CVE-2024 第29页
CVE-2024-23917: JetBrains TeamCity > 2023.11.3 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2024-23917: JetBrains TeamCity > 2023.11.3 – Authentication Bypass

漏洞标题 CVE-2024-23917: JetBrains TeamCity > 2023.11.3 - Authentication Bypass 漏洞描述 In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年5月31日 20:58
30
Apache OFBiz StatsSinceStart 远程代码执行漏洞(CVE-2024-45507)-渗透云记 - 专注于网络安全与技术分享

Apache OFBiz StatsSinceStart 远程代码执行漏洞(CVE-2024-45507)

漏洞标题 Apache OFBiz StatsSinceStart 远程代码执行漏洞(CVE-2024-45507) 漏洞描述 Apache OFBiz 18.12.16 之前的版本在 Linux 和 Windows 系统上存在未经身份验证的远程代码执行漏洞。 PoC...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年7月16日 10:20
20
CVE-2024-8529: LearnPress < 4.2.7.1 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-8529: LearnPress < 4.2.7.1 - SQL Injection

漏洞标题 CVE-2024-8529: LearnPress < 4.2.7.1 - SQL Injection 漏洞描述 The LearnPress WordPress LMS Plugin before 4.2.7.1 is vulnerable to unauthenticated SQL injection via the &...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年10月18日 07:48
30
CVE-2024-6651: WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-6651: WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting

漏洞标题 CVE-2024-6651: WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting 漏洞描述 The WordPress File Upload plugin before version 4.24.8 contains a reflected cross-s...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年5月19日 07:51
10
CVE-2024-3032: WordPress Themify Builder < 7.5.8 - Open Redirect-渗透云记 - 专注于网络安全与技术分享

CVE-2024-3032: WordPress Themify Builder < 7.5.8 - Open Redirect

漏洞标题 CVE-2024-3032: WordPress Themify Builder < 7.5.8 - Open Redirect 漏洞描述 The Themify Builder WordPress plugin before version 7.5.8 contains an open redirect vulnerabil...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年6月21日 16:47
10
CVE-2024-27954: WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF-渗透云记 - 专注于网络安全与技术分享

CVE-2024-27954: WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF

漏洞标题 CVE-2024-27954: WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF 漏洞描述 WordPress Automatic plugin <3.92.1 is vulnerable to unauthenticated Ar...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年8月27日 22:18
30
CVE-2024-35693: WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-35693: WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting

漏洞标题 CVE-2024-35693: WordPress 12 Step Meeting List Plugin <= 3.14.33 - Cross-Site Scripting 漏洞描述 Code for Recovery 12 Step Meeting List versions up to 3.14.33 contain a...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年2月23日 23:28
10
CVE-2024-1061: WordPress HTML5 Video Player - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-1061: WordPress HTML5 Video Player – SQL Injection

漏洞标题 CVE-2024-1061: WordPress HTML5 Video Player - SQL Injection 漏洞描述 WordPress HTML5 Video Player plugin is vulnerable to SQL injection. An unauthenticated attacker can ex...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年1月10日 08:25
10
CVE-2024-55550: Mitel MiCollab - Arbitary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2024-55550: Mitel MiCollab – Arbitary File Read

漏洞标题 CVE-2024-55550: Mitel MiCollab - Arbitary File Read 漏洞描述 The Mitel Collab Arbitrary File Read vulnerability allows an unauthenticated attacker to read arbitrary files ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年5月13日 09:09
30
CVE-2024-4956: Nexus Repository Manager 文件读取漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2024-4956: Nexus Repository Manager 文件读取漏洞

漏洞标题 CVE-2024-4956: Nexus Repository Manager 文件读取漏洞 漏洞描述 Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年1月23日 04:07
60
CVE-2024-6586: Lightdash v0.1024.6 - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2024-6586: Lightdash v0.1024.6 – Server-Side Request Forgery

漏洞标题 CVE-2024-6586: Lightdash v0.1024.6 - Server-Side Request Forgery 漏洞描述 Server-Side Request Forgery (“SSRF”) in the export dashboard functionality of Lightdash version...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年7月22日 08:58
50
CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read

漏洞标题 CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read 漏洞描述 Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser t...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年7月19日 12:43
30
CVE-2024-9796: WordPress WP-Advanced-Search <= 3.3.9 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-9796: WordPress WP-Advanced-Search <= 3.3.9 - SQL Injection

漏洞标题 CVE-2024-9796: WordPress WP-Advanced-Search <= 3.3.9 - SQL Injection 漏洞描述 The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to SQL Injection in al...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年6月21日 02:35
10
CVE-2024-11305: Altenergy Power Control Software - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-11305: Altenergy Power Control Software – SQL Injection

漏洞标题 CVE-2024-11305: Altenergy Power Control Software - SQL Injection 漏洞描述 A vulnerability classified as critical was found in Altenergy Power Control Software up to 202411...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年5月5日 18:36
40
CVE-2024-51568: CyberPanel - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-51568: CyberPanel – Command Injection

漏洞标题 CVE-2024-51568: CyberPanel - Command Injection 漏洞描述 CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputE...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年10月12日 03:59
60
Adobe ColdFusion CVE-2024-20767 任意文件读取漏洞-渗透云记 - 专注于网络安全与技术分享

Adobe ColdFusion CVE-2024-20767 任意文件读取漏洞

漏洞标题 Adobe ColdFusion CVE-2024-20767 任意文件读取漏洞 漏洞描述 Adobe ColdFusion中存在任意文件读取漏洞,此漏洞是由于未充分验证用户输入file_name参数的数据所导致的。 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年4月11日 15:53
50