8.5

CVSS4.0

CVE-2022-50904 - Wondershare UBackit 2.0.5 - 'wsbackup' Unquoted Service Path

Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the wsbackup service to inject malicious executables that would run with LocalSystem pe…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2022-50903 - Wondershare MobileTrans 3.5.9 - 'ElevationService' Unquoted Service Path

Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path by placing malicious executables in specific filesystem locations that w…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.5

CVSS4.0

CVE-2022-50902 - Wondershare FamiSafe 1.0 - 'FSService' Unquoted Service Path

Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\FamiSafe\ to inject malicious code that would run wit…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2022-50901 - Wondershare Dr.Fone 11.4.9 - 'DFWSIDService' Unquoted Service Path

Wondershare Dr.Fone 11.4.9 contains an unquoted service path vulnerability in the DFWSIDService that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\Wondershare Dr.Fone\ to inject malicious executables that woul…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.5

CVSS4.0

CVE-2022-50900 - Wondershare Dr.Fone 12.0.18 - 'Wondershare InstallAssist' Unquoted Service Path

Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path to insert malicious code that will be executed with LocalSystem permissions during serv…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.7

CVSS4.0

CVE-2022-50899 - Geonetwork 4.2.0 - XML External Entity (XXE)

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from the server. Attackers can exploit the insecure XML parser by crafting a malicious XML document with external entity references to read system files thr…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.6

CVSS4.0

CVE-2022-50898 - NanoCMS 0.4 - Remote Code Execution (RCE) (Authenticated)

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper inpu…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 2:16 p.m.

8.7

CVSS4.0

CVE-2022-50897 - mPDF 7.0 - Local File Inclusion

mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.8

CVSS4.0

CVE-2022-50895 - Aero CMS 0.0.1 - SQL Injection

Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the syste…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.

5.1

CVSS4.0

CVE-2022-50891 - Owlfiles File Manager 12.0.1 Cross-Site Scripting via HTTP Server

Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the path parameter in HTTP server endpoints. Attackers can craft URLs targeting the download and list endpoints with embedded script tags to execute arbitrary JavaScr…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: April 7, 2026, 2:06 p.m.
Total resulsts: 349182
Page 2149 of 34,919
Β« previous page Β» next page
Filters