最新发布第328页
CVE-2024-40422: Devika v1 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2024-40422: Devika v1 – Path Traversal

漏洞标题 CVE-2024-40422: Devika v1 - Path Traversal 漏洞描述 The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path t...
CVE-2019-5128: YouPHPTube Encoder - Arbitrary File Write-渗透云记 - 专注于网络安全与技术分享

CVE-2019-5128: YouPHPTube Encoder – Arbitrary File Write

漏洞标题 CVE-2019-5128: YouPHPTube Encoder - Arbitrary File Write 漏洞描述 Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing enc...
CVE-2017-1000028: Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2017-1000028: Oracle GlassFish Server Open Source Edition 4.1 – Local File Inclusion

漏洞标题 CVE-2017-1000028: Oracle GlassFish Server Open Source Edition 4.1 - Local File Inclusion 漏洞描述 Oracle GlassFish Server Open Source Edition 4.1 is vulnerable to both aut...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2017年3月28日 23:34
10
CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass

漏洞标题 CVE-2022-23134: Zabbix Setup Configuration Authentication Bypass 漏洞描述 After the initial setup process, some steps of setup.php file are reachable not only by super-adm...
CVE-2021-24165: WordPress Ninja Forms <3.4.34 - Open Redirect-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24165: WordPress Ninja Forms <3.4.34 - Open Redirect

漏洞标题 CVE-2021-24165: WordPress Ninja Forms <3.4.34 - Open Redirect 漏洞描述 WordPress Ninja Forms plugin before 3.4.34 contains an open redirect vulnerability via the wp_aja...
CVE-2022-29548: WSO2 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-29548: WSO2 – Cross-Site Scripting

漏洞标题 CVE-2022-29548: WSO2 - Cross-Site Scripting 漏洞描述 WSO2 contains a reflected cross-site scripting vulnerability in the Management Console of API Manager 2.2.0, 2.5.0, 2....
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年4月27日 18:06
10
CVE-2021-24849: WCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24849: WCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL Injection

漏洞标题 CVE-2021-24849: WCFM WooCommerce Multivendor Marketplace < 3.4.12 - SQL Injection 漏洞描述 The wcfm_ajax_controller AJAX action of the WCFM Marketplace WordPress plugin...
CVE-2024-11587: idcCMS V1.60 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-11587: idcCMS V1.60 – Cross-Site Scripting

漏洞标题 CVE-2024-11587: idcCMS V1.60 - Cross-Site Scripting 漏洞描述 idcCMS V1.60 is vulnerable to reflected cross-site scripting (XSS) via the idName parameter in read.php. Unsan...
 CVE-2021-31805 Struts2 S2-062远程代码执行漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2021-31805 Struts2 S2-062远程代码执行漏洞

本文转载于公众号:融云攻防实验室,原文地址: 漏洞复现 CVE-2021-31805 Struts2 S2-062远程代码执行漏洞  Struts是Apache软件基金会(ASF)赞助的一个开源项目。它最初是Jakarta项目中的一个...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年2月10日 11:26
01459
CVE-2020-13851: Artica Pandora FMS 7.44 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2020-13851: Artica Pandora FMS 7.44 – Remote Code Execution

漏洞标题 CVE-2020-13851: Artica Pandora FMS 7.44 - Remote Code Execution 漏洞描述 Artica Pandora FMS 7.44 allows remote command execution via the events feature. PoC代码
CVE-2025-41243: Spring Cloud Gateway Server Webflux - Broken Access Control-渗透云记 - 专注于网络安全与技术分享

CVE-2025-41243: Spring Cloud Gateway Server Webflux – Broken Access Control

漏洞标题 CVE-2025-41243: Spring Cloud Gateway Server Webflux - Broken Access Control 漏洞描述 Spring Cloud Gateway Server Webflux contains a vulnerability caused by unsecured and e...
一个脚本让你的app自动吐出密钥信息-渗透云记 - 专注于网络安全与技术分享

一个脚本让你的app自动吐出密钥信息

### 背景 安全小天地某个私密项目中涉及到一个app的测试,打开一看,证书校验--不让抓包,信息加密-无法篡改,遇到这种情况怎么,正常我这种小菜鸡都是直接放弃了,奈何厂家奖金给的高啊,我还...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年3月10日 23:36
080
CVE-2023-1177: MLflow get-artifact 任意文件读取漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2023-1177: MLflow get-artifact 任意文件读取漏洞

漏洞标题 CVE-2023-1177: MLflow get-artifact 任意文件读取漏洞 漏洞描述 使用 MLflow 模型注册表托管 MLflow 开源项目的用户 mlflow server或者 mlflow ui使用早于 MLflow 2.2.1 的 MLflow 版...
CVE-2020-10189: ManageEngine Desktop Central Java Deserialization-渗透云记 - 专注于网络安全与技术分享

CVE-2020-10189: ManageEngine Desktop Central Java Deserialization

漏洞标题 CVE-2020-10189: ManageEngine Desktop Central Java Deserialization 漏洞描述 Zoho ManageEngine Desktop Central before 10.0.474 is vulnerable to a deserialization of untruste...
CVE-2021-3374: Rstudio Shiny Server <1.5.16 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2021-3374: Rstudio Shiny Server <1.5.16 - Local File Inclusion

漏洞标题 CVE-2021-3374: Rstudio Shiny Server <1.5.16 - Local File Inclusion 漏洞描述 Rstudio Shiny Server prior to 1.5.16 is vulnerable to local file inclusion and source code l...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年12月15日 21:48
30
CVE-2024-6670: WhatsUp Gold HasErrors SQL Injection - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2024-6670: WhatsUp Gold HasErrors SQL Injection – Authentication Bypass

漏洞标题 CVE-2024-6670: WhatsUp Gold HasErrors SQL Injection - Authentication Bypass 漏洞描述 In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allow...
漏洞复现
漏洞复现,安全小天地的技术文章仅供参考,此文所提供的信息只为网络安全人员对自己所负责的网站、服务器等(包括但不限于)进行检测或维护参考,未经授权请勿利用文章中的技术资料对任何计算机系统进行入侵操作。利用此文所提供的信息而造成的直接或间接后果和损失,均由使用者本人负责。本文所提供的工具仅用于学习,禁止用于其他!!!
168篇文章更多文章
白帽黑客
白帽黑客网络用语中指站在黑客的立场攻击自己的系统以进行安全漏洞排查的程序员。他们用的是黑客(一般指“黑帽子黑客”)惯用的破坏攻击的方法,行的却是维护安全之事
274篇文章更多文章
渗透测试实战
在渗透测试项目中,外网的信息收集是至关重要的一个环节,外网打点信息收集全面了,可能会有四两拨千斤效果,直接突破外网边界进入内网。 子域名是域名信息收集的一个重要部分,在防御措施严密情况下我们无法直接拿下主域名,那么就可以采用迂回战术拿下子域名,然后无限靠近主域名。
22篇文章更多文章
2026年4月24日 17:11
2026年4月7日 21:49
2026年2月13日 12:53