9.3

CVSS4.0

CVE-2023-53963 - SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'passworโ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:37 p.m. ๐Ÿ”„ Last Modified: Jan. 13, 2026, 3:42 p.m.

8.8

CVSS4.0

CVE-2023-53962 - SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File Write

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with dirโ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:37 p.m. ๐Ÿ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

5.1

CVSS4.0

CVE-2023-53961 - SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request Forgery

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administratโ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:37 p.m. ๐Ÿ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

9.3

CVSS4.0

CVE-2023-53960 - SOUND4 IMPACT/FIRST/PULSE/Eco v2.x SQL Injection via Authentication Bypass

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentiallyโ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:37 p.m. ๐Ÿ”„ Last Modified: Jan. 16, 2026, 7:16 p.m.

9.3

CVSS4.0

CVE-2023-53955 - SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without pโ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:37 p.m. ๐Ÿ”„ Last Modified: Jan. 13, 2026, 6:23 p.m.

8.6

CVSS4.0

CVE-2023-53981 - PhotoShow 3.0 Remote Code Execution via Exiftran Path Injection

PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a cโ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:08 p.m.

8.7

CVSS4.0

CVE-2023-53980 - ProjectSend r1605 Remote Code Execution via File Extension Manipulation

ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts with disguised extensions through the upload.process.php endpoint to execute arbitrary commands on the server.

๐Ÿ“… Published: Dec. 22, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 12:03 p.m.

8.6

CVSS4.0

CVE-2023-53979 - MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities

MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editiโ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 12:03 p.m.

5.1

CVSS4.0

CVE-2023-53978 - myBB Forums 1.8.26 Stored Cross-Site Scripting via Forum Announcements

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum announcement system that allows authenticated administrators to inject malicious scripts when creating announcements. Attackers can exploit this vulnerability by inserting script payloads in the announcement title โ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:08 p.m.

5.1

CVSS4.0

CVE-2023-53977 - myBB Forums 1.8.26 Stored Cross-Site Scripting via Forum Management

myBB Forums 1.8.26 contains a stored cross-site scripting vulnerability in the forum management system that allows authenticated administrators to inject malicious scripts when creating new forums. Attackers can exploit this vulnerability by inserting script payloads in the forum title field when aโ€ฆ

๐Ÿ“… Published: Dec. 22, 2025, 9:35 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:08 p.m.
Total resulsts: 343984
Page 1956 of 34,399
ยซ previous page ยป next page
Filters