云记-渗透云记 - 专注于网络安全与技术分享-第893页
CVE-2021-42627: D-Link DIR-615 - Unauthorized Access-渗透云记 - 专注于网络安全与技术分享

CVE-2021-42627: D-Link DIR-615 – Unauthorized Access

漏洞标题 CVE-2021-42627: D-Link DIR-615 - Unauthorized Access 漏洞描述 D-Link DIR-615 devices with firmware 20.06 are susceptible to unauthorized access. An attacker can access the...
CVE-2023-36346: POS Codekop v2.0 - Cross Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-36346: POS Codekop v2.0 – Cross Site Scripting

漏洞标题 CVE-2023-36346: POS Codekop v2.0 - Cross Site Scripting 漏洞描述 POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm...
CVE-2020-6287: SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition-渗透云记 - 专注于网络安全与技术分享

CVE-2020-6287: SAP NetWeaver AS JAVA 7.30-7.50 – Remote Admin Addition

漏洞标题 CVE-2020-6287: SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin Addition 漏洞描述 SAP NetWeaver AS JAVA (LM Configuration Wizard), versions 7.30, 7.31, 7.40, 7.50, does not ...
Apache Airflow admin 未授权访问漏洞 (CVE-2020-17526)-渗透云记 - 专注于网络安全与技术分享

Apache Airflow admin 未授权访问漏洞 (CVE-2020-17526)

漏洞标题 Apache Airflow admin 未授权访问漏洞 (CVE-2020-17526) 漏洞描述 攻击者可以创建与目标相同版本的本地安装,以管理员身份登录并将会话cookie重播到目标以在远程计算机上以管理员身...
CVE-2020-19295: Jeesns 1.4.2 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2020-19295: Jeesns 1.4.2 – Cross-Site Scripting

漏洞标题 CVE-2020-19295: Jeesns 1.4.2 - Cross-Site Scripting 漏洞描述 Jeesns 1.4.2 is vulnerable to reflected cross-site scripting in the /weibo/topic component and allows attacker...
CVE-2021-38314: WordPress Redux Framework <=4.2.11 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2021-38314: WordPress Redux Framework <=4.2.11 - Information Disclosure

漏洞标题 CVE-2021-38314: WordPress Redux Framework <=4.2.11 - Information Disclosure 漏洞描述 WordPress Redux Framework plugin through 4.2.11 is susceptible to information discl...
CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2022-26148: Grafana & Zabbix Integration – Credentials Disclosure

漏洞标题 CVE-2022-26148: Grafana & Zabbix Integration - Credentials Disclosure 漏洞描述 Grafana through 7.3.4, when integrated with Zabbix, contains a credential disclosure vul...
CVE-2022-0826: WordPress WP Video Gallery <=1.7.1 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-0826: WordPress WP Video Gallery <=1.7.1 - SQL Injection

漏洞标题 CVE-2022-0826: WordPress WP Video Gallery <=1.7.1 - SQL Injection 漏洞描述 WordPress WP Video Gallery plugin through 1.7.1 contains a SQL injection vulnerability. The p...
CVE-2022-2376: WordPress Directorist <7.3.1 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2022-2376: WordPress Directorist <7.3.1 - Information Disclosure

漏洞标题 CVE-2022-2376: WordPress Directorist <7.3.1 - Information Disclosure 漏洞描述 WordPress Directorist plugin before 7.3.1 is susceptible to information disclosure. The pl...
CVE-2019-12987: Citrix SD-WAN Center - Remote Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2019-12987: Citrix SD-WAN Center – Remote Command Injection

漏洞标题 CVE-2019-12987: Citrix SD-WAN Center - Remote Command Injection 漏洞描述 Citrix SD-WAN Center is susceptible to remote command injection via the apply action in StorageMgm...
CVE-2022-0208: WordPress Plugin MapPress <2.73.4 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-0208: WordPress Plugin MapPress <2.73.4 - Cross-Site Scripting

漏洞标题 CVE-2022-0208: WordPress Plugin MapPress <2.73.4 - Cross-Site Scripting 漏洞描述 WordPress Plugin MapPress before version 2.73.4 does not sanitize and escape the '...
CVE-2023-0942: WordPress Japanized for WooCommerce <2.5.5 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-0942: WordPress Japanized for WooCommerce <2.5.5 - Cross-Site Scripting

漏洞标题 CVE-2023-0942: WordPress Japanized for WooCommerce <2.5.5 - Cross-Site Scripting 漏洞描述 WordPress Japanized for WooCommerce plugin before 2.5.5 is susceptible to cros...
CVE-2023-1454: Jeecg-boot 3.5.0 qurestSql - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-1454: Jeecg-boot 3.5.0 qurestSql – SQL Injection

漏洞标题 CVE-2023-1454: Jeecg-boot 3.5.0 qurestSql - SQL Injection 漏洞描述 A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part ...
CVE-2023-5089: Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)-渗透云记 - 专注于网络安全与技术分享

CVE-2023-5089: Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)

漏洞标题 CVE-2023-5089: Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page) 漏洞描述 The Defender Security WordPress plugin before 4.1.0 does not prevent redirects...
CVE-2023-32243: WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset-渗透云记 - 专注于网络安全与技术分享

CVE-2023-32243: WordPress Elementor Lite 5.7.1 – Arbitrary Password Reset

漏洞标题 CVE-2023-32243: WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset 漏洞描述 Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allo...
CVE-2024-35693: WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-35693: WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting

漏洞标题 CVE-2024-35693: WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting 漏洞描述 Code for Recovery 12 Step Meeting List versions up to 3.14.33 contain a...