8.5

CVSS4.0

CVE-2022-50914 - EaseUS Data Recovery - 'ensserver.exe' Unquoted Service Path

EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2022-50913 - TCQ - 'ITeCProteccioAppServer.exe' Unquoted Service Path

ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code with elevated system privileges. Attackers can insert a malicious executable in the service path to gain elevated access during service restart or system reboot.

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2022-50912 - ImpressCMS 1.4.4 - Unrestricted File Upload

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

0.0

CVE-2022-50911 -

This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 16, 2026, 3:15 p.m.

8.5

CVSS4.0

CVE-2022-50910 - Beehive Forum - Account Takeover

Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct aut…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.6

CVSS4.0

CVE-2022-50909 - Algo 8028 Control Panel - Remote Code Execution (RCE) (Authenticated)

Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enablin…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2022-50908 - Mailhog 1.0.1 - Stored Cross-Site Scripting (XSS)

Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through email attachments. Attackers can send crafted emails with XSS payloads to execute arbitrary API calls, including message deletion and browser manipulation.

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2022-50907 - e107 CMS v3.2.1 - Admin Upload Restriction Bypass + RCE

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload URL parameter, enabling remote code execution thr…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.

4.8

CVSS4.0

CVE-2022-50906 - e107 CMS v3.2.1 - Admin Upload Restriction Bypass + Stored XSS

e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files with embedded cross-site scripting (XSS) payloads t…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.

9.8

CVSS3.1

CVE-2022-50905 - e107 CMS v3.2.1 - Reflected XSS via Comment Flow

e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS that occurs in the news comment functionality when authenticated users interact with the comment form. An attacker can inject malicious JavaScript code …

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.
Total resulsts: 349182
Page 2148 of 34,919
Β« previous page Β» next page
Filters