6.9

CVSS4.0

CVE-2022-50788 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 3:09 p.m.

5.3

CVSS4.0

CVE-2022-50787 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username input to execute arbitrary HTML and JavaScript code in victim …

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 13, 2026, 3:12 p.m.

9.3

CVSS4.0

CVE-2022-50696 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions w…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: March 4, 2026, 7:29 p.m.

8.7

CVSS4.0

CVE-2022-50695 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php, traceroute.php, and dns.php to generate network flooding attacks targeting externa…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 9:20 p.m.

8.8

CVSS4.0

CVE-2022-50694 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x SQL Injection via Username Parameter

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username parameter to bypass authentication and potentially access unau…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 9:20 p.m.

6.9

CVSS4.0

CVE-2022-50692 - SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack active user sessions and gain unauthorized access to the applicat…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 20, 2026, 6:51 p.m.

9.3

CVSS4.0

CVE-2022-50691 - MiniDVBLinux 5.4 Remote Root Command Execution via commands.sh

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system acces…

πŸ“… Published: Dec. 30, 2025, 10:41 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 2:16 p.m.

0.0

CVE-2025-62753 - WordPress MAS Videos plugin <= 1.3.4 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in MadrasThemes MAS Videos masvideos allows PHP Local File Inclusion.This issue affects MAS Videos: from n/a through <= 1.3.4.

πŸ“… Published: Dec. 30, 2025, 10:37 p.m. πŸ”„ Last Modified: April 1, 2026, 5:28 p.m.

5.1

CVSS4.0

CVE-2025-15360 - newbee-mall-plus Product Information Edit UploadController.java upload unrestricted upload

A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/common/UploadController.java of the component Product Information Edit Page. This manipulation of the argument File causes unrestricted upload. The attack …

πŸ“… Published: Dec. 30, 2025, 9:32 p.m. πŸ”„ Last Modified: Jan. 9, 2026, 7:29 p.m.

2.7

CVSS4.0

CVE-2025-61594 - URI Credential Leakage Bypass over CVE-2025-27221

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the fix to CVE-2025-27221 that can expose user credentials. When using the `+` operator to combine URIs, sensitive information like passwords from the origin…

πŸ“… Published: Dec. 30, 2025, 9:03 p.m. πŸ”„ Last Modified: Feb. 24, 2026, 2:57 p.m.
Total resulsts: 343920
Page 1815 of 34,392
Β« previous page Β» next page
Filters