最新发布第256页
CVE-2022-22954: VMware Workspace ONE Access - Server-Side Template Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-22954: VMware Workspace ONE Access – Server-Side Template Injection

漏洞标题 CVE-2022-22954: VMware Workspace ONE Access - Server-Side Template Injection 漏洞描述 VMware Workspace ONE Access is susceptible to a remote code execution vulnerability d...
CVE-2023-40755: PHPJabbers Callback Widget v1.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-40755: PHPJabbers Callback Widget v1.0 – Cross-Site Scripting

漏洞标题 CVE-2023-40755: PHPJabbers Callback Widget v1.0 - Cross-Site Scripting 漏洞描述 There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of p...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年3月12日 15:35
50
CVE-2020-36728: WordPress Plugin Adning Advertising < 1.5.6 - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2020-36728: WordPress Plugin Adning Advertising < 1.5.6 - Arbitrary File Upload

漏洞标题 CVE-2020-36728: WordPress Plugin Adning Advertising < 1.5.6 - Arbitrary File Upload 漏洞描述 The Adning Advertising plugin for WordPress versions below 1.5.6 is vulnera...
CVE-2022-2467: Garage Management System 1.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-2467: Garage Management System 1.0 – SQL Injection

漏洞标题 CVE-2022-2467: Garage Management System 1.0 - SQL Injection 漏洞描述 Garage Management System 1.0 contains a SQL injection vulnerability in /login.php via manipulation of ...
CVE-2022-0783: Multiple Shipping Address Woocommerce < 2.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-0783: Multiple Shipping Address Woocommerce < 2.0 - SQL Injection

漏洞标题 CVE-2022-0783: Multiple Shipping Address Woocommerce < 2.0 - SQL Injection 漏洞描述 The Multiple Shipping Address Woocommerce plugin before 2.0 does not properly saniti...
CVE-2023-34537: Hoteldruid 3.0.5 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-34537: Hoteldruid 3.0.5 – Cross-Site Scripting

漏洞标题 CVE-2023-34537: Hoteldruid 3.0.5 - Cross-Site Scripting 漏洞描述 A Reflected XSS was discovered in HotelDruid version 3.0.5, an attacker can issue malicious code/command o...
CVE-2019-11886: Yellow Pencil Visual Theme Customizer < 7.2.1 - Privilege Escalation-渗透云记 - 专注于网络安全与技术分享

CVE-2019-11886: Yellow Pencil Visual Theme Customizer < 7.2.1 - Privilege Escalation

漏洞标题 CVE-2019-11886: Yellow Pencil Visual Theme Customizer < 7.2.1 - Privilege Escalation 漏洞描述 The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-cus...
Apache Tomcat SSI printenv CVE-2019-0221 跨站脚本漏洞-渗透云记 - 专注于网络安全与技术分享

Apache Tomcat SSI printenv CVE-2019-0221 跨站脚本漏洞

漏洞标题 Apache Tomcat SSI printenv CVE-2019-0221 跨站脚本漏洞 漏洞描述 Apache Tomcat SSI printenv command存在跨站脚本漏洞,此漏洞是由于应用程序对用户输入没有进行充分校验导致的。 P...
CVE-2021-26084: Confluence Server - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-26084: Confluence Server – Remote Code Execution

漏洞标题 CVE-2021-26084: Confluence Server - Remote Code Execution 漏洞描述 Confluence Server and Data Center contain an OGNL injection vulnerability that could allow an authentica...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年11月2日 22:21
50
CVE-2019-16057: D-Link DNS-320 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2019-16057: D-Link DNS-320 – Remote Code Execution

漏洞标题 CVE-2019-16057: D-Link DNS-320 - Remote Code Execution 漏洞描述 The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. PoC...
CVE-2023-37999: HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation-渗透云记 - 专注于网络安全与技术分享

CVE-2023-37999: HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation

漏洞标题 CVE-2023-37999: HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege Escalation 漏洞描述 The HT Mega plugin for WordPress is vulnerabl...
CVE-2022-2467: Garage Management System 1.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-2467: Garage Management System 1.0 – SQL Injection

漏洞标题 CVE-2022-2467: Garage Management System 1.0 - SQL Injection 漏洞描述 Garage Management System 1.0 contains a SQL injection vulnerability in /login.php via manipulation of ...
CVE-2022-0666: Microweber < 1.2.11 - CRLF Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-0666: Microweber < 1.2.11 - CRLF Injection

漏洞标题 CVE-2022-0666: Microweber < 1.2.11 - CRLF Injection 漏洞描述 CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in Pa...
CVE-2021-41773: Apache 2.4.49 - Path Traversal and Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-41773: Apache 2.4.49 – Path Traversal and Remote Code Execution

漏洞标题 CVE-2021-41773: Apache 2.4.49 - Path Traversal and Remote Code Execution 漏洞描述 A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An ...
CVE-2020-36728: WordPress Plugin Adning Advertising < 1.5.6 - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2020-36728: WordPress Plugin Adning Advertising < 1.5.6 - Arbitrary File Upload

漏洞标题 CVE-2020-36728: WordPress Plugin Adning Advertising < 1.5.6 - Arbitrary File Upload 漏洞描述 The Adning Advertising plugin for WordPress versions below 1.5.6 is vulnera...
CVE-2023-47873: WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2023-47873: WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload

漏洞标题 CVE-2023-47873: WordPress WP Child Theme Generator < 1.1.3 - Arbitrary File Upload 漏洞描述 Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutio...
漏洞复现
漏洞复现,安全小天地的技术文章仅供参考,此文所提供的信息只为网络安全人员对自己所负责的网站、服务器等(包括但不限于)进行检测或维护参考,未经授权请勿利用文章中的技术资料对任何计算机系统进行入侵操作。利用此文所提供的信息而造成的直接或间接后果和损失,均由使用者本人负责。本文所提供的工具仅用于学习,禁止用于其他!!!
168篇文章更多文章
白帽黑客
白帽黑客网络用语中指站在黑客的立场攻击自己的系统以进行安全漏洞排查的程序员。他们用的是黑客(一般指“黑帽子黑客”)惯用的破坏攻击的方法,行的却是维护安全之事
275篇文章更多文章
渗透测试实战
在渗透测试项目中,外网的信息收集是至关重要的一个环节,外网打点信息收集全面了,可能会有四两拨千斤效果,直接突破外网边界进入内网。 子域名是域名信息收集的一个重要部分,在防御措施严密情况下我们无法直接拿下主域名,那么就可以采用迂回战术拿下子域名,然后无限靠近主域名。
22篇文章更多文章
2026年4月24日 17:11
2026年4月7日 21:49
2026年2月13日 12:53