwords in plain text.
CVE:
CVE-2020-37094
Published
2026-02-03
CVSS:
8.6
ShadowTrackr CVSS:
6.2
Summary:
EspoCRM 5.7.0 prior to 5.9.0 contains an authentication token reuse vulnerability that allows authenticated attackers to bypass two-factor authentication by exploiting token-to-password-hash mapping in application/Espo/Core/Utils/Authentication/Espo.php. Attackers can obtain an authentication token for a controlled account and replay it against any victim account sharing the same password, since tokens are bound to password hashes rather than unique per-user values, bypassing the victim's 2FA protections.
CVE:
CVE-2020-37092
Published
2026-02-03
CVSS:
9.3
ShadowTrackr CVSS:
8.1
Summary:
Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefined credentials. Attackers can leverage the embedded root account with a crackable password to gain full administrative access to the network device.
CVE:
CVE-2020-37091
Published
2026-02-03
CVSS:
5.1
ShadowTrackr CVSS:
1.2
Summary:
Maian Support Helpdesk 4.3 contains a cross-site request forgery vulnerability that allows attackers to create administrative accounts without authentication. Attackers can craft malicious HTML forms to add admin users and upload PHP files with unrestricted file upload capabilities through the FAQ attachment system.
CVE:
CVE-2020-37090
Published
2026-02-03
CVSS:
8.7
ShadowTrackr CVSS:
6.3
Summary:
School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.
CVE:
CVE-2020-37099
Published
2026-02-03
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Savvy Enterprise\bin\disksvs.exe' to inject malicious executables and escalate privileges.
CVE:
CVE-2020-37098
Published
2026-02-03
CVSS:
8.5
ShadowTrackr CVSS:
5.9
Summary:
Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.
CVE:
CVE-2020-3709
Published
2021-12-20
CVSS:
-
ShadowTrackr CVSS:
0.0
Summary: