9.3

CVSS4.0

CVE-2023-54330 - Inbit Messenger 4.9.0 - Unauthenticated Remote SEH Overflow

Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to overโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:29 a.m.

9.3

CVSS4.0

CVE-2023-54329 - Inbit Messenger 4.9.0 - Unauthenticated Remote Command Execution (RCE)

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to โ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:29 a.m.

5.1

CVSS4.0

CVE-2023-54328 - AimOne Video Converter 2.04 Build 103 Buffer Overflow in Registration Form

AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes application crashes. Attackers can generate a 7000-byte payload to trigger the denial of service and potentially exploit the software's registration mechanism.

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: Feb. 2, 2026, 4:16 p.m.

8.5

CVSS4.0

CVE-2023-53984 - HotKey Clipboard 2.1.0.6 - Privilege Escalation Unquoted Service Path

Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS4.0

CVE-2022-50939 - e107 CMS v3.2.1 - Upload Restriction Bypass with Path Traversal File Override

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulnerability exists in the Media Manager's remote URL upload functionality (image.php) where the upload_caption parameter is โ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.5

CVSS4.0

CVE-2022-50938 - CONTPAQiยฎ AdminPAQ 14.0.0 - Unquoted Service Path

CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system priโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2022-50937 - Ametys CMS v4.4.1 - Cross Site Scripting (XSS)

Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for external links. Attackers can inject malicious script code in link text and descriptions to execute persistent attacks that compromise user sessions and manipulate application modules.

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 2:06 p.m.

8.7

CVSS4.0

CVE-2022-50936 - WBCE CMS 1.5.2 - Remote Code Execution (RCE) (Authenticated)

WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by craftiโ€ฆ

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: March 5, 2026, 1:29 a.m.

8.5

CVSS4.0

CVE-2022-50935 - FLAME II MODEM USB - Unquoted Service Path

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2022-50933 - Cain & Abel 4.9.56 - Unquoted Service Path

Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions.

๐Ÿ“… Published: Jan. 13, 2026, 10:52 p.m. ๐Ÿ”„ Last Modified: Feb. 2, 2026, 4:16 p.m.
Total resulsts: 346934
Page 1921 of 34,694
ยซ previous page ยป next page
Filters