最新发布第736页
CVE-2024-48360: Qualitor <= v8.24 - Server-Side Request Forgery
漏洞标题 CVE-2024-48360: Qualitor <= v8.24 - Server-Side Request Forgery 漏洞描述 Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component...
CVE-2023-28662: WordPress Gift Cards <= 4.3.1 - SQL Injection
漏洞标题 CVE-2023-28662: Wordpress Gift Cards <= 4.3.1 - SQL Injection 漏洞描述 The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by...
CVE-2025-29925: XWiki REST API – Private Pages Disclosure
漏洞标题 CVE-2025-29925: XWiki REST API - Private Pages Disclosure 漏洞描述 A vulnerability in XWiki's REST API allows unauthenticated users to access information about privat...
CVE-2023-30625: Rudder Server < 1.3.0-rc.1 - SQL Injection
漏洞标题 CVE-2023-30625: Rudder Server < 1.3.0-rc.1 - SQL Injection 漏洞描述 Rudder-server is part of RudderStack, an open source Customer Data Platform (CDP). Versions of rudde...
CVE-2010-2037: Joomla! Component Percha Downloads Attach 1.1 – Directory Traversal
漏洞标题 CVE-2010-2037: Joomla! Component Percha Downloads Attach 1.1 - Directory Traversal 漏洞描述 A directory traversal vulnerability in the Percha Downloads Attach (com_perchad...
漏洞复现 D-Link DCS 密码泄露漏洞
漏洞描述 D-link DCS是一款网络摄像机,工作温度为0-50℃。D-link DCS系统存在密码泄露漏洞,攻击者可以根据泄露信息,进入后台 适用范围中小企业设备类型网络摄像机 图象分辨率(dpi)704×480,...
CVE-2023-4116: PHPJabbers Taxi Booking 2.0 – Cross Site Scripting
漏洞标题 CVE-2023-4116: PHPJabbers Taxi Booking 2.0 - Cross Site Scripting 漏洞描述 A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by...
CVE-2021-36580: IceWarp Mail Server – Open Redirect
漏洞标题 CVE-2021-36580: IceWarp Mail Server - Open Redirect 漏洞描述 IceWarp Mail Server contains an open redirect via the referer parameter. This can lead to phishing attacks or ...
CVE-2021-45811: osTicket 1.15.x – SQL Injection
漏洞标题 CVE-2021-45811: osTicket 1.15.x - SQL Injection 漏洞描述 A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket ...
用友U8 UploadFileData任意文件上传
本文转载于公众号:融云攻防实验室,原文地址: 用友U8 UploadFileData任意文件上传 用友GRP-U8R10行政事业财务管理软件是用友公司专注于电子政务事业,基于云计算技术所推出的新一代产品,是我...
CVE-2023-44012: mojoPortal v.2.7.0.0 – Cross-Site Scripting
漏洞标题 CVE-2023-44012: mojoPortal v.2.7.0.0 - Cross-Site Scripting 漏洞描述 Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitra...
Apache Nifi 信息泄露漏洞(CVE-2024-56512)
漏洞标题 Apache Nifi 信息泄露漏洞(CVE-2024-56512) 漏洞描述 ApacheNiFi是一款用于提取、转换和加载数据的软件工具。NiFi通过内置处理器集成了许多不同的数据类型和文件格式。通过集成FTL、S...
Chamilo LMS 存在命令执行漏洞(CVE-2023-3368)
漏洞标题 Chamilo LMS 存在命令执行漏洞(CVE-2023-3368) 漏洞描述 Chamilo是一款可供用户免费下载的学习管理软件,该软件存在命令执行漏洞,可执行任意系统命令 PoC代码 暂无
CVE-2015-4455: WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta – Arbitrary File Upload
漏洞标题 CVE-2015-4455: WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload 漏洞描述 Unrestricted file upload vulnerability in includes/up...
CVE-2024-32709: WP-Recall <= 16.26.5 - SQL Injection
漏洞标题 CVE-2024-32709: WP-Recall <= 16.26.5 - SQL Injection 漏洞描述 The WP-Recall Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injecti...
Atlassian Jira未授权访问 (CVE-2020-14179)
漏洞标题 Atlassian Jira未授权访问 (CVE-2020-14179) 漏洞描述 该漏洞源于Jira Server and DataCenter允许远程、未经身份验证的攻击者通过/secure/QueryComponent!Default中的一个信息泄露漏洞...







