
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-36973 | Published 2026-01-28 | CVSS: 8.7 | ShadowTrackr CVSS: 6.3 | Summary: PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques. |
CVE: CVE-2020-36970 | Published 2026-01-28 | CVSS: 6.9 | ShadowTrackr CVSS: 4.6 | Summary: PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint. |
CVE: CVE-2020-36972 | Published 2026-01-28 | CVSS: 8.8 | ShadowTrackr CVSS: 6.7 | Summary: SmartBlog 2.0.1 contains a blind SQL injection vulnerability in the 'id_post' parameter of the details controller that allows attackers to extract database information. Attackers can systematically test and retrieve database contents by injecting crafted SQL queries that compare character-by-character of database information. |
CVE: CVE-2020-36971 | Published 2026-01-28 | CVSS: 8.4 | ShadowTrackr CVSS: 5.7 | Summary: Nidesoft 3GP Video Converter 2.6.18 contains a local stack buffer overflow vulnerability in the license registration parameter. Attackers can craft a malicious payload and paste it into the 'License Code' field to execute arbitrary code on the system. |
CVE: CVE-2020-36978 | Published 2026-01-27 | CVSS: 5.1 | ShadowTrackr CVSS: 1.2 | Summary: Froxlor Server Management Panel 0.10.16 contains a persistent cross-site scripting vulnerability in customer registration input fields. Attackers can inject malicious scripts through username, name, and firstname parameters to execute code when administrators view customer traffic modules. |
CVE: CVE-2020-36979 | Published 2026-01-27 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup. |
CVE: CVE-2020-36977 | Published 2026-01-27 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to LocalSystem account. |
CVE: CVE-2020-36976 | Published 2026-01-27 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup. |
CVE: CVE-2020-36975 | Published 2026-01-27 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common Files\EPSON\EPW!3SSRP\E_S60RPB.EXE' to inject malicious executables and escalate privileges. |
CVE: CVE-2020-36974 | Published 2026-01-27 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files\IDT\WDM\AESTSr64.exe' to inject malicious code that would execute during service startup or system reboot. |
CVE: CVE-2020-3697 | Published 2021-12-20 | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |