漏洞库 第122页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2024-38653: Ivanti Avalanche SmartDeviceServer - XML External Entity-渗透云记 - 专注于网络安全与技术分享

CVE-2024-38653: Ivanti Avalanche SmartDeviceServer – XML External Entity

漏洞标题 CVE-2024-38653: Ivanti Avalanche SmartDeviceServer - XML External Entity 漏洞描述 XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attack...
CVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-24329: TotoLink Router setPortForwardRules – Command Injection

漏洞标题 CVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection 漏洞描述 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vuln...
CVE-2024-3273: D-Link Network Attached Storage - Command Injection and Backdoor Account-渗透云记 - 专注于网络安全与技术分享

CVE-2024-3273: D-Link Network Attached Storage – Command Injection and Backdoor Account

漏洞标题 CVE-2024-3273: D-Link Network Attached Storage - Command Injection and Backdoor Account 漏洞描述 UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as crit...
CVE-2024-36837: CRMEB开源电商系统 /api/products SQL注入漏洞(CVE-2024-36837)-渗透云记 - 专注于网络安全与技术分享

CVE-2024-36837: CRMEB开源电商系统 /api/products SQL注入漏洞(CVE-2024-36837)

漏洞标题 CVE-2024-36837: CRMEB开源电商系统 /api/products SQL注入漏洞(CVE-2024-36837) 漏洞描述 该漏洞可以通过请求api的路径接口来进行SQL注入,进而可能导致敏感信息泄露,该注入可暴露后...
CVE-2024-6289: WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2024-6289: WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure

漏洞标题 CVE-2024-6289: WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure 漏洞描述 The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the l...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年5月13日 14:56
00
CVE-2024-55550: Mitel MiCollab - Arbitary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2024-55550: Mitel MiCollab – Arbitary File Read

漏洞标题 CVE-2024-55550: Mitel MiCollab - Arbitary File Read 漏洞描述 The Mitel Collab Arbitrary File Read vulnerability allows an unauthenticated attacker to read arbitrary files ...
CVE-2024-4040: CrushFTP VFS - Sandbox Escape LFR-渗透云记 - 专注于网络安全与技术分享

CVE-2024-4040: CrushFTP VFS – Sandbox Escape LFR

漏洞标题 CVE-2024-4040: CrushFTP VFS - Sandbox Escape LFR 漏洞描述 VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers ...
CVE-2024-6651: WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-6651: WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting

漏洞标题 CVE-2024-6651: WordPress File Upload Plugin < 4.24.8 - Cross-Site Scripting 漏洞描述 The WordPress File Upload plugin before version 4.24.8 contains a reflected cross-s...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年5月13日 03:13
00
CVE-2024-29868: Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation-渗透云记 - 专注于网络安全与技术分享

CVE-2024-29868: Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation

漏洞标题 CVE-2024-29868: Apache StreamPipes <= 0.93.0 - Use of Cryptographically Weak PRNG in Recovery Token Generation 漏洞描述 Apache StreamPipes from version 0.69.0 through 0...
CVE-2024-28255: OpenMetadata - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2024-28255: OpenMetadata – Authentication Bypass

漏洞标题 CVE-2024-28255: OpenMetadata - Authentication Bypass 漏洞描述 OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata...
ConnectWise ScreenConnect CVE-2024-1709身份验证绕过漏洞-渗透云记 - 专注于网络安全与技术分享

ConnectWise ScreenConnect CVE-2024-1709身份验证绕过漏洞

漏洞标题 ConnectWise ScreenConnect CVE-2024-1709身份验证绕过漏洞 漏洞描述 ConnectWise ScreenConnect存在身份验证绕过漏洞,此漏洞是由于对url验证不充分导致的,特殊的url可绕过验证并访...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年5月12日 06:07
00
CVE-2024-9935: PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download-渗透云记 - 专注于网络安全与技术分享

CVE-2024-9935: PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download

漏洞标题 CVE-2024-9935: PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download 漏洞描述 The PDF Generator Addon for Elementor Page Builder plugin for ...
CVE-2024-50477: WordPress Stacks Mobile App Builder <=5.2.3 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2024-50477: WordPress Stacks Mobile App Builder <=5.2.3 - Authentication Bypass

漏洞标题 CVE-2024-50477: WordPress Stacks Mobile App Builder <=5.2.3 - Authentication Bypass 漏洞描述 Stacks Mobile App Builder WordPress plugin ≤ 5.2.3 suffers from an authent...
CVE-2024-22476: Intel Neural Compressor <2.5.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-22476: Intel Neural Compressor <2.5.0 - SQL Injection

漏洞标题 CVE-2024-22476: Intel Neural Compressor <2.5.0 - SQL Injection 漏洞描述 Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may a...
CVE-2024-3234: Chuanhu Chat - Directory Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2024-3234: Chuanhu Chat – Directory Traversal

漏洞标题 CVE-2024-3234: Chuanhu Chat - Directory Traversal 漏洞描述 The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdate...
云记的头像-渗透云记 - 专注于网络安全与技术分享初心赞助云记2024年5月11日 03:56
40
CVE-2024-55416: DevDojo Voyager <=1.8.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2024-55416: DevDojo Voyager <=1.8.0 - Cross-Site Scripting

漏洞标题 CVE-2024-55416: DevDojo Voyager <=1.8.0 - Cross-Site Scripting 漏洞描述 DevDojo Voyager through version 1.8.0 is vulnerable to reflected XSS via /admin/compass. By mani...