CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2023-54340

    Last Modified: 15 Apr 2026

    WorkOrder CMS 0.1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to bypass login by manipulating username and password parameters. Attackers can inject malicious SQL queries using techniques like OR '1'='1' and stacked queries to access database information or execute administrative commands.

    Published: 13 Jan 2026
    9.3
    Critical

    CVE-2023-54339

    Last Modified: 5 Mar 2026

    Webgrind 1.1 contains a remote command execution vulnerability that allows unauthenticated attackers to inject OS commands via the dataFile parameter in index.php. Attackers can execute arbitrary system commands by manipulating the dataFile parameter, such as using payload '0%27%26calc.exe%26%27' to execute commands on the target system.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2023-54338

    Last Modified: 15 Apr 2026

    Tftpd32 SE 4.60 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be run with system-level permissions.

    Published: 13 Jan 2026
    5.1
    Medium

    CVE-2023-54337

    Last Modified: 5 Mar 2026

    Sysax Multi Server 6.95 contains a denial of service vulnerability in the administrative password field that allows attackers to crash the application. Attackers can overwrite the password field with 800 bytes of repeated characters to trigger an application crash and disrupt server functionality.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2023-54336

    Last Modified: 15 Apr 2026

    Mediconta 3.7.27 contains an unquoted service path vulnerability in the servermedicontservice that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\medicont3\ to inject malicious code that would execute with LocalSystem permissions during service startup.

    Published: 13 Jan 2026
    9.3
    Critical

    CVE-2023-54335

    Last Modified: 7 Apr 2026

    eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without a password by manipulating the login request. Attackers can exploit this flaw to upload malicious PHP files and execute remote commands on the vulnerable file management system.

    Published: 13 Jan 2026
    7
    High

    CVE-2023-54334

    Last Modified: 30 Jan 2026

    Explorer32++ 1.3.5.531 contains a buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows attackers to execute arbitrary code. Attackers can exploit the vulnerability by providing a long file name argument over 396 characters to corrupt the SEH chain and potentially execute malicious code.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2023-54331

    Last Modified: 5 Mar 2026

    Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be executed with LocalSystem permissions.

    Published: 13 Jan 2026
    9.3
    Critical

    CVE-2023-54330

    Last Modified: 5 Mar 2026

    Inbit Messenger versions 4.6.0 to 4.9.0 contain a remote stack-based buffer overflow vulnerability that allows unauthenticated attackers to execute arbitrary code by sending malformed network packets. Attackers can craft a specially designed payload targeting the messenger's network handler to overwrite the Structured Exception Handler (SEH) and execute shellcode on vulnerable Windows systems.

    Published: 13 Jan 2026
    9.3
    Critical

    CVE-2023-54329

    Last Modified: 5 Mar 2026

    Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.

    Published: 13 Jan 2026
    5.1
    Medium

    CVE-2023-54328

    Last Modified: 2 Feb 2026

    AimOne Video Converter 2.04 Build 103 contains a buffer overflow vulnerability in its registration form that causes application crashes. Attackers can generate a 7000-byte payload to trigger the denial of service and potentially exploit the software's registration mechanism.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2023-53984

    Last Modified: 15 Apr 2026

    Clevo HotKey Clipboard 2.1.0.6 contains an unquoted service path vulnerability in the HKClipSvc service that allows local non-privileged users to potentially execute code with system privileges. Attackers can exploit the misconfigured service path to inject and execute arbitrary code by placing malicious executables in specific file system locations.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2022-50939

    Last Modified: 7 Apr 2026

    e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulnerability exists in the Media Manager's remote URL upload functionality (image.php) where the upload_caption parameter is not properly sanitized. An attacker with administrative privileges can use directory traversal sequences (../../../) in the upload_caption field to overwrite critical system files outside the intended upload directory. This can lead to complete compromise of the web application by overwriting configuration files, executable scripts, or other critical system components. The vulnerability was discovered by Hubert Wojciechowski and affects the image.php component in the admin interface.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50938

    Last Modified: 15 Apr 2026

    CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.

    Published: 13 Jan 2026
    5.1
    Medium

    CVE-2022-50937

    Last Modified: 7 Apr 2026

    Ametys CMS v4.4.1 contains a persistent cross-site scripting vulnerability in the link directory's input fields for external links. Attackers can inject malicious script code in link text and descriptions to execute persistent attacks that compromise user sessions and manipulate application modules.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2022-50936

    Last Modified: 5 Mar 2026

    WBCE CMS version 1.5.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious droplets through the admin panel. Authenticated attackers can exploit the droplet upload functionality in the admin tools to create and execute arbitrary PHP code by crafting a specially designed zip file payload.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50935

    Last Modified: 15 Apr 2026

    Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

    Published: 13 Jan 2026
    Unknown

    CVE-2022-50934

    Last Modified: 14 Jan 2026

    This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50933

    Last Modified: 2 Feb 2026

    Cain & Abel 4.9.56 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2022-50932

    Last Modified: 28 Jul 2026

    Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file paths under the /js/ path. Attackers can exploit the issue by sending requests like /js/../../../../.../etc/passwd%00.jpg (null-byte appended traversal) to access critical files such as /etc/passwd and /etc/shadow.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50931

    Last Modified: 5 Mar 2026

    TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system executables like ts3client_win32.exe with custom files to potentially gain SYSTEM or Administrator-level access.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50930

    Last Modified: 15 Apr 2026

    Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50929

    Last Modified: 15 Apr 2026

    Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Connectify\ConnectifyService.exe' to inject malicious executables and escalate privileges.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50928

