排序
CVE-2024-11921: Give WP Plugin < 3.19.0 - Cross-Site Scripting
漏洞标题 CVE-2024-11921: Give WP Plugin < 3.19.0 - Cross-Site Scripting 漏洞描述 The plugin does not sanitise and escape a parameter before outputting it back in the page, leadi...
CVE-2024-35694: WordPress WPMobile.App >= 11.42 – Cross-Site Scripting
漏洞标题 CVE-2024-35694: Wordpress WPMobile.App >= 11.42 - Cross-Site Scripting 漏洞描述 WPMobile.App versions up to 11.41 contain a reflected cross-site scripting (XSS) caused ...
CVE-2024-13888: WPMobile.App <= 11.56 - Open Redirect
漏洞标题 CVE-2024-13888: WPMobile.App <= 11.56 - Open Redirect 漏洞描述 The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including...
CVE-2024-36837: CRMEB开源电商系统 /api/products SQL注入漏洞(CVE-2024-36837)
漏洞标题 CVE-2024-36837: CRMEB开源电商系统 /api/products SQL注入漏洞(CVE-2024-36837) 漏洞描述 该漏洞可以通过请求api的路径接口来进行SQL注入,进而可能导致敏感信息泄露,该注入可暴露后...
CVE-2024-6420: Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
漏洞标题 CVE-2024-6420: Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure 漏洞描述 The Hide My WP Ghost plugin does not prevent redirects to the login page via the auth_r...
CVE-2024-11587: idcCMS V1.60 – Cross-Site Scripting
漏洞标题 CVE-2024-11587: idcCMS V1.60 - Cross-Site Scripting 漏洞描述 idcCMS V1.60 is vulnerable to reflected cross-site scripting (XSS) via the idName parameter in read.php. Unsan...
CVE-2024-5276: Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection
漏洞标题 CVE-2024-5276: Fortra FileCatalyst Workflow <= v5.1.6 - SQL Injection 漏洞描述 A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modif...
CVE-2024-6555: WP Popups – Information Disclosure
漏洞标题 CVE-2024-6555: WP Popups - Information Disclosure 漏洞描述 WP Popups - WordPress Popup builder plugin for WordPress contains a full path disclosure caused by using mobiled...
CVE-2024-13496: GamiPress <= 2.8.9 - SQL Injection
漏洞标题 CVE-2024-13496: GamiPress <= 2.8.9 - SQL Injection 漏洞描述 GamiPress WordPress plugin version 2.8.9 and below suffers from an SQL injection vulnerability due to insuff...
CVE-2024-8484: REST API TO MiniProgram <= 4.7.1 - SQL Injection
漏洞标题 CVE-2024-8484: REST API TO MiniProgram <= 4.7.1 - SQL Injection 漏洞描述 The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'o...
CVE-2024-34982: LyLme-Spage – Arbitary File Upload
漏洞标题 CVE-2024-34982: LyLme-Spage - Arbitary File Upload 漏洞描述 An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attacker...
CVE-2024-47533: Cobbler ‘XML-RPC’ – Authentication Bypass
漏洞标题 CVE-2024-47533: Cobbler 'XML-RPC' - Authentication Bypass 漏洞描述 Cobbler, a Linux installation server that allows for rapid setup of network installation envir...
CVE-2024-42009: Roundcube Webmail – Cross-Site Scripting
漏洞标题 CVE-2024-42009: Roundcube Webmail - Cross-Site Scripting 漏洞描述 A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote a...
AcuToWeb 存在 XSS 漏洞(CVE-2024-42852)
漏洞标题 AcuToWeb 存在 XSS 漏洞(CVE-2024-42852) 漏洞描述 AcuToWeb v.10.5.0.7577C8b 版本存在 XSS 漏洞,该漏洞源于容易受到反射型跨站脚本攻击,允许远程攻击者通过 index.php组件执行任...
CVE-2024-0799: Arcserve Unified Data Protection – Authentication Bypass
漏洞标题 CVE-2024-0799: Arcserve Unified Data Protection - Authentication Bypass 漏洞描述 An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and ...
Arcserve Unified Data Protection CVE-2024-0801 拒绝服务漏洞
漏洞标题 Arcserve Unified Data Protection CVE-2024-0801 拒绝服务漏洞 漏洞描述 Arcserve Unified Data Protection存在拒绝服务漏洞,此漏洞是由于EdgeServiceConsoleImpl接口对用户的请求验...









