9.3

CVSS4.0

CVE-2023-53969 - Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Password Change

Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords w…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 26, 2025, 4:50 p.m.

9.3

CVSS4.0

CVE-2023-53968 - Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase Account

Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts wi…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 26, 2025, 4:45 p.m.

9.3

CVSS4.0

CVE-2023-53967 - Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password Change

Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password t…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 26, 2025, 4:50 p.m.

9.3

CVSS4.0

CVE-2023-53966 - SOUND4 LinkAndShare Transmitter 1.1.2 Format String Stack Buffer Overflow

SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbit…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 5:12 p.m.

8.6

CVSS4.0

CVE-2023-53965 - SOUND4 Server Service 4.1.102 Local Privilege Escalation via Unquoted Service Path

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute wit…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 4:11 p.m.

8.5

CVSS4.0

CVE-2022-50690 - Wondershare MirrorGo 2.0.11.346 Local Privilege Escalation via Insecure File Permissions

Wondershare MirrorGo 2.0.11.346 contains a local privilege escalation vulnerability due to incorrect file permissions on executable files. Unprivileged local users can replace the ElevationService.exe with a malicious file to execute arbitrary code with LocalSystem privileges.

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2022-50689 - Cobian Reflector 0.9.93 RC1 Local Denial of Service via Password Field

Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task configuration.

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 31, 2025, 5:53 p.m.

8.5

CVSS4.0

CVE-2022-50688 - Cobian Backup Gravity 11.2.0.582 Unquoted Service Path Privilege Escalation

Cobian Backup Gravity 11.2.0.582 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the CobianBackup11 service to inject malicious code that would execute w…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2022-50687 - Cobian Backup 11 Gravity 11.2.0.582 Local Denial of Service via Password Field

Cobian Backup 11 Gravity 11.2.0.582 contains a denial of service vulnerability in the FTP password input field that allows attackers to crash the application. Attackers can generate a specially crafted 800-byte buffer and paste it into the password field to trigger an application crash.

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: March 5, 2026, 12:02 p.m.

6.9

CVSS4.0

CVE-2021-47715 - Hasura GraphQL 1.3.3 Server-Side Request Forgery via Remote Schema Injection

Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL defini…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 26, 2025, 4:57 p.m.
Total resulsts: 346710
Page 2229 of 34,671
Β« previous page Β» next page
Filters