9.2

CVSS4.0

CVE-2023-53881 - ReyeeOS 1.204.1614 Man-in-the-Middle Remote Code Execution via CWMP

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by ex…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

4.8

CVSS4.0

CVE-2023-53880 - Lucee 5.4.2.17 Authenticated Reflected Cross-Site Scripting via Admin Interfaces

Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through administrative interface parameters. Attackers can craft specific payloads targeting admin pages like server.cfm and web.cfm to execute arbitrary JavaScript…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

7.3

CVSS4.0

CVE-2023-53878 - Member Login Script 3.3 Client-Side Request Desynchronization Vulnerability

Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass server-side request p…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

9.3

CVSS4.0

CVE-2023-53877 - Bus Reservation System 1.1 Multiple SQL Injection via pickup_id Parameter

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

5.1

CVSS4.0

CVE-2023-53876 - Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaSc…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

7.5

CVSS4.0

CVE-2023-53875 - GOM Player 2.3.90.5360 Remote Code Execution via Insecure IE Component

GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server in…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

6.7

CVSS4.0

CVE-2023-53874 - GOM Player 2.3.90.5360 Buffer Overflow via Equalizer Preset Name

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

8.7

CVSS4.0

CVE-2023-53873 - SyncBreeze 15.2.24 Denial of Service via Login Endpoint Overflow

SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availab…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:48 p.m.

9.3

CVSS4.0

CVE-2023-53872 - Wp2Fac 1.0 OS Command Injection via send.php Endpoint

Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'numara' parameter by appending shell commands with '&' operators to execute malicious code.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:48 p.m.

6.9

CVSS4.0

CVE-2023-53871 - Soosyze 2.0.0 Unrestricted File Upload via Broken Upload Logic

Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. Attackers can exploit the broken file upload mechanism to potentially view sensitive file paths and execute malicious PHP scripts on the server.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:48 p.m.
Total resulsts: 322536
Page 18 of 32,254
Β« previous page Β» next page
Filters