CVE-2024 第49页
CVE-2024-49757: Zitadel - User Registration Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2024-49757: Zitadel – User Registration Bypass

漏洞标题 CVE-2024-49757: Zitadel - User Registration Bypass 漏洞描述 The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registr...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年2月5日 13:18
30
CVE-2024-7954: SPIP Porte Plume Plugin - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2024-7954: SPIP Porte Plume Plugin – Remote Code Execution

漏洞标题 CVE-2024-7954: SPIP Porte Plume Plugin - Remote Code Execution 漏洞描述 The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbi...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年12月6日 03:24
30
CVE-2024-21485: Dash Framework - Cross-site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-21485: Dash Framework – Cross-site Scripting

漏洞标题 CVE-2024-21485: Dash Framework - Cross-site Scripting 漏洞描述 Dash framework versions before 2.15.0 are vulnerable to Cross-site Scripting (XSS) via href attribute in anc...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年3月7日 07:04
30
CVE-2024-0012: Palo Alto Networks PAN-OS身份认证绕过导致RCE漏洞(CVE-2024-0012)-渗透云记 - 专注于网络安全与技术分享

CVE-2024-0012: Palo Alto Networks PAN-OS身份认证绕过导致RCE漏洞(CVE-2024-0012)

漏洞标题 CVE-2024-0012: Palo Alto Networks PAN-OS身份认证绕过导致RCE漏洞(CVE-2024-0012) 漏洞描述 PAN-OS 设备管理 Web 界面中存在身份认证绕过漏洞,未经身份验证的远程攻击者可以通过网...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年3月6日 05:50
30
CVE-2024-9465: Palo Alto Expedition - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-9465: Palo Alto Expedition – SQL Injection

漏洞标题 CVE-2024-9465: Palo Alto Expedition - SQL Injection 漏洞描述 An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal E...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年6月17日 20:29
30
CVE-2024-41628: Cluster Control CMON API - Directory Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2024-41628: Cluster Control CMON API – Directory Traversal

漏洞标题 CVE-2024-41628: Cluster Control CMON API - Directory Traversal 漏洞描述 Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 be...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年12月21日 18:06
30
CVE-2024-32640: Mura/Masa CMS - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-32640: Mura/Masa CMS – SQL Injection

漏洞标题 CVE-2024-32640: Mura/Masa CMS - SQL Injection 漏洞描述 The Mura/Masa CMS is vulnerable to SQL Injection. PoC代码
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年12月26日 23:30
30
CVE-2024-38472: Apache HTTPd Windows UNC - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2024-38472: Apache HTTPd Windows UNC – Server-Side Request Forgery

漏洞标题 CVE-2024-38472: Apache HTTPd Windows UNC - Server-Side Request Forgery 漏洞描述 SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年1月21日 18:46
30
CVE-2024-4956: Sonatype Nexus Repository Manager 3 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2024-4956: Sonatype Nexus Repository Manager 3 – Local File Inclusion

漏洞标题 CVE-2024-4956: Sonatype Nexus Repository Manager 3 - Local File Inclusion 漏洞描述 Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年5月18日 01:37
30
CVE-2024-9166: TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2024-9166: TitanNit Web Control 2.01/Atemio 7600 – Remote Code Execution

漏洞标题 CVE-2024-9166: TitanNit Web Control 2.01/Atemio 7600 - Remote Code Execution 漏洞描述 The device contains a command injection caused by the 'getcommand' query in...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年10月3日 03:31
30
CVE-2024-9061: WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2024-9061: WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode Execution

漏洞标题 CVE-2024-9061: WP Popup Builder Popup Forms and Marketing Lead Generation <= 1.3.5 - Arbitrary Shortcode Execution 漏洞描述 The The WP Popup Builder Popup Forms and Mar...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年6月6日 17:10
30
CVE-2024-35219: OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete-渗透云记 - 专注于网络安全与技术分享

CVE-2024-35219: OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete

漏洞标题 CVE-2024-35219: OpenAPI Generator <= 7.5.0 - Arbitrary File Read/Delete 漏洞描述 OpenAPI Generator versions 7.5.0 and below are prone to an Arbitrary File Read/Delete v...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年4月3日 08:46
30
CVE-2024-7313: Shield Security Plugin < 20.0.6 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-7313: Shield Security Plugin < 20.0.6 - Cross-Site Scripting

漏洞标题 CVE-2024-7313: Shield Security Plugin < 20.0.6 - Cross-Site Scripting 漏洞描述 The Shield Security WordPress plugin before 20.0.6 contains a reflected cross-site script...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年1月21日 22:46
30
CVE-2024-5765: WpStickyBar <= 2.1.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-5765: WpStickyBar <= 2.1.0 - SQL Injection

漏洞标题 CVE-2024-5765: WpStickyBar <= 2.1.0 - SQL Injection 漏洞描述 The plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年6月16日 13:15
30
CVE-2024-40711: Veeam Backup & Replication - Unauthenticated-渗透云记 - 专注于网络安全与技术分享

CVE-2024-40711: Veeam Backup & Replication – Unauthenticated

漏洞标题 CVE-2024-40711: Veeam Backup & Replication - Unauthenticated 漏洞描述 A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthent...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年4月17日 07:11
30
CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read

漏洞标题 CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read 漏洞描述 Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser t...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年12月21日 01:46
30