漏洞库 第15页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2025-25257: Fortinet FortiWeb - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-25257: Fortinet FortiWeb – SQL Injection

漏洞标题 CVE-2025-25257: Fortinet FortiWeb - SQL Injection 漏洞描述 An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月29日 13:41
20
Commvault /commandcenter/publicLink.do 权限绕过漏洞(CVE-2025-57788)-渗透云记 - 专注于网络安全与技术分享

Commvault /commandcenter/publicLink.do 权限绕过漏洞(CVE-2025-57788)

漏洞标题 Commvault /commandcenter/publicLink.do 权限绕过漏洞(CVE-2025-57788) 漏洞描述 Commvault-WebServer是Commvault公司推出的一款网络服务器软件。该软件具有高效、安全、稳定的特点...
CVE-2025-2746: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2746: Kentico Xperience 13 CMS – Staging Service Authentication Bypass (WT-2025-0011)

漏洞标题 CVE-2025-2746: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011) 漏洞描述 Before Kentico Xperience 13 Hotfix 173, this vulnerability can be e...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月29日 12:25
10
CVE-2025-6058: WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6058: WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload

漏洞标题 CVE-2025-6058: WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload 漏洞描述 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missi...
(CVE-2025-29927) Next.js 中间件授权检查绕过漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2025-29927) Next.js 中间件授权检查绕过漏洞

漏洞标题 (CVE-2025-29927) Next.js 中间件授权检查绕过漏洞 漏洞描述 (CVE-2025-29927) Next.js 中间件授权检查绕过漏洞 PoC代码 暂无
(CVE-2025-48828) vBulletin模板条件处理任意PHP代码执行漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2025-48828) vBulletin模板条件处理任意PHP代码执行漏洞

漏洞标题 (CVE-2025-48828) vBulletin模板条件处理任意PHP代码执行漏洞 漏洞描述 (CVE-2025-48828) vBulletin模板条件处理任意PHP代码执行漏洞 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月28日 13:32
10
CVE-2025-47423: Personal Weather Station Dashboard 12 - Directory Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2025-47423: Personal Weather Station Dashboard 12 – Directory Traversal

漏洞标题 CVE-2025-47423: Personal Weather Station Dashboard 12 - Directory Traversal 漏洞描述 Personal Weather Station Dashboard 12_lts allows unauthenticated remote attackers to r...
CVE-2025-34045: WeiPHP 5.0 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34045: WeiPHP 5.0 – Path Traversal

漏洞标题 CVE-2025-34045: WeiPHP 5.0 - Path Traversal 漏洞描述 WeiPHP 5.0 contains a path traversal caused by insufficient input validation of the picUrl parameter in /public/index....
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月27日 14:55
20
CVE-2025-64446: FortiWeb - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-64446: FortiWeb – Authentication Bypass

漏洞标题 CVE-2025-64446: FortiWeb - Authentication Bypass 漏洞描述 A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, F...
CVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows – Log File Exposure

漏洞标题 CVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File Exposure 漏洞描述 Twonky Server 8.5.2 contains a broken access control vulnerability caused by bypassin...
CVE-2025-55182: React Server Components - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-55182: React Server Components – Remote Code Execution

漏洞标题 CVE-2025-55182: React Server Components - Remote Code Execution 漏洞描述 React Server Components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel, reac...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月26日 21:40
20
CVE-2025-2473 PHPGurukul 访客管理系统 2.0 SQL注入漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2473 PHPGurukul 访客管理系统 2.0 SQL注入漏洞

漏洞标题 CVE-2025-2473 PHPGurukul 访客管理系统 2.0 SQL注入漏洞 漏洞描述 CVE-2025-2473 PHPGurukul 访客管理系统 2.0 SQL注入漏洞 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月26日 13:26
10
CVE-2025-2710: Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2710: Yonyou UFIDA ERP-NC V5.0 – Cross-Site Scripting

漏洞标题 CVE-2025-2710: Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting 漏洞描述 Yonyou UFIDA ERP-NC V5.0 is vulnerable to reflected cross-site scripting (XSS) via the flag paramet...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月25日 23:31
00
CVE-2025-34291: Langflow AI <= 1.6.9 - CORS Misconfiguration-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34291: Langflow AI <= 1.6.9 - CORS Misconfiguration

漏洞标题 CVE-2025-34291: Langflow AI <= 1.6.9 - CORS Misconfiguration 漏洞描述 Langflow AI versions 1.6.9 and earlier are vulnerable to a CORS misconfiguration that allows any o...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月25日 20:59
20
CVE-2025-24752: Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2025-24752: Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting

漏洞标题 CVE-2025-24752: Essential Addons for Elementor < 6.0.15 - Cross-Site Scripting 漏洞描述 A Cross-Site Scripting (XSS) vulnerability exists in Essential Addons for Elemen...
CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4302: Stop User Enumeration WordPress plugin – Authentication Bypass

漏洞标题 CVE-2025-4302: Stop User Enumeration WordPress plugin - Authentication Bypass 漏洞描述 Stop User Enumeration WordPress plugin < 1.7.3 contains an authentication bypass ...