7.3

CVSS4.0

CVE-2023-53878 - Member Login Script 3.3 Client-Side Request Desynchronization Vulnerability

Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass server-side request p…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

9.3

CVSS4.0

CVE-2023-53877 - Bus Reservation System 1.1 Multiple SQL Injection via pickup_id Parameter

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

5.1

CVSS4.0

CVE-2023-53876 - Academy LMS 6.1 Arbitrary File Upload Vulnerability via Profile Settings

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaSc…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

7.5

CVSS4.0

CVE-2023-53875 - GOM Player 2.3.90.5360 Remote Code Execution via Insecure IE Component

GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server in…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

6.7

CVSS4.0

CVE-2023-53874 - GOM Player 2.3.90.5360 Buffer Overflow via Equalizer Preset Name

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:47 p.m.

8.7

CVSS4.0

CVE-2023-53873 - SyncBreeze 15.2.24 Denial of Service via Login Endpoint Overflow

SyncBreeze 15.2.24 contains a denial of service vulnerability in the login authentication mechanism that allows attackers to crash the service. Attackers can send an oversized password parameter with repeated 'password=' values to overwhelm the login endpoint and potentially disrupt service availab…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:48 p.m.

9.3

CVSS4.0

CVE-2023-53872 - Wp2Fac 1.0 OS Command Injection via send.php Endpoint

Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execute arbitrary system commands. Attackers can inject shell commands through the 'numara' parameter by appending shell commands with '&' operators to execute malicious code.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:48 p.m.

6.9

CVSS4.0

CVE-2023-53871 - Soosyze 2.0.0 Unrestricted File Upload via Broken Upload Logic

Soosyze 2.0.0 contains a file upload vulnerability that allows attackers to upload arbitrary HTML files with embedded PHP code to the application. Attackers can exploit the broken file upload mechanism to potentially view sensitive file paths and execute malicious PHP scripts on the server.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:48 p.m.

5.1

CVSS4.0

CVE-2023-53870 - Jorani 1.0.3 Cross-Site Scripting Vulnerability via Language Parameter

Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter that allows attackers to inject malicious scripts. Attackers can craft XSS payloads in the language parameter to execute arbitrary JavaScript and potentially steal user session information.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:48 p.m.

8.7

CVSS4.0

CVE-2023-53869 - WEBIGniter 28.7.23 Unrestricted File Upload Remote Code Execution

WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: Dec. 15, 2025, 9:48 p.m.
Total resulsts: 322544
Page 19 of 32,255
Β« previous page Β» next page
Filters