最新发布第920页
cPanel低于11.109.9999.116存在XSS漏洞(CVE-2023-29489)-渗透云记 - 专注于网络安全与技术分享

cPanel低于11.109.9999.116存在XSS漏洞(CVE-2023-29489)

漏洞标题 cPanel低于11.109.9999.116存在XSS漏洞(CVE-2023-29489) 漏洞描述 cPanel 是一套在网页寄存业中最享负盛名的商业软件,是基于于 Linux 和 BSD 系统及以 PHP开发且性质为闭源软件;提供...
CVE-2023-22047: Oracle Peoplesoft - Unauthenticated File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2023-22047: Oracle Peoplesoft – Unauthenticated File Read

漏洞标题 CVE-2023-22047: Oracle Peoplesoft - Unauthenticated File Read 漏洞描述 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component- Port...
CVE-2020-29597: IncomCMS 2.0 - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2020-29597: IncomCMS 2.0 – Arbitrary File Upload

漏洞标题 CVE-2020-29597: IncomCMS 2.0 - Arbitrary File Upload 漏洞描述 IncomCMS 2.0 has a an insecure file upload vulnerability in modules/uploader/showcase/script.php. This allows...
CVE-2024-6587: LiteLLM - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2024-6587: LiteLLM – Server-Side Request Forgery

漏洞标题 CVE-2024-6587: LiteLLM - Server-Side Request Forgery 漏洞描述 LiteLLM vulnerable to Server-Side Request Forgery (SSRF) vulnerability Exposes OpenAI API Keys. PoC代码
CVE-2023-50094: reNgine 2.2.0 - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-50094: reNgine 2.2.0 – Command Injection

漏洞标题 CVE-2023-50094: reNgine 2.2.0 - Command Injection 漏洞描述 reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell...
CVE-2023-3380: WAVLINK WN579X3 - Remote Command Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2023-3380: WAVLINK WN579X3 – Remote Command Execution

漏洞标题 CVE-2023-3380: WAVLINK WN579X3 - Remote Command Execution 漏洞描述 Remote Command Execution vulnerability in WAVLINK WN579X3 routers via pingIp parameter in /cgi-bin/adm.c...
CVE-2022-36553: Hytec Inter HWL-2511-SS - Remote Command Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2022-36553: Hytec Inter HWL-2511-SS – Remote Command Execution

漏洞标题 CVE-2022-36553: Hytec Inter HWL-2511-SS - Remote Command Execution 漏洞描述 Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerabi...
CVE-2023-22463: KubePi JwtSigKey - Admin Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2023-22463: KubePi JwtSigKey – Admin Authentication Bypass

漏洞标题 CVE-2023-22463: KubePi JwtSigKey - Admin Authentication Bypass 漏洞描述 KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-co...
CVE-2023-42793: JetBrains TeamCity < 2023.05.4 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2023-42793: JetBrains TeamCity < 2023.05.4 - Remote Code Execution

漏洞标题 CVE-2023-42793: JetBrains TeamCity < 2023.05.4 - Remote Code Execution 漏洞描述 In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity ...
CVE-2024-5936: PrivateGPT < 0.5.0 - Open Redirect-渗透云记 - 专注于网络安全与技术分享

CVE-2024-5936: PrivateGPT < 0.5.0 - Open Redirect

漏洞标题 CVE-2024-5936: PrivateGPT < 0.5.0 - Open Redirect 漏洞描述 An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the &...
CVE-2023-22463: KubePi JwtSigKey - Admin Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2023-22463: KubePi JwtSigKey – Admin Authentication Bypass

漏洞标题 CVE-2023-22463: KubePi JwtSigKey - Admin Authentication Bypass 漏洞描述 KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-co...
CVE-2023-27637: PrestaShop `tshirtecommerce` Module - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27637: PrestaShop `tshirtecommerce` Module – SQL Injection

漏洞标题 CVE-2023-27637: PrestaShop `tshirtecommerce` Module - SQL Injection 漏洞描述 The tshirtecommerce module for PrestaShop is vulnerable to unauthenticated SQL injection via t...
CVE-2024-3032: WordPress Themify Builder < 7.5.8 - Open Redirect-渗透云记 - 专注于网络安全与技术分享

CVE-2024-3032: WordPress Themify Builder < 7.5.8 - Open Redirect

漏洞标题 CVE-2024-3032: WordPress Themify Builder < 7.5.8 - Open Redirect 漏洞描述 The Themify Builder WordPress plugin before version 7.5.8 contains an open redirect vulnerabil...
CVE-2024-9234: GutenKit <= 2.1.0 - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2024-9234: GutenKit <= 2.1.0 - Arbitrary File Upload

漏洞标题 CVE-2024-9234: GutenKit <= 2.1.0 - Arbitrary File Upload 漏洞描述 The GutenKit Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPr...
CVE-2023-43374: Hoteldruid v3.0.5 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-43374: Hoteldruid v3.0.5 – SQL Injection

漏洞标题 CVE-2023-43374: Hoteldruid v3.0.5 - SQL Injection 漏洞描述 Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /ho...
CVE-2023-43795: GeoServer WPS - Server Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2023-43795: GeoServer WPS – Server Side Request Forgery

漏洞标题 CVE-2023-43795: GeoServer WPS - Server Side Request Forgery 漏洞描述 GeoServer is an open source software server written in Java that allows users to share and edit geospa...
漏洞复现
漏洞复现,安全小天地的技术文章仅供参考,此文所提供的信息只为网络安全人员对自己所负责的网站、服务器等(包括但不限于)进行检测或维护参考,未经授权请勿利用文章中的技术资料对任何计算机系统进行入侵操作。利用此文所提供的信息而造成的直接或间接后果和损失,均由使用者本人负责。本文所提供的工具仅用于学习,禁止用于其他!!!
168篇文章更多文章
白帽黑客
白帽黑客网络用语中指站在黑客的立场攻击自己的系统以进行安全漏洞排查的程序员。他们用的是黑客(一般指“黑帽子黑客”)惯用的破坏攻击的方法,行的却是维护安全之事
273篇文章更多文章
渗透测试实战
在渗透测试项目中,外网的信息收集是至关重要的一个环节,外网打点信息收集全面了,可能会有四两拨千斤效果,直接突破外网边界进入内网。 子域名是域名信息收集的一个重要部分,在防御措施严密情况下我们无法直接拿下主域名,那么就可以采用迂回战术拿下子域名,然后无限靠近主域名。
22篇文章更多文章
2026年4月24日 17:11
2026年4月7日 21:49
2026年2月13日 12:53