8.8

CVSS4.0

CVE-2022-50892 - VIAVIWEB Wallpaper Admin 1.0 - SQL Injection via Login Page

VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials. Attackers can exploit the login page by injecting 'admin' or 1=1-- - payload to gain unauthorized access to the administrative interface.

πŸ“… Published: Jan. 13, 2026, 10:56 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.

5.1

CVSS4.0

CVE-2021-47750 - YouPHPTube <= 7.8 - Cross-Site Scripting

YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they ac…

πŸ“… Published: Jan. 13, 2026, 10:56 p.m. πŸ”„ Last Modified: March 5, 2026, 1:28 a.m.

5.1

CVSS4.0

CVE-2020-36919 - WPForms 1.7.8 - Cross-Site Scripting (XSS)

WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.

πŸ“… Published: Jan. 13, 2026, 10:55 p.m. πŸ”„ Last Modified: March 5, 2026, 1:26 a.m.

5.1

CVSS4.0

CVE-2023-54341 - Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) via file Parameter

Webgrind 1.1 and before contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts via the file parameter in index.php. The application does not sufficiently encode user-controlled inputs, allowing attackers to execute arbitrary JavaScr…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.8

CVSS4.0

CVE-2023-54340 - WorkOrder CMS 0.1.0 - SQL Injection

WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by manipulating username and password parameters. Attackers can inject malicious SQL queries using techniques like OR '1'='1' and stacked queries to access database information or execut…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2023-54339 - Webgrind 1.1 - Remote Command Execution (RCE) via dataFile Parameter

Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' t…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.5

CVSS4.0

CVE-2023-54338 - Tftpd32_SE 4.60 - 'Tftpd32_svc' Unquoted Service Path

Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permiss…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2023-54337 - Sysax Multi Server 6.95 - 'Password' Denial of Service (PoC)

Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.5

CVSS4.0

CVE-2023-54336 - Mediconta 3.7.27 - 'servermedicontservice' Unquoted Service Path

Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with L…

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2023-54335 - eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: April 7, 2026, 2:08 p.m.
Total resulsts: 349182
Page 2144 of 34,919
Β« previous page Β» next page
Filters