CVE-2020 第19页
CVE-2020-13483: Bitrix24 <=20.0.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2020-13483: Bitrix24 <=20.0.0 - Cross-Site Scripting

漏洞标题 CVE-2020-13483: Bitrix24 <=20.0.0 - Cross-Site Scripting 漏洞描述 The Web Application Firewall in Bitrix24 up to and including 20.0.0 allows XSS via the items[ITEMS][ID...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月5日 04:21
50
CVE-2020-2096: Jenkins Gitlab Hook <=1.4.2 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2020-2096: Jenkins Gitlab Hook <=1.4.2 - Cross-Site Scripting

漏洞标题 CVE-2020-2096: Jenkins Gitlab Hook <=1.4.2 - Cross-Site Scripting 漏洞描述 Jenkins Gitlab Hook 1.4.2 and earlier does not escape project names in the build_now endpoint...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月4日 17:04
20
CVE-2020-7980: Satellian 1.12 Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2020-7980: Satellian 1.12 Remote Code Execution

漏洞标题 CVE-2020-7980: Satellian 1.12 Remote Code Execution 漏洞描述 厦门服云信息科技有限公司网站安全狗APACHE版存在webshell绕过漏洞,攻击者可以利用漏洞绕过网站安全狗获取服务器权限...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月4日 16:10
30
CVE-2020-8209: Citrix XenMobile Server - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2020-8209: Citrix XenMobile Server – Local File Inclusion

漏洞标题 CVE-2020-8209: Citrix XenMobile Server - Local File Inclusion 漏洞描述 Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月4日 06:35
30
CVE-2020-28185: TerraMaster TOS < 4.2.06 - User Enumeration-渗透云记 - 专注于网络安全与技术分享

CVE-2020-28185: TerraMaster TOS < 4.2.06 - User Enumeration

漏洞标题 CVE-2020-28185: TerraMaster TOS < 4.2.06 - User Enumeration 漏洞描述 User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attack...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月3日 19:08
10
CVE-2020-15920: Mida eFramework <=2.9.0 - Remote Command Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2020-15920: Mida eFramework <=2.9.0 - Remote Command Execution

漏洞标题 CVE-2020-15920: Mida eFramework <=2.9.0 - Remote Command Execution 漏洞描述 Mida eFramework through 2.9.0 allows an attacker to achieve remote code execution with admin...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月2日 04:42
10
CVE-2020-15415: DrayTek Vigor - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2020-15415: DrayTek Vigor – Command Injection

漏洞标题 CVE-2020-15415: DrayTek Vigor - Command Injection 漏洞描述 DrayTek Vigor devices contain a command injection vulnerability in the cvmcfgupload functionality. The vulnerabi...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月1日 04:01
50
CVE-2020-3580: Cisco ASA/FTD Software - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2020-3580: Cisco ASA/FTD Software – Cross-Site Scripting

漏洞标题 CVE-2020-3580: Cisco ASA/FTD Software - Cross-Site Scripting 漏洞描述 Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software ar...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月1日 01:59
20
CVE-2020-15415: DrayTek Vigor - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2020-15415: DrayTek Vigor – Command Injection

漏洞标题 CVE-2020-15415: DrayTek Vigor - Command Injection 漏洞描述 DrayTek Vigor devices contain a command injection vulnerability in the cvmcfgupload functionality. The vulnerabi...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年10月1日 01:36
00
CVE-2020-24312: WordPress Plugin File Manager (wp-file-manager) Backup Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2020-24312: WordPress Plugin File Manager (wp-file-manager) Backup Disclosure

漏洞标题 CVE-2020-24312: WordPress Plugin File Manager (wp-file-manager) Backup Disclosure 漏洞描述 mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年9月30日 21:55
20
CVE-2020-26248: PrestaShop Product Comments <4.2.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2020-26248: PrestaShop Product Comments <4.2.0 - SQL Injection

漏洞标题 CVE-2020-26248: PrestaShop Product Comments <4.2.0 - SQL Injection 漏洞描述 PrestaShop Product Comments module before version 4.2.1 contains a SQL injection vulnerabili...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年9月30日 19:37
20
CVE-2020-14882: Oracle Weblogic Server - Remote Command Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2020-14882: Oracle Weblogic Server – Remote Command Execution

漏洞标题 CVE-2020-14882: Oracle Weblogic Server - Remote Command Execution 漏洞描述 Oracle WebLogic Server contains an easily exploitable remote command execution vulnerability whi...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年9月30日 17:50
10
CVE-2020-10549: rConfig <=3.9.4 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2020-10549: rConfig <=3.9.4 - SQL Injection

漏洞标题 CVE-2020-10549: rConfig <=3.9.4 - SQL Injection 漏洞描述 rConfig 3.9.4 and prior has unauthenticated snippets.inc.php SQL injection. Because nodes' passwords are s...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年9月30日 15:57
50
CVE-2020-36731: Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update-渗透云记 - 专注于网络安全与技术分享

CVE-2020-36731: Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update

漏洞标题 CVE-2020-36731: Flexible Checkout Fields for WooCommerce <= 2.3.1 - Unauthenticated Arbitrary Plugin Settings Update 漏洞描述 The Flexible Checkout Fields for WooCommer...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年9月30日 07:48
30
CVE-2020-24285: INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2020-24285: INTELBRAS TELEFONE IP TIP200 60.61.75.22 – Local File Inclusion

漏洞标题 CVE-2020-24285: INTELBRAS TELEFONE IP TIP200 60.61.75.22 - Local File Inclusion 漏洞描述 INTELBRAS TELEFONE IP TIP200 version 60.61.75.22 is vulnerable to information disc...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年9月29日 22:45
40
CVE-2020-9054: Zyxel NAS Firmware 5.21- Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2020-9054: Zyxel NAS Firmware 5.21- Remote Code Execution

漏洞标题 CVE-2020-9054: Zyxel NAS Firmware 5.21- Remote Code Execution 漏洞描述 Multiple Zyxel network-attached storage (NAS) devices running firmware version 5.21 contain a pre-au...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年9月29日 07:59
50