8.7

CVSS4.0

CVE-2023-53971 - WebTareas 2.4 Authenticated Remote Code Execution via File Upload

WebTareas 2.4 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the chat photo upload functionality. Attackers can upload a PHP file with arbitrary code to the /files/Messages/ directory and execute it directly through the generated file path.

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

8.7

CVSS4.0

CVE-2023-53970 - Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Reset Board Config

Screen SFT DAB 600/C Firmware 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP-bound session identifiers. Attackers can exploit the vulnerable deviceManagement API endpoint to reset device configurations by sending crafted …

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

9.3

CVSS4.0

CVE-2023-53969 - Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Password Change

Screen SFT DAB 600/C firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to change user passwords w…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

9.3

CVSS4.0

CVE-2023-53968 - Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Erase Account

Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts wi…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

9.3

CVSS4.0

CVE-2023-53967 - Screen SFT DAB 600/C Firmware 1.9.3 Authentication Bypass Admin Password Change

Screen SFT DAB 600/C firmware 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without requiring the current credentials. Attackers can exploit the userManager.cgx API endpoint by sending a crafted POST request with a new MD5-hashed password t…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

9.3

CVSS4.0

CVE-2023-53966 - SOUND4 LinkAndShare Transmitter 1.1.2 Format String Stack Buffer Overflow

SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the username environment variable with format string payloads to potentially execute arbit…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

8.6

CVSS4.0

CVE-2023-53965 - SOUND4 Server Service 4.1.102 Local Privilege Escalation via Unquoted Service Path

SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary path by inserting malicious code in the system root path that could execute wit…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

8.5

CVSS4.0

CVE-2022-50690 - Wondershare MirrorGo 2.0.11.346 Local Privilege Escalation via Insecure File Permissions

Wondershare MirrorGo 2.0.11.346 contains a local privilege escalation vulnerability due to incorrect file permissions on executable files. Unprivileged local users can replace the ElevationService.exe with a malicious file to execute arbitrary code with LocalSystem privileges.

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

6.9

CVSS4.0

CVE-2022-50689 - Cobian Reflector 0.9.93 RC1 Local Denial of Service via Password Field

Cobian Reflector 0.9.93 RC1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the password input field. Attackers can paste a large 8000-byte buffer into the password field to trigger an application crash during SFTP task configuration.

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.

8.5

CVSS4.0

CVE-2022-50688 - Cobian Backup Gravity 11.2.0.582 Unquoted Service Path Privilege Escalation

Cobian Backup Gravity 11.2.0.582 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the CobianBackup11 service to inject malicious code that would execute w…

πŸ“… Published: Dec. 22, 2025, 9:35 p.m. πŸ”„ Last Modified: Dec. 22, 2025, 9:35 p.m.
Total resulsts: 323671
Page 3 of 32,368
Β« previous page Β» next page
Filters