5.1

CVSS4.0

CVE-2023-53887 - Zomplog 3.9 Cross-Site Scripting Vulnerability via Page Creation

Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating new pages. Attackers can craft malicious image source and onerror attributes to execute arbitrary JavaScript code in victim's browser.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

5.7

CVSS4.0

CVE-2023-53886 - Xlight FTP Server 3.9.3.6 Stack Buffer Overflow Vulnerability via Execute Program

Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the application. Attackers can trigger the vulnerability by inserting 294 characters into the program execution configuration, causing a denial of service c…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

7.2

CVSS4.0

CVE-2023-53885 - Webutler v3.2 Remote Code Execution via Arbitrary File Upload

Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP files with system command execution. Attackers can upload a PHAR file with embedded system commands to the media browser and execute arbitrary commands by accessing the uploaded file.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

5.1

CVSS4.0

CVE-2023-53884 - Webedition CMS v2.9.8.8 Stored Cross-Site Scripting via SVG Upload

Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the media upload feature to inject and execute arbitrary scripts when the file is viewe…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

7.2

CVSS4.0

CVE-2023-53883 - Webedition CMS v2.9.8.8 Remote Code Execution via PHP Page Creation

Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

5.1

CVSS4.0

CVE-2023-53882 - JLex GuestBook 1.6.4 Reflected Cross-Site Scripting via URL Parameter

JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attackers to inject malicious scripts. Attackers can craft malicious links with XSS payloads to steal session tokens or execute arbitrary JavaScript in victims' browsers.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.2

CVSS4.0

CVE-2023-53881 - ReyeeOS 1.204.1614 Man-in-the-Middle Remote Code Execution via CWMP

ReyeeOS 1.204.1614 contains an unencrypted CWMP communication vulnerability that allows attackers to intercept and manipulate device communication through a man-in-the-middle attack. Attackers can create a fake CWMP server to inject and execute arbitrary commands on Ruijie Reyee Cloud devices by ex…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.

4.8

CVSS4.0

CVE-2023-53880 - Lucee 5.4.2.17 Authenticated Reflected Cross-Site Scripting via Admin Interfaces

Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through administrative interface parameters. Attackers can craft specific payloads targeting admin pages like server.cfm and web.cfm to execute arbitrary JavaScript…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS4.0

CVE-2023-53878 - Member Login Script 3.3 Client-Side Request Desynchronization Vulnerability

Member Login Script 3.3 contains a client-side desynchronization vulnerability that allows attackers to manipulate HTTP request handling by exploiting Content-Length header parsing. Attackers can send crafted POST requests with smuggled secondary requests to potentially bypass server-side request p…

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.3

CVSS4.0

CVE-2023-53877 - Bus Reservation System 1.1 Multiple SQL Injection via pickup_id Parameter

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to steal information from the database.

πŸ“… Published: Dec. 15, 2025, 8:28 p.m. πŸ”„ Last Modified: April 7, 2026, 2:07 p.m.
Total resulsts: 349182
Page 2602 of 34,919
Β« previous page Β» next page
Filters