7.1

CVSS4.0

CVE-2022-50799 - Fetch Softworks Fetch FTP Client 5.8.2 Remote CPU Consumption Denial of Service

Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specially crafted FTP server responses exceeding 2K bytes to cause excessive resource utilization and potentially crash the ap…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 5, 2026, 12:25 p.m.

0.0

CVE-2022-50798 -

This candidate is a duplicate of CVE-2017-11359.

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 5:15 p.m.

9.3

CVSS4.0

CVE-2022-50796 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized acce…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 9:22 p.m.

8.5

CVSS4.0

CVE-2022-50795 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the traceroute.php script, which t…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

9.3

CVSS4.0

CVE-2022-50794 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system command…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 2:34 p.m.

8.7

CVSS4.0

CVE-2022-50793 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 2:36 p.m.

8.7

CVSS4.0

CVE-2022-50792 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected d…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 4, 2026, 7:24 p.m.

8.5

CVSS4.0

CVE-2022-50791 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the vulnerable ping.php script, wh…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

6.9

CVSS4.0

CVE-2022-50790 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream Disclosure

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability by calling specific web scripts to disclose radio stream deta…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 4, 2026, 7:27 p.m.

8.5

CVSS4.0

CVE-2022-50789 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malicious commands by making a single HTTP POST request to the vuln…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.
Total resulsts: 343920
Page 1814 of 34,392
Β« previous page Β» next page
Filters