漏洞库 第206页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2023-3188: Owncast - Server Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2023-3188: Owncast – Server Side Request Forgery

漏洞标题 CVE-2023-3188: Owncast - Server Side Request Forgery 漏洞描述 Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0. PoC代码
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年8月1日 23:31
00
CVE-2023-32007: Apache Spark远程代码执行漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2023-32007: Apache Spark远程代码执行漏洞

漏洞标题 CVE-2023-32007: Apache Spark远程代码执行漏洞 漏洞描述 Apache Spark 3.4.0之前版本存在命令注入漏洞,该漏洞源于如果ACL启用后,HttpSecurityFilter中的代码路径可以允许通过提供任...
CVE-2023-6989: Shield Security WP Plugin <= 18.5.9 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2023-6989: Shield Security WP Plugin <= 18.5.9 - Local File Inclusion

漏洞标题 CVE-2023-6989: Shield Security WP Plugin <= 18.5.9 - Local File Inclusion 漏洞描述 The Shield Security Smart Bot Blocking & Intrusion Prevention Security plugin for...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年8月1日 18:20
10
CVE-2023-43323: mooSocial 3.1.8 - External Service Interaction-渗透云记 - 专注于网络安全与技术分享

CVE-2023-43323: mooSocial 3.1.8 – External Service Interaction

漏洞标题 CVE-2023-43323: mooSocial 3.1.8 - External Service Interaction 漏洞描述 mooSocial 3.1.8 is vulnerable to external service interaction via multiple parameters in the post f...
CVE-2023-6933: Better Search Replace < 1.4.5 - PHP Object Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-6933: Better Search Replace < 1.4.5 - PHP Object Injection

漏洞标题 CVE-2023-6933: Better Search Replace < 1.4.5 - PHP Object Injection 漏洞描述 The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all...
CVE-2023-1263: Coming Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page Access-渗透云记 - 专注于网络安全与技术分享

CVE-2023-1263: Coming Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page Access

漏洞标题 CVE-2023-1263: Coming Soon & Maintenance < 4.1.7 - Unauthenticated Post/Page Access 漏洞描述 The plugin does not restrict access to published and non protected post...
CVE-2023-1671: Sophos Web Appliance - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2023-1671: Sophos Web Appliance – Remote Code Execution

漏洞标题 CVE-2023-1671: Sophos Web Appliance - Remote Code Execution 漏洞描述 A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older t...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年7月31日 23:00
30
CVE-2023-47248: PyArrow Flight RPC - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2023-47248: PyArrow Flight RPC – Remote Code Execution

漏洞标题 CVE-2023-47248: PyArrow Flight RPC - Remote Code Execution 漏洞描述 PyArrow Flight RPC from v0.14.0 through v14.0.0 allows remote attackers to execute arbitrary code via a...
CVE-2023-4284: WordPress Post Timeline Plugin < 2.2.6 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-4284: WordPress Post Timeline Plugin < 2.2.6 - Cross-Site Scripting

漏洞标题 CVE-2023-4284: WordPress Post Timeline Plugin < 2.2.6 - Cross-Site Scripting 漏洞描述 The Post Timeline WordPress plugin before version 2.2.6 contains a reflected cross...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年7月31日 14:27
30
CVE-2023-44012: mojoPortal v.2.7.0.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-44012: mojoPortal v.2.7.0.0 – Cross-Site Scripting

漏洞标题 CVE-2023-44012: mojoPortal v.2.7.0.0 - Cross-Site Scripting 漏洞描述 Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitra...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年7月31日 14:03
50
CVE-2023-2059: DedeCMS 5.7.87 - Directory Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2023-2059: DedeCMS 5.7.87 – Directory Traversal

漏洞标题 CVE-2023-2059: DedeCMS 5.7.87 - Directory Traversal 漏洞描述 Directory traversal vulnerability in DedeCMS 5.7.87 allows reading sensitive files via the $activepath paramet...
CVE-2023-27639: PrestaShop TshirteCommerce - Directory Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27639: PrestaShop TshirteCommerce – Directory Traversal

漏洞标题 CVE-2023-27639: PrestaShop TshirteCommerce - Directory Traversal 漏洞描述 The Custom Product Designer (tshirtecommerce) module for PrestaShop allows HTTP requests to be fo...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年7月31日 13:24
30
CVE-2023-27584: Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27584: Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret

漏洞标题 CVE-2023-27584: Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret 漏洞描述 Dragonfly is an open source P2P-based file distribution and image acceleration system. It is h...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年7月31日 03:16
70
CVE-2023-27179: GDidees CMS v3.9.1 - Arbitrary File Download-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27179: GDidees CMS v3.9.1 – Arbitrary File Download

漏洞标题 CVE-2023-27179: GDidees CMS v3.9.1 - Arbitrary File Download 漏洞描述 GDidees CMS v3.9.1 and lower was discovered to contain an arbitrary file download vulenrability via t...
CVE-2023-0037: WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-0037: WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injection

漏洞标题 CVE-2023-0037: WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL Injection 漏洞描述 The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does n...
CVE-2023-3139: Protect WP Admin < 4.0 - Unauthenticated Protection Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2023-3139: Protect WP Admin < 4.0 - Unauthenticated Protection Bypass

漏洞标题 CVE-2023-3139: Protect WP Admin < 4.0 - Unauthenticated Protection Bypass 漏洞描述 The Protect WP Admin WordPress plugin before version 4.0 disclosed the URL of the adm...