CVE-2024 第59页
CVE-2024-12824: Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change-渗透云记 - 专注于网络安全与技术分享

CVE-2024-12824: Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change

漏洞标题 CVE-2024-12824: Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change 漏洞描述 The Nokri – Job Board WordPress Theme theme for WordPr...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年3月3日 22:01
00
CVE-2024-24328: TotoLink Router setMacFilterRules - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-24328: TotoLink Router setMacFilterRules – Command Injection

漏洞标题 CVE-2024-24328: TotoLink Router setMacFilterRules - Command Injection 漏洞描述 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulner...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年2月2日 07:54
40
CVE-2024-55556: InvoiceShelf <= 1.3.0 - PHP Deserialization-渗透云记 - 专注于网络安全与技术分享

CVE-2024-55556: InvoiceShelf <= 1.3.0 - PHP Deserialization

漏洞标题 CVE-2024-55556: InvoiceShelf <= 1.3.0 - PHP Deserialization 漏洞描述 InvoiceShelf version 1.3.0 and below contains an unauthenticated PHP deserialization vulnerability ...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年5月23日 08:38
00
CVE-2024-6924: TrueBooker <= 1.0.2 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-6924: TrueBooker <= 1.0.2 - SQL Injection

漏洞标题 CVE-2024-6924: TrueBooker <= 1.0.2 - SQL Injection 漏洞描述 The TrueBooker Appointment Booking and Scheduler Plugin. plugin for WordPress is vulnerable to SQL Injection...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年2月24日 16:55
20
CVE-2024-39250: EfroTech Timetrax v8.3 - Sql Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-39250: EfroTech Timetrax v8.3 – Sql Injection

漏洞标题 CVE-2024-39250: EfroTech Timetrax v8.3 - Sql Injection 漏洞描述 EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q p...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年12月24日 10:34
30
CVE-2024-4455: YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-4455: YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting

漏洞标题 CVE-2024-4455: YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting 漏洞描述 The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年12月24日 22:56
10
CVE-2024-40711: Veeam Backup & Replication - Unauthenticated-渗透云记 - 专注于网络安全与技术分享

CVE-2024-40711: Veeam Backup & Replication – Unauthenticated

漏洞标题 CVE-2024-40711: Veeam Backup & Replication - Unauthenticated 漏洞描述 A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthent...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年2月20日 22:39
10
CVE-2024-49757: Zitadel - User Registration Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2024-49757: Zitadel – User Registration Bypass

漏洞标题 CVE-2024-49757: Zitadel - User Registration Bypass 漏洞描述 The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registr...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年3月27日 09:32
00
CVE-2024-9007: 123Solar 1.8.4.5 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-9007: 123Solar 1.8.4.5 – Cross-Site Scripting

漏洞标题 CVE-2024-9007: 123Solar 1.8.4.5 - Cross-Site Scripting 漏洞描述 123Solar 1.8.4.5 is vulnerable to reflected cross-site scripting (XSS) via the date1 parameter in detailed....
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年4月6日 17:41
10
CVE-2024-10486: Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File-渗透云记 - 专注于网络安全与技术分享

CVE-2024-10486: Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File

漏洞标题 CVE-2024-10486: Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File 漏洞描述 The Google for WooCommerce plugin for WordPress ...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年10月1日 01:05
30
CVE-2024-28000: WordPress LiteSpeed Cache - Unauthenticated Privilege Escalation to Admin-渗透云记 - 专注于网络安全与技术分享

CVE-2024-28000: WordPress LiteSpeed Cache – Unauthenticated Privilege Escalation to Admin

漏洞标题 CVE-2024-28000: WordPress LiteSpeed Cache - Unauthenticated Privilege Escalation to Admin 漏洞描述 Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies L...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年10月27日 11:21
40
CVE-2024-5522: WordPress HTML5 Video Player < 2.5.27 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-5522: WordPress HTML5 Video Player < 2.5.27 - SQL Injection

漏洞标题 CVE-2024-5522: WordPress HTML5 Video Player < 2.5.27 - SQL Injection 漏洞描述 The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a param...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年4月29日 10:49
40
CVE-2024-1512: MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-1512: MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection

漏洞标题 CVE-2024-1512: MasterStudy LMS WordPress Plugin <= 3.2.5 - SQL Injection 漏洞描述 The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordP...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年5月16日 13:30
10
CVE-2024-21650: XWiki < 4.10.20 - Remote code execution-渗透云记 - 专注于网络安全与技术分享

CVE-2024-21650: XWiki < 4.10.20 - Remote code execution

漏洞标题 CVE-2024-21650: XWiki < 4.10.20 - Remote code execution 漏洞描述 XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年5月6日 18:17
00
CVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-24329: TotoLink Router setPortForwardRules – Command Injection

漏洞标题 CVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection 漏洞描述 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vuln...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年6月6日 03:58
40
CVE-2024-3848: Mlflow < 2.11.0 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2024-3848: Mlflow < 2.11.0 - Path Traversal

漏洞标题 CVE-2024-3848: Mlflow < 2.11.0 - Path Traversal 漏洞描述 A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previousl...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年5月6日 16:09
00