
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-37087 | Published 2026-02-03 | CVSS: 5.1 | ShadowTrackr CVSS: 1.2 | Summary: Easy Transfer Wifi Transfer v1.7 for iOS contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious scripts by manipulating the oldPath, newPath, and path parameters in Create Folder and Move/Edit functions. Attackers can exploit improper input validation via POST requests to execute arbitrary JavaScript in the context of the mobile web application. |
CVE: CVE-2020-37084 | Published 2026-02-03 | CVSS: 8.6 | ShadowTrackr CVSS: 6.1 | Summary: School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile photos by bypassing file extension checks. Attackers can exploit improper file validation in pre-editstudent.inc.php to execute arbitrary code on the server. |
CVE: CVE-2020-37089 | Published 2026-02-03 | CVSS: 7.1 | ShadowTrackr CVSS: 5.0 | Summary: School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries through GET requests. Attackers can exploit the vulnerable parameter by injecting crafted SQL statements to potentially extract, modify, or delete database information. |
CVE: CVE-2020-37088 | Published 2026-02-03 | CVSS: 8.7 | ShadowTrackr CVSS: 6.6 | Summary: School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information. |
CVE: CVE-2020-37086 | Published 2026-02-03 | CVSS: 6.9 | ShadowTrackr CVSS: 4.6 | Summary: Easy Transfer 1.7 iOS mobile application contains a directory traversal vulnerability that allows remote attackers to access unauthorized file system paths without authentication. Attackers can exploit the vulnerability by manipulating path parameters in GET and POST requests to list or download sensitive system files and inject malicious scripts into application parameters. |
CVE: CVE-2020-37085 | Published 2026-02-03 | CVSS: 8.7 | ShadowTrackr CVSS: 6.6 | Summary: VirtualTablet Server 3.0.2 contains a denial of service vulnerability that allows attackers to crash the service by sending oversized string payloads through the Thrift protocol. Attackers can exploit the vulnerability by sending a long string to the send_say() method, causing the server to become unresponsive. |
CVE: CVE-2020-37083 | Published 2026-02-03 | CVSS: 8.8 | ShadowTrackr CVSS: 6.7 | Summary: PHP AddressBook 9.0.0.1 contains a time-based blind SQL injection vulnerability that allows remote attackers to manipulate database queries through the 'id' parameter. Attackers can inject crafted SQL statements with time delays to extract information by observing response times in the photo.php endpoint. |
CVE: CVE-2020-37082 | Published 2026-02-03 | CVSS: 8.6 | ShadowTrackr CVSS: 6.2 | Summary: webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].sql.gz file. |
CVE: CVE-2020-37080 | Published 2026-02-03 | CVSS: 7.2 | ShadowTrackr CVSS: 5.1 | Summary: webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on the server through an unauthenticated file deletion mechanism. |
CVE: CVE-2020-37081 | Published 2026-02-03 | CVSS: 7.1 | ShadowTrackr CVSS: 5.0 | Summary: Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calendar.php that allow attackers to inject malicious SQL commands. Attackers can exploit vulnerable parameters like uid, pid, type, m, y, and code to compromise the database management system and web application without user interaction. |
CVE: CVE-2020-3708 | Published 2021-12-20 | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |