6.9

CVSS4.0

CVE-2022-50800 - H3C SSL VPN n/a Username Enumeration via Login Script Credential Verification

H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txtUsrName' POST parameter. Attackers can submit different usernames to the login_submit.cgi endpoint and analyze response messages to distinguish between existing and non-existing a…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 10:19 a.m.

7.1

CVSS4.0

CVE-2022-50799 - Fetch Softworks Fetch FTP Client 5.8.2 Remote CPU Consumption Denial of Service

Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the ap…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 12:25 p.m.

0.0

CVE-2022-50798 -

This candidate is a duplicate of CVE-2017-11359.

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 5:15 p.m.

9.3

CVSS4.0

CVE-2022-50796 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized acce…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 9:22 p.m.

8.5

CVSS4.0

CVE-2022-50795 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the traceroute.php script, which t…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

9.3

CVSS4.0

CVE-2022-50794 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system command…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 2:34 p.m.

8.7

CVSS4.0

CVE-2022-50793 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 2:36 p.m.

8.7

CVSS4.0

CVE-2022-50792 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected d…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 4, 2026, 7:24 p.m.

8.5

CVSS4.0

CVE-2022-50791 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the vulnerable ping.php script, wh…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

6.9

CVSS4.0

CVE-2022-50790 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream Disclosure

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream deta…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 4, 2026, 7:27 p.m.
Total resulsts: 343921
Page 1814 of 34,393
Β« previous page Β» next page
Filters