最新发布第40页
CVE-2021-29490: Jellyfin 10.7.2 – Server Side Request Forgery
漏洞标题 CVE-2021-29490: Jellyfin 10.7.2 - Server Side Request Forgery 漏洞描述 Jellyfin is a free software media system. Versions 10.7.2 and below are vulnerable to unauthenticate...
CVE-2021-29441: Nacos <1.4.1 - Authentication Bypass
漏洞标题 CVE-2021-29441: Nacos <1.4.1 - Authentication Bypass 漏洞描述 This template only works on Nuclei engine prior to version 2.3.3 and version >= 2.3.5. In Nacos before ...
CVE-2018-10818: LG NAS Devices – Remote Code Execution
漏洞标题 CVE-2018-10818: LG NAS Devices - Remote Code Execution 漏洞描述 LG NAS devices contain a pre-auth remote command injection via the "password" parameter. PoC代码
CVE-2023-25573: Metersphere – Arbitrary File Read
漏洞标题 CVE-2023-25573: Metersphere - Arbitrary File Read 漏洞描述 Metersphere is an open source continuous testing platform. In affected versions an improper access control vulne...
CVE-2018-7193: osTicket < 1.10.2 - Cross-Site Scripting
漏洞标题 CVE-2018-7193: osTicket < 1.10.2 - Cross-Site Scripting 漏洞描述 Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 al...
CVE-2023-6023: VertaAI ModelDB – Path Traversal
漏洞标题 CVE-2023-6023: VertaAI ModelDB - Path Traversal 漏洞描述 The endpoint "/api/v1/artifact/getArtifact?artifact_path=" is vulnerable to path traversal. The main cau...
CVE-2018-15531: JavaMelody XXE
漏洞标题 CVE-2018-15531: JavaMelody XXE 漏洞描述 JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. PoC代码
CVE-2022-40843: Tenda AC1200 V-W15Ev2 – Authentication Bypass
漏洞标题 CVE-2022-40843: Tenda AC1200 V-W15Ev2 - Authentication Bypass 漏洞描述 The Tenda AC1200 V-W15Ev2 router is affected by improper authorization/improper session management. ...
CVE-2024-36683: PrestaShop productsalert – SQL Injection
漏洞标题 CVE-2024-36683: PrestaShop productsalert - SQL Injection 漏洞描述 In the module 'Products Alert' (productsalert) up to version 1.7.4 from Smart Modules for Prest...
CVE-2018-12613: PhpMyAdmin 4.8.1 Remote File Inclusion
漏洞标题 CVE-2018-12613: PhpMyAdmin 4.8.1 Remote File Inclusion 漏洞描述 An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potent...
CVE-2017-12637: SAP NetWeaver Application Server Java 7.5 – Local File Inclusion
漏洞标题 CVE-2017-12637: SAP NetWeaver Application Server Java 7.5 - Local File Inclusion 漏洞描述 SAP NetWeaver Application Server Java 7.5 is susceptible to local file inclusion ...
Atlassian Jira信息泄露漏洞(CVE-2019-8449)
漏洞标题 Atlassian Jira信息泄露漏洞(CVE-2019-8449) 漏洞描述 Atlassian Jira 8.4.0之前版本/rest/api/latest/groupuserpicker接口允许远程攻击者枚举用户名,导致信息泄露。 PoC代码 暂无
CVE-2021-21307: Lucee Admin – Remote Code Execution
漏洞标题 CVE-2021-21307: Lucee Admin - Remote Code Execution 漏洞描述 Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 contains an unauthenticated remote code execution v...
CVE-2021-35587: Oracle Access Manager – Remote Code Execution
漏洞标题 CVE-2021-35587: Oracle Access Manager - Remote Code Execution 漏洞描述 The Oracle Access Manager portion of Oracle Fusion Middleware (component: OpenSSO Agent) is vulnerab...
Apache Flink 文件读取(CVE-2020-17519)
漏洞标题 Apache Flink 文件读取(CVE-2020-17519) 漏洞描述 【漏洞对象】Apache Flink 【涉及版本】Flink部分版本(1.11.0, 1.11.1, 1.11.2) \【漏洞描述】ApacheFlink是一个开源的流处理框架...
CVE-2019-10717: BlogEngine.NET 3.3.7.0 – Local File Inclusion
漏洞标题 CVE-2019-10717: BlogEngine.NET 3.3.7.0 - Local File Inclusion 漏洞描述 BlogEngine.NET 3.3.7.0 allows /api/filemanager local file inclusion via the path parameter PoC代码





