排序
CVE-2024-3753: Hostel < 1.1.5.3 - Cross-Site Scripting
漏洞标题 CVE-2024-3753: Hostel < 1.1.5.3 - Cross-Site Scripting 漏洞描述 The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it...
CVE-2024-13979: St. Joe ERP system – SQL Injection
漏洞标题 CVE-2024-13979: St. Joe ERP system - SQL Injection 漏洞描述 A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenti...
CVE-2024-41713: MitelMiCollab 身份绕过导致任意文件读取漏洞
漏洞标题 CVE-2024-41713: MitelMiCollab 身份绕过导致任意文件读取漏洞 漏洞描述 Mitel MiCollab 是一个企业协作平台,它将各种通信工具整合到一个应用程序中,提供语音和视频通话、消息传递、...
CVE-2024-48766: NetAlert X – Arbitary File Read
漏洞标题 CVE-2024-48766: NetAlert X - Arbitary File Read 漏洞描述 A directory traversal vulnerability has been identified in NetAlertX versions v24.7.18 - v24.9.12. PoC代码
CVE-2024-2771: Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation
漏洞标题 CVE-2024-2771: Contact Form Plugin by Fluent Forms < 5.1.17 - Unauthenticated Limited Privilege Escalation 漏洞描述 The plugin is vulnerable to privilege escalation due...
CVE-2024-3850: Uniview NVR301-04S2-P4 – Cross-Site Scripting
漏洞标题 CVE-2024-3850: Uniview NVR301-04S2-P4 - Cross-Site Scripting 漏洞描述 Uniview NVR301-04S2-P4 contains a reflected cross-site scripting vulnerability via the PATH of LAPI. ...
CVE-2024-57514: TP-Link Archer A20 v3 Router – Cross-site Scripting
漏洞标题 CVE-2024-57514: TP-Link Archer A20 v3 Router - Cross-site Scripting 漏洞描述 The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper h...
Apache Solr /solr/admin/info/properties:/admin/info/key 权限绕过漏洞(CVE-2024-45216)
漏洞标题 Apache Solr /solr/admin/info/properties:/admin/info/key 权限绕过漏洞(CVE-2024-45216) 漏洞描述 Apache Solr是一个开源搜索服务器,使用Java语言开发,主要基于HTTP和Apache Luc...
CVE-2024-3234: Chuanhu Chat – Directory Traversal
漏洞标题 CVE-2024-3234: Chuanhu Chat - Directory Traversal 漏洞描述 The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdate...
CVE-2024-34257: TOTOLINK EX1800T TOTOLINK EX1800T – Command Injection
漏洞标题 CVE-2024-34257: TOTOLINK EX1800T TOTOLINK EX1800T - Command Injection 漏洞描述 TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType paramete...
CVE-2024-38653: Ivanti Avalanche SmartDeviceServer – XML External Entity
漏洞标题 CVE-2024-38653: Ivanti Avalanche SmartDeviceServer - XML External Entity 漏洞描述 XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attack...
CVE-2024-5057: WordPress Easy Digital Downloads <= 3.2.12 - SQL Injection
漏洞标题 CVE-2024-5057: WordPress Easy Digital Downloads <= 3.2.12 - SQL Injection 漏洞描述 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...
CVE-2024-0939: Smart S210 Management Platform – Arbitary File Upload
漏洞标题 CVE-2024-0939: Smart S210 Management Platform - Arbitary File Upload 漏洞描述 A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and cl...
CVE-2024-11728: KiviCare Clinic & Patient Management System (EHR) <= 3.6.4 - SQL Injection
漏洞标题 CVE-2024-11728: KiviCare Clinic & Patient Management System (EHR) <= 3.6.4 - SQL Injection 漏洞描述 The KiviCare Clinic & Patient Management System (EHR) plugin...
CVE-2024-35584: openSIS < 9.1 - SQL Injection
漏洞标题 CVE-2024-35584: openSIS < 9.1 - SQL Injection 漏洞描述 SQL injection vulnerability in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php i...
CVE-2024-51211: openSIS Classic v9.1 – SQL Injection
漏洞标题 CVE-2024-51211: openSIS Classic v9.1 - SQL Injection 漏洞描述 SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.ph...









