漏洞库 第186页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2023-0527: Online Security Guards Hiring System - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-0527: Online Security Guards Hiring System – Cross-Site Scripting

漏洞标题 CVE-2023-0527: Online Security Guards Hiring System - Cross-Site Scripting 漏洞描述 A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and cl...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月30日 18:40
30
CVE-2023-28435: File upload interface does not do permission verification exists XSS vulnerability-渗透云记 - 专注于网络安全与技术分享

CVE-2023-28435: File upload interface does not do permission verification exists XSS vulnerability

漏洞标题 CVE-2023-28435: File upload interface does not do permission verification exists XSS vulnerability 漏洞描述 The file upload interface is not checked for permissions, so us...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月30日 18:40
20
CVE-2023-32243: WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset-渗透云记 - 专注于网络安全与技术分享

CVE-2023-32243: WordPress Elementor Lite 5.7.1 – Arbitrary Password Reset

漏洞标题 CVE-2023-32243: WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset 漏洞描述 Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allo...
Atlassian Confluence CVE-2023-22527 远程命令执行漏洞-渗透云记 - 专注于网络安全与技术分享

Atlassian Confluence CVE-2023-22527 远程命令执行漏洞

漏洞标题 Atlassian Confluence CVE-2023-22527 远程命令执行漏洞 漏洞描述 Atlassian Confluence存在远程命令执行漏洞,此漏洞是对用户的数据缺乏校验导致的。 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月30日 14:49
00
CVE-2023-7116: WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-7116: WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection

漏洞标题 CVE-2023-7116: WeiYe-Jing datax-web <= 2.1.2 - OS Command Injection 漏洞描述 A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2...
Apache Superset Cookie 权限绕过漏洞(CVE-2023-27524)-渗透云记 - 专注于网络安全与技术分享

Apache Superset Cookie 权限绕过漏洞(CVE-2023-27524)

漏洞标题 Apache Superset Cookie 权限绕过漏洞(CVE-2023-27524) 漏洞描述 Apache Superset 是一个开源的现代数据探索和可视化平台。Apache Superset Cookie 存在权限绕过漏洞,攻击者可通过...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月29日 19:13
30
CVE-2023-4542: D-Link DAR-8000-10 - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-4542: D-Link DAR-8000-10 – Command Injection

漏洞标题 CVE-2023-4542: D-Link DAR-8000-10 - Command Injection 漏洞描述 D-Link DAR-8000-10 version has an operating system command injection vulnerability. The vulnerability origin...
Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518)-渗透云记 - 专注于网络安全与技术分享

Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518)

漏洞标题 Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518) 漏洞描述 Atlassian Confluence是一款企业知识管理与协作软件。该漏洞存在于Atlassian Confluence...
CVE-2023-2825: GitLab 16.0.0 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2023-2825: GitLab 16.0.0 – Path Traversal

漏洞标题 CVE-2023-2825: GitLab 16.0.0 - Path Traversal 漏洞描述 An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can us...
CVE-2023-3849: mooDating 1.2 - Cross-site scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-3849: mooDating 1.2 – Cross-site scripting

漏洞标题 CVE-2023-3849: mooDating 1.2 - Cross-site scripting 漏洞描述 A vulnerability, which was classified as problematic, was found in mooSocial mooDating 1.2. Affected is an unk...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月29日 03:45
30
CVE-2023-38879: openSIS v9.0 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2023-38879: openSIS v9.0 – Path Traversal

漏洞标题 CVE-2023-38879: openSIS v9.0 - Path Traversal 漏洞描述 A path traversal vulnerability exists in openSIS Classic Community Edition v9.0 via the 'filename' paramet...
CVE-2023-28662: Wordpress Gift Cards <= 4.3.1 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-28662: WordPress Gift Cards <= 4.3.1 - SQL Injection

漏洞标题 CVE-2023-28662: Wordpress Gift Cards <= 4.3.1 - SQL Injection 漏洞描述 The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by...
CVE-2023-35078: Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2023-35078: Ivanti Endpoint Manager Mobile (EPMM) – Authentication Bypass

漏洞标题 CVE-2023-35078: Ivanti Endpoint Manager Mobile (EPMM) - Authentication Bypass 漏洞描述 Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, through 11.10 allow...
CVE-2023-0678: PHPIPAM <v1.5.1 - Missing Authorization-渗透云记 - 专注于网络安全与技术分享
CVE-2023-38501: CopyParty v1.8.6 - Cross Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-38501: CopyParty v1.8.6 – Cross Site Scripting

漏洞标题 CVE-2023-38501: CopyParty v1.8.6 - Cross Site Scripting 漏洞描述 Copyparty is a portable file server. Versions prior to 1.8.6 are subject to a reflected cross-site scripti...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月27日 23:04
40
CVE-2023-3345: LMS by Masteriyo < 1.6.8 - Information Exposure-渗透云记 - 专注于网络安全与技术分享

CVE-2023-3345: LMS by Masteriyo < 1.6.8 - Information Exposure

漏洞标题 CVE-2023-3345: LMS by Masteriyo < 1.6.8 - Information Exposure 漏洞描述 The plugin does not properly safeguards sensitive user information, like other user's email...