    Last Modified: 2 Feb 2026

    BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in 'C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe' to inject malicious executables and escalate privileges.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50927

    Last Modified: 15 Apr 2026

    Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted sudo permissions.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2022-50926

    Last Modified: 15 Apr 2026

    WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without authentication.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2022-50925

    Last Modified: 7 Apr 2026

    Prowise Reflect version 1.0.9 contains a remote keystroke injection vulnerability that allows attackers to send keyboard events through an exposed WebSocket on port 8082. Attackers can craft malicious web pages to inject keystrokes, opening applications and typing arbitrary text by sending specific WebSocket messages.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50924

    Last Modified: 15 Apr 2026

    Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50923

    Last Modified: 5 Mar 2026

    Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CobianReflectorService to inject malicious code that will execute with LocalSystem permissions during service startup.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2022-50922

    Last Modified: 15 Apr 2026

    Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory with a specially crafted registration code. Attackers can generate a payload that overwrites the application's memory stack, potentially enabling remote code execution through a carefully constructed input buffer.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50921

    Last Modified: 2 Feb 2026

    WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions during service startup.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50920

    Last Modified: 15 Apr 2026

    Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

    Published: 13 Jan 2026
    9.3
    Critical

    CVE-2022-50919

    Last Modified: 5 Mar 2026

    Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50918

    Last Modified: 15 Apr 2026

    VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific system directories to gain LocalSystem access during service startup.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50917

    Last Modified: 7 Apr 2026

    ProtonVPN 1.26.0 contains an unquoted service path vulnerability in its WireGuard service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path by placing malicious executables in specific file system locations to gain elevated privileges during service startup.

    Published: 13 Jan 2026
    8.7
    High

    CVE-2022-50916

    Last Modified: 7 Apr 2026

    e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrators to override server files through the Media Manager import functionality. Attackers can exploit the upload mechanism by manipulating the upload URL parameter to overwrite existing files like top.php in the web application directory.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50915

    Last Modified: 7 Apr 2026

    PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Primera Technology\PTPublisher\UsbFlashDongleService.exe' to inject malicious executables and gain system-level access.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50914

    Last Modified: 15 Apr 2026

    EaseUS Data Recovery 15.1.0.0 contains an unquoted service path vulnerability in the EaseUS UPDATE SERVICE executable. Attackers can exploit the unquoted path to inject and execute malicious code with elevated LocalSystem privileges.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50913

    Last Modified: 15 Apr 2026

    ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code with elevated system privileges. Attackers can insert a malicious executable in the service path to gain elevated access during service restart or system reboot.

    Published: 13 Jan 2026
    9.3
    Critical

    CVE-2022-50912

    Last Modified: 5 Mar 2026

    ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.

    Published: 13 Jan 2026
    Unknown

    CVE-2022-50911

    Last Modified: 16 Jan 2026

    This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50910

    Last Modified: 5 Mar 2026

    Beehive Forum 1.5.2 contains a host header injection vulnerability in the forgot password functionality that allows attackers to manipulate password reset requests. Attackers can inject a malicious host header to intercept password reset tokens and change victim account passwords without direct authentication.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2022-50909

    Last Modified: 15 Apr 2026

    Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code execution through a crafted POST request.

    Published: 13 Jan 2026
    5.1
    Medium

    CVE-2022-50908

    Last Modified: 15 Apr 2026

    Mailhog 1.0.1 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through email attachments. Attackers can send crafted emails with XSS payloads to execute arbitrary API calls, including message deletion and browser manipulation.

    Published: 13 Jan 2026
    8.6
    High

    CVE-2022-50907

    Last Modified: 7 Apr 2026

    e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload URL parameter, enabling remote code execution through the Media Manager import feature.

    Published: 13 Jan 2026
    4.8
    Medium

    CVE-2022-50906

    Last Modified: 7 Apr 2026

    e107 CMS 3.2.1 contains an upload restriction bypass vulnerability that allows authenticated administrators to upload malicious SVG files through the media manager. Attackers with admin privileges can exploit this vulnerability to upload SVG files with embedded cross-site scripting (XSS) payloads that can execute arbitrary scripts when viewed.

    Published: 13 Jan 2026
    9.8
    Critical

    CVE-2022-50905

    Last Modified: 7 Apr 2026

    e107 CMS version 3.2.1 contains multiple vulnerabilities that allow cross-site scripting (XSS) attacks. The first vulnerability is a reflected XSS that occurs in the news comment functionality when authenticated users interact with the comment form. An attacker can inject malicious JavaScript code through the URL parameter that gets executed when users click outside the comment field after typing content. The second vulnerability involves an upload restriction bypass for authenticated administrators, allowing them to upload SVG files containing malicious code through the media manager's remote URL upload feature. This results in stored XSS when the uploaded SVG files are accessed. These vulnerabilities were discovered by Hubert Wojciechowski and affect the news.php and image.php components of the CMS.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50904

    Last Modified: 15 Apr 2026

    Wondershare UBackit 2.0.5 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the wsbackup service to inject malicious executables that would run with LocalSystem permissions during service startup.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50903

    Last Modified: 5 Mar 2026

    Wondershare MobileTrans 3.5.9 contains an unquoted service path vulnerability in the ElevationService that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path by placing malicious executables in specific filesystem locations that will be executed with LocalSystem permissions during service startup.

    Published: 13 Jan 2026
    8.5
    High

    CVE-2022-50902

    Last Modified: 15 Apr 2026

    Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\FamiSafe\ to inject malicious code that would run with LocalSystem permissions during service startup.

    Published: 13 Jan 2026