5.1

CVSS4.0

CVE-2023-54341 - Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) via file Parameter

Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScr…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.8

CVSS4.0

CVE-2023-54340 - WorkOrder CMS 0.1.0 - SQL Injection

WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by manipulating username and password parameters. Attackers can inject malicious SQL queries using techniques like OR '1'='1' and stacked queries to access database information or execut…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2023-54339 - Webgrind 1.1 - Remote Command Execution (RCE) via dataFile Parameter

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' t…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.5

CVSS4.0

CVE-2023-54338 - Tftpd32_SE 4.60 - 'Tftpd32_svc' Unquoted Service Path

Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permiss…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2023-54337 - Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)

Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.5

CVSS4.0

CVE-2023-54336 - Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with L…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2023-54335 - eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: April 7, 2026, 2:08 p.m.

7

CVSS4.0

CVE-2023-54334 - Explorer32++ 1.3.5.531 - Buffer overflow

Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially …

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: Jan. 30, 2026, 3:51 p.m.

8.5

CVSS4.0

CVE-2023-54331 - Outline 1.6.0 - Unquoted Service Path

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be executed with Local…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

9.3

CVSS4.0

CVE-2023-54330 - Inbit Messenger 4.9.0 - Unauthenticated Remote SEH Overflow

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to over…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.
Total resulsts: 345291
Page 1757 of 34,530
Β« previous page Β» next page
Filters