8.5

CVSS4.0

CVE-2022-50808 - CoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service Path

CoolerMaster MasterPlus 1.8.5 contains an unquoted service path vulnerability in the MPService that allows local attackers to execute code with elevated system privileges. Attackers can drop a malicious executable in the service path and trigger code execution during service startup or system rebooโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2022-50806 - 4images 1.9 - Remote Command Execution (RCE)

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoinโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.8

CVSS4.0

CVE-2022-50805 - Senayan Library Management System 9.0.0 - SQL Injection

Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL queries. Attackers can exploit the vulnerability by submitting crafted payloads to manipulate database queries and potentially extract sensitive infoโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2022-50693 - Splashtop 8.71.12001.0 - Unquoted Service Path

Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2021-47751 - CuteEditor for PHP 6.6 - Directory Traversal

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using dโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:05 p.m.

8.7

CVSS4.0

CVE-2021-47749 - YouPHPTube <= 7.8 - Directory Traversal

YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intendโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:28 a.m.

9.3

CVSS4.0

CVE-2020-36911 - Covenant 0.5 - Remote Code Execution (RCE)

Covenant 0.1.3 - 0.5 contains a remote code execution vulnerability that allows attackers to craft malicious JWT tokens with administrative privileges. Attackers can generate forged tokens with admin roles and upload custom DLL payloads to execute arbitrary commands on the target system.

๐Ÿ“… Published: Jan. 13, 2026, 10:51 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:26 a.m.

10

CVSS4.0

CVE-2026-23478 - Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback

Cal.com is open-source scheduling software. From 3.1.6 to before 6.0.7, there is a vulnerability in a custom NextAuth JWT callback that allows attackers to gain full authenticated access to any user's account by supplying a target email address via session.update(). This vulnerability is fixed in 6โ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 9:37 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 6:30 a.m.

4.3

CVSS3.1

CVE-2025-68658 - Open Source Point of Sale (opensourcepos) Stored XSS in Configuration (Information) โ€“ Company Nameโ€ฆ

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. opensourcepos 3.4.0 and 3.4.1 has a stored XSS vulnerability exists in the Configuration (Information) functionality. An authenticated user with the permission โ€œConfiguratiโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 9:25 p.m. ๐Ÿ”„ Last Modified: Jan. 21, 2026, 6:40 p.m.

5.7

CVSS4.0

CVE-2025-68947 - NSecsoft NSecKrnl process termination privilege escalation

NSecsoft 'NSecKrnl' is a Windows driver that allows a local, authenticated attacker to terminate processes owned by other users, including SYSTEM and Protected Processes by issuing crafted IOCTL requests to the driver.

๐Ÿ“… Published: Jan. 13, 2026, 9:19 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345253
Page 1759 of 34,526
ยซ previous page ยป next page
Filters