8.7

CVSS4.0

CVE-2022-50899 - Geonetwork 4.2.0 - XML External Entity (XXE)

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files thrโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.6

CVSS4.0

CVE-2022-50898 - NanoCMS 0.4 - Remote Code Execution (RCE) (Authenticated)

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper inpuโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 2:16 p.m.

8.7

CVSS4.0

CVE-2022-50897 - mPDF 7.0 - Local File Inclusion

mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.8

CVSS4.0

CVE-2022-50895 - Aero CMS 0.0.1 - SQL Injection

Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the systeโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

5.1

CVSS4.0

CVE-2022-50891 - Owlfiles File Manager 12.0.1 Cross-Site Scripting via HTTP Server

Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the path parameter in HTTP server endpoints. Attackers can craft URLs targeting the download and list endpoints with embedded script tags to execute arbitrary JavaScrโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.7

CVSS4.0

CVE-2022-50890 - Owlfiles File Manager 12.0.1 - Path Traversal

Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the devโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.5

CVSS4.0

CVE-2022-50808 - CoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service Path

CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system rebooโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2022-50806 - 4images 1.9 - Remote Command Execution (RCE)

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoinโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.8

CVSS4.0

CVE-2022-50805 - Senayan Library Management System 9.0.0 - SQL Injection

Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL queries. Attackers can exploit the vulnerability by submitting crafted payloads to manipulate database queries and potentially extract sensitive infoโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2022-50693 - Splashtop 8.71.12001.0 - Unquoted Service Path

Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345219
Page 1755 of 34,522
ยซ previous page ยป next page
Filters