9.3

CVSS4.0

CVE-2023-53950 - InnovaStudio WYSIWYG Editor 5.4 Unrestricted File Upload via Filename Manipulation

InnovaStudio WYSIWYG Editor 5.4 contains an unrestricted file upload vulnerability that allows attackers to bypass file extension restrictions through filename manipulation. Attackers can upload malicious ASP shells by using null byte techniques and alternate file extensions to circumvent upload co…

πŸ“… Published: Dec. 19, 2025, 9:07 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:07 p.m.

8.5

CVSS4.0

CVE-2023-53959 - FileZilla Client 3.63.1 DLL Hijacking via Missing TextShaping.dll

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code executio…

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.6

CVSS4.0

CVE-2023-53958 - LDAP Tool Box Self Service Password 1.5.2 Account Takeover via HTTP Host Header

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeove…

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.5

CVSS4.0

CVE-2023-53957 - Kimai 1.30.10 SameSite Cookie Vulnerability Session Hijacking

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijack…

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.7

CVSS4.0

CVE-2023-53956 - Flatnux 2021-03.25 Authenticated File Upload Remote Code Execution

Flatnux 2021-03.25 contains an authenticated file upload vulnerability that allows administrative users to upload arbitrary PHP files through the file manager. Attackers with admin credentials can upload malicious PHP scripts to the web root directory, enabling remote code execution on the server.

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.5

CVSS4.0

CVE-2023-53954 - ActFax 10.10 Unquoted Path Services Privilege Escalation Vulnerability

ActFax 10.10 contains an unquoted service path vulnerability that allows local attackers to potentially escalate privileges by exploiting the ActiveFaxServiceNT service configuration. Attackers with write permissions to Program Files directories can inject a malicious ActSrvNT.exe executable to gai…

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.7

CVSS4.0

CVE-2023-53952 - Dotclear 2.25.3 Authenticated Remote Code Execution via File Upload

Dotclear 2.25.3 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension through the blog post creation interface. Attackers can upload files containing PHP system commands that execute when the uploaded file is accessed, …

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

9.3

CVSS4.0

CVE-2023-53951 - Ever Gauzy v0.281.9 JWT Authentication Weakness via HMAC Secret

Ever Gauzy v0.281.9 contains a JWT authentication vulnerability that allows attackers to exploit weak HMAC secret key implementation. Attackers can leverage the exposed JWT token to authenticate and gain unauthorized access with administrative permissions.

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

8.5

CVSS4.0

CVE-2023-53949 - AspEmail 5.6.0.2 Local Privilege Escalation via Binary Permission Vulnerability

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.

9.3

CVSS4.0

CVE-2023-53948 - Lilac-Reloaded for Nagios 2.0.8 Remote Code Execution via Autodiscovery

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a crafted POST request…

πŸ“… Published: Dec. 19, 2025, 9:05 p.m. πŸ”„ Last Modified: Dec. 19, 2025, 9:05 p.m.
Total resulsts: 323546
Page 6 of 32,355
Β« previous page Β» next page
Filters