CVE-2021 第42页
CVE-2021-41419: QVIS NVR/DVR - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-41419: QVIS NVR/DVR – Remote Code Execution

漏洞标题 CVE-2021-41419: QVIS NVR/DVR - Remote Code Execution 漏洞描述 QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization. PoC代码
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年6月7日 17:25
30
CVE-2021-43734: kkFileView getCorsFile 任意文件读取漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2021-43734: kkFileView getCorsFile 任意文件读取漏洞

漏洞标题 CVE-2021-43734: kkFileView getCorsFile 任意文件读取漏洞 漏洞描述 kkFileView getCorsFile 3.6.0 版本以下存在任意文件读取漏洞,攻击者通过漏洞可以获取服务器中的任意文件,获取...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年3月22日 14:55
30
CVE-2021-31195: Microsoft Exchange Server - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-31195: Microsoft Exchange Server – Cross-Site Scripting

漏洞标题 CVE-2021-31195: Microsoft Exchange Server - Cross-Site Scripting 漏洞描述 Microsoft Exchange Server, or OWA, is vulnerable to a cross-site scripting vulnerability in refur...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年6月13日 17:06
30
CVE-2021-22145: Elasticsearch 7.10.0-7.13.3 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2021-22145: Elasticsearch 7.10.0-7.13.3 – Information Disclosure

漏洞标题 CVE-2021-22145: Elasticsearch 7.10.0-7.13.3 - Information Disclosure 漏洞描述 ElasticSsarch 7.10.0 to 7.13.3 is susceptible to information disclosure. A user with the abil...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年9月18日 22:57
30
CVE-2021-29441: Nacos <1.4.1 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2021-29441: Nacos <1.4.1 - Authentication Bypass

漏洞标题 CVE-2021-29441: Nacos <1.4.1 - Authentication Bypass 漏洞描述 This template only works on Nuclei engine prior to version 2.3.3 and version >= 2.3.5. In Nacos before ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年2月16日 07:02
30
CVE-2021-21345: XStream < 1.4.16 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-21345: XStream < 1.4.16 - Remote Code Execution

漏洞标题 CVE-2021-21345: XStream < 1.4.16 - Remote Code Execution 漏洞描述 XStream before 1.4.16 is susceptible to remote code execution. An attacker who has sufficient rights c...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年4月29日 07:07
30
CVE-2021-39144: XStream 1.4.18 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-39144: XStream 1.4.18 – Remote Code Execution

漏洞标题 CVE-2021-39144: XStream 1.4.18 - Remote Code Execution 漏洞描述 XStream 1.4.18 is susceptible to remote code execution. An attacker can execute commands of the host by man...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年2月17日 22:05
30
Apache Druid 远程代码执行 (CVE-2021-25646)-渗透云记 - 专注于网络安全与技术分享

Apache Druid 远程代码执行 (CVE-2021-25646)

漏洞标题 Apache Druid 远程代码执行 (CVE-2021-25646) 漏洞描述 Apache Druid 包括执行用户提供的 JavaScript 的功能嵌入在各种类型请求中的代码。此功能在用于高信任度环境中,默认已被禁用。...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年5月26日 03:13
30
(CVE-2021-26086) Atlassian Jira Server/Data Center 路径遍历漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2021-26086) Atlassian Jira Server/Data Center 路径遍历漏洞

漏洞标题 (CVE-2021-26086) Atlassian Jira Server/Data Center 路径遍历漏洞 漏洞描述 (CVE-2021-26086) Atlassian Jira Server/Data Center 路径遍历漏洞 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年5月23日 18:34
30
CVE-2021-21345: XStream < 1.4.16 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-21345: XStream < 1.4.16 - Remote Code Execution

漏洞标题 CVE-2021-21345: XStream < 1.4.16 - Remote Code Execution 漏洞描述 XStream before 1.4.16 is susceptible to remote code execution. An attacker who has sufficient rights c...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年5月12日 08:00
30
CVE-2021-21351: XStream <1.4.16 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-21351: XStream <1.4.16 - Remote Code Execution

漏洞标题 CVE-2021-21351: XStream <1.4.16 - Remote Code Execution 漏洞描述 XStream before 1.4.16 is susceptible to remote code execution. An attacker can load and execute arbitra...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年11月26日 08:39
30
CVE-2021-39144: XStream 1.4.18 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-39144: XStream 1.4.18 – Remote Code Execution

漏洞标题 CVE-2021-39144: XStream 1.4.18 - Remote Code Execution 漏洞描述 XStream 1.4.18 is susceptible to remote code execution. An attacker can execute commands of the host by man...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年6月2日 10:40
30
Apache Tapestry远程代码执行(CVE-2021-27850 )-渗透云记 - 专注于网络安全与技术分享

Apache Tapestry远程代码执行(CVE-2021-27850 )

漏洞标题 Apache Tapestry远程代码执行(CVE-2021-27850 ) 漏洞描述 Apache Tapestry 5.4.5、5.5.0、5.6.2 and 5.7.0。在CVE-2019-0195中,通过操纵classpath资产文件URL,攻击者可以在classpath...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年4月21日 23:38
30
CVE-2021-44521: Apache Cassandra Load UDF RCE-渗透云记 - 专注于网络安全与技术分享

CVE-2021-44521: Apache Cassandra Load UDF RCE

漏洞标题 CVE-2021-44521: Apache Cassandra Load UDF RCE 漏洞描述 When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年9月6日 19:29
30
CVE-2021-44228: Apache Log4j2 Remote Code Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-44228: Apache Log4j2 Remote Code Injection

漏洞标题 CVE-2021-44228: Apache Log4j2 Remote Code Injection 漏洞描述 Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect aga...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年6月15日 23:07
30
CVE-2021-22986: F5 BIG-IP iControl REST unauthenticated RCE-渗透云记 - 专注于网络安全与技术分享

CVE-2021-22986: F5 BIG-IP iControl REST unauthenticated RCE

漏洞标题 CVE-2021-22986: F5 BIG-IP iControl REST unauthenticated RCE 漏洞描述 On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年6月28日 04:00
30