CVE-2024-9935: PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download
漏洞标题 CVE-2024-9935: PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download 漏洞描述 The PDF Generator Addon for Elementor Page Builder plugin for ...
ConnectWise ScreenConnect CVE-2024-1709身份验证绕过漏洞
漏洞标题 ConnectWise ScreenConnect CVE-2024-1709身份验证绕过漏洞 漏洞描述 ConnectWise ScreenConnect存在身份验证绕过漏洞,此漏洞是由于对url验证不充分导致的,特殊的url可绕过验证并访...
CVE-2024-28255: OpenMetadata – Authentication Bypass
漏洞标题 CVE-2024-28255: OpenMetadata - Authentication Bypass 漏洞描述 OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata...
CVE-2024-29868: Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation
漏洞标题 CVE-2024-29868: Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation 漏洞描述 Apache StreamPipes from version 0.69.0 through 0...
CVE-2024-6651: WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting
漏洞标题 CVE-2024-6651: WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting 漏洞描述 The WordPress File Upload plugin before version 4.24.8 contains a reflected cross-s...
CVE-2024-4040: CrushFTP VFS – Sandbox Escape LFR
漏洞标题 CVE-2024-4040: CrushFTP VFS - Sandbox Escape LFR 漏洞描述 VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers ...
CVE-2024-55550: Mitel MiCollab – Arbitary File Read
漏洞标题 CVE-2024-55550: Mitel MiCollab - Arbitary File Read 漏洞描述 The Mitel Collab Arbitrary File Read vulnerability allows an unauthenticated attacker to read arbitrary files ...
CVE-2024-6289: WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
漏洞标题 CVE-2024-6289: WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure 漏洞描述 The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the l...
CVE-2024-36837: CRMEB开源电商系统 /api/products SQL注入漏洞(CVE-2024-36837)
漏洞标题 CVE-2024-36837: CRMEB开源电商系统 /api/products SQL注入漏洞(CVE-2024-36837) 漏洞描述 该漏洞可以通过请求api的路径接口来进行SQL注入,进而可能导致敏感信息泄露,该注入可暴露后...
CVE-2024-3273: D-Link Network Attached Storage – Command Injection and Backdoor Account
漏洞标题 CVE-2024-3273: D-Link Network Attached Storage - Command Injection and Backdoor Account 漏洞描述 UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as crit...









