8.5

CVSS4.0

CVE-2022-50933 - Cain & Abel 4.9.56 - Unquoted Service Path

Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions.

πŸ“… Published: Jan. 13, 2026, 10:52 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:15 p.m.

8.7

CVSS4.0

CVE-2022-50932 - Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated)

Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file paths under the /js/ path. Attackers can exploit the issue by sending requests like /js/../../../../.../etc/passwd%00.jpg (…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:15 p.m.

8.5

CVSS4.0

CVE-2022-50931 - TeamSpeak 3.5.6 - Insecure File Permissions

TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system executables like ts3client_win32.exe with custom files to potentially gain SYSTEM or Administrator-level access.

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 4:25 p.m.

8.5

CVSS4.0

CVE-2022-50930 - Emerson PAC Machine Edition 9.80 Build 8695 - 'TrapiServer' Unquoted Service Path

Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute …

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 4:25 p.m.

8.5

CVSS4.0

CVE-2022-50929 - Connectify Hotspot 2018 'ConnectifyService' - Unquoted Service Path

Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Connectify\ConnectifyService.exe' to inject malicious exe…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 4:25 p.m.

8.5

CVSS4.0

CVE-2022-50928 - Bluetooth Application 5.4.277 - 'BlueSoleilCS' Unquoted Service Path

BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in 'C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe' to inject mal…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:15 p.m.

8.5

CVSS4.0

CVE-2022-50927 - Cyclades Serial Console Server 3.3.0 - Local Privilege Escalation

Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted …

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:19 p.m.

8.7

CVSS4.0

CVE-2022-50926 - WAGO 750-8212 PFC200 G2 2ETH RS Privilege Escalation

WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without authentication.

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:19 p.m.

8.6

CVSS4.0

CVE-2022-50925 - Prowise Reflect v1.0.9 - Remote Keystroke Injection

Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 8:15 p.m.

8.5

CVSS4.0

CVE-2022-50924 - Private Internet Access 3.3 - 'pia-service' Unquoted Service Path

Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSyste…

πŸ“… Published: Jan. 13, 2026, 10:51 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 7:19 p.m.
Total resulsts: 328486
Page 96 of 32,849
Β« previous page Β» next page
Filters