CVE-2021 第116页
CVE-2021-24991: WooCommerce PDF Invoices & Packing Slips WordPress Plugin < 2.10.5 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24991: WooCommerce PDF Invoices & Packing Slips WordPress Plugin < 2.10.5 - Cross-Site Scripting

漏洞标题 CVE-2021-24991: WooCommerce PDF Invoices & Packing Slips WordPress Plugin < 2.10.5 - Cross-Site Scripting 漏洞描述 The Wordpress plugin WooCommerce PDF Invoices &am...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年8月21日 21:28
40
CVE-2021-32789: WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-32789: WooCommerce Blocks 2.5 to 5.5 – Unauthenticated SQL Injection

漏洞标题 CVE-2021-32789: WooCommerce Blocks 2.5 to 5.5 - Unauthenticated SQL Injection 漏洞描述 woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg B...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年7月7日 15:05
10
CVE-2021-24212: WooCommerce Help Scout - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24212: WooCommerce Help Scout – Arbitrary File Upload

漏洞标题 CVE-2021-24212: WooCommerce Help Scout - Arbitrary File Upload 漏洞描述 WooCommerce Help Scout plugin before version 2.9.1 contains an unrestricted file upload vulnerabili...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年8月22日 09:09
20
CVE-2021-22122: FortiWeb - Cross Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-22122: FortiWeb – Cross Site Scripting

漏洞标题 CVE-2021-22122: FortiWeb - Cross Site Scripting 漏洞描述 FortiWeb 6.3.0 through 6.3.7 and versions before 6.2.4 contain an unauthenticated cross-site scripting vulnerabili...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年10月17日 12:31
20
CVE-2021-43495: AlquistManager Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2021-43495: AlquistManager Local File Inclusion

漏洞标题 CVE-2021-43495: AlquistManager Local File Inclusion 漏洞描述 AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory travers...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年8月30日 23:43
10
CVE-2021-42192: KONGA 0.14.9 - Privilege Escalation-渗透云记 - 专注于网络安全与技术分享

CVE-2021-42192: KONGA 0.14.9 – Privilege Escalation

漏洞标题 CVE-2021-42192: KONGA 0.14.9 - Privilege Escalation 漏洞描述 KONGA 0.14.9 allows attackers to set higher privilege users to full administration access. The attack vector i...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年2月9日 16:14
20
CVE-2021-46104: webp_server_go 0.4.0 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2021-46104: webp_server_go 0.4.0 – Path Traversal

漏洞标题 CVE-2021-46104: webp_server_go 0.4.0 - Path Traversal 漏洞描述 webp_server_go 0.4.0 contains a path traversal caused by insufficient sanitization in file handling, letting...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年7月24日 16:27
10
CVE-2021-24295: Spam protection, AntiSpam, FireWall by CleanTalk < 5.153.4 - Unauthenticated Blind SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24295: Spam protection, AntiSpam, FireWall by CleanTalk < 5.153.4 - Unauthenticated Blind SQL Injection

漏洞标题 CVE-2021-24295: Spam protection, AntiSpam, FireWall by CleanTalk < 5.153.4 - Unauthenticated Blind SQL Injection 漏洞描述 It was possible to exploit an Unauthenticated ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年3月10日 02:25
10
CVE-2021-23241: MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2021-23241: MERCUSYS Mercury X18G 1.0.5 Router – Local File Inclusion

漏洞标题 CVE-2021-23241: MERCUSYS Mercury X18G 1.0.5 Router - Local File Inclusion 漏洞描述 MERCUSYS Mercury X18G 1.0.5 devices are vulnerable to local file inclusion via ../ in co...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年12月21日 05:14
60
CVE-2021-31755: Tenda Router AC11 - Remote Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-31755: Tenda Router AC11 – Remote Command Injection

漏洞标题 CVE-2021-31755: Tenda Router AC11 - Remote Command Injection 漏洞描述 Tenda Router AC11 is susceptible to remote command injection vulnerabilities in the web-based managem...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年1月8日 12:03
20
CVE-2021-35394: RealTek AP Router SDK - Arbitrary Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-35394: RealTek AP Router SDK – Arbitrary Command Injection

漏洞标题 CVE-2021-35394: RealTek AP Router SDK - Arbitrary Command Injection 漏洞描述 The SDK exposes a UDP server that allows remote execution of arbitray commands. PoC代码
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年9月26日 15:13
00
CVE-2021-41460: ECShop 4.1.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-41460: ECShop 4.1.0 – SQL Injection

漏洞标题 CVE-2021-41460: ECShop 4.1.0 - SQL Injection 漏洞描述 ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information. Po...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年7月8日 13:38
30
CVE-2021-43574: Atmail 6.5.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-43574: Atmail 6.5.0 – Cross-Site Scripting

漏洞标题 CVE-2021-43574: Atmail 6.5.0 - Cross-Site Scripting 漏洞描述 Atmail 6.5.0 contains a cross-site scripting vulnerability in WebAdmin Control Pane via the format parameter t...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年2月9日 11:39
10
CVE-2021-40868: Cloudron 6.2 Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-40868: Cloudron 6.2 Cross-Site Scripting

漏洞标题 CVE-2021-40868: Cloudron 6.2 Cross-Site Scripting 漏洞描述 In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to cross-site scripting. PoC代码
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年11月12日 22:34
10
CVE-2021-21402: Jellyfin prior to 10.7.0 Unauthenticated Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2021-21402: Jellyfin prior to 10.7.0 Unauthenticated Arbitrary File Read

漏洞标题 CVE-2021-21402: Jellyfin prior to 10.7.0 Unauthenticated Arbitrary File Read 漏洞描述 Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with cer...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年11月6日 18:37
00
CVE-2021-29490: Jellyfin 10.7.2 - Server Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2021-29490: Jellyfin 10.7.2 – Server Side Request Forgery

漏洞标题 CVE-2021-29490: Jellyfin 10.7.2 - Server Side Request Forgery 漏洞描述 Jellyfin is a free software media system. Versions 10.7.2 and below are vulnerable to unauthenticate...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年4月22日 12:10
00