漏洞库 第224页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2023-1893: Login Configurator <=2.1 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-1893: Login Configurator <=2.1 - Cross-Site Scripting

漏洞标题 CVE-2023-1893: Login Configurator <=2.1 - Cross-Site Scripting 漏洞描述 Login Configurator WordPress plugin <= 2.1 contains a reflected cross-site scripting caused b...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年6月12日 16:24
30
CVE-2023-49105: OwnCloud - WebDAV API Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2023-49105: OwnCloud – WebDAV API Authentication Bypass

漏洞标题 CVE-2023-49105: OwnCloud - WebDAV API Authentication Bypass 漏洞描述 An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or d...
CVE-2023-32235: Ghost CMS < 5.42.1 - Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2023-32235: Ghost CMS < 5.42.1 - Path Traversal

漏洞标题 CVE-2023-32235: Ghost CMS < 5.42.1 - Path Traversal 漏洞描述 Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder v...
CVE-2023-21839: Oracle WebLogic Server - Unauthorized Access-渗透云记 - 专注于网络安全与技术分享

CVE-2023-21839: Oracle WebLogic Server – Unauthorized Access

漏洞标题 CVE-2023-21839: Oracle WebLogic Server - Unauthorized Access 漏洞描述 Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Su...
CVE-2023-34362: MOVEit Transfer - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2023-34362: MOVEit Transfer – Remote Code Execution

漏洞标题 CVE-2023-34362: MOVEit Transfer - Remote Code Execution 漏洞描述 In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年6月12日 10:56
10
CVE-2023-23488: WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-23488: WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection

漏洞标题 CVE-2023-23488: WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection 漏洞描述 WordPress Paid Memberships Pro plugin before 2.9.8 contains a blind SQL injection v...
CVE-2023-27624: WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27624: WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS

漏洞标题 CVE-2023-27624: WordPress Redirect After Login <= 0.1.9 - Admin Stored XSS 漏洞描述 Marcelotorres Redirect After Login plugin <= 0.1.9 contains a stored cross-site s...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年6月12日 01:08
00
CVE-2023-41621: Emlog Pro v2.1.14 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-41621: Emlog Pro v2.1.14 – Cross-Site Scripting

漏洞标题 CVE-2023-41621: Emlog Pro v2.1.14 - Cross-Site Scripting 漏洞描述 Cross Site Scripting (XSS) vulnerability in Emlog Pro v2.1.14 via /admin/store.php. PoC代码
CVE-2023-6553: Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2023-6553: Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution

漏洞标题 CVE-2023-6553: Worpress Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution 漏洞描述 The Backup Migration plugin for WordPress is vulnerable to Remote Cod...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年6月11日 14:16
20
CVE-2023-29827: Embedded JavaScript(EJS) 3.1.6 - Template Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-29827: Embedded JavaScript(EJS) 3.1.6 – Template Injection

漏洞标题 CVE-2023-29827: Embedded JavaScript(EJS) 3.1.6 - Template Injection 漏洞描述 ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, t...
CVE-2023-41621: Emlog Pro v2.1.14 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-41621: Emlog Pro v2.1.14 – Cross-Site Scripting

漏洞标题 CVE-2023-41621: Emlog Pro v2.1.14 - Cross-Site Scripting 漏洞描述 Cross Site Scripting (XSS) vulnerability in Emlog Pro v2.1.14 via /admin/store.php. PoC代码
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年6月11日 09:47
40
CVE-2023-44353: Adobe ColdFusion WDDX Deserialization Gadgets-渗透云记 - 专注于网络安全与技术分享

CVE-2023-44353: Adobe ColdFusion WDDX Deserialization Gadgets

漏洞标题 CVE-2023-44353: Adobe ColdFusion WDDX Deserialization Gadgets 漏洞描述 Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserial...
CVE-2023-49494: DedeCMS v5.7.111 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-49494: DedeCMS v5.7.111 – Cross-Site Scripting

漏洞标题 CVE-2023-49494: DedeCMS v5.7.111 - Cross-Site Scripting 漏洞描述 DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the c...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年6月11日 08:08
10
CVE-2023-27584: Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27584: Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret

漏洞标题 CVE-2023-27584: Dragonfly2 < 2.1.0-beta.1 - Hardcoded JWT Secret 漏洞描述 Dragonfly is an open source P2P-based file distribution and image acceleration system. It is h...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年6月11日 06:03
20
CVE-2023-0527: Online Security Guards Hiring System - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-0527: Online Security Guards Hiring System – Cross-Site Scripting

漏洞标题 CVE-2023-0527: Online Security Guards Hiring System - Cross-Site Scripting 漏洞描述 A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0 and cl...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年6月11日 03:24
40
CVE-2023-27847: PrestaShop xipblog - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27847: PrestaShop xipblog – SQL Injection

漏洞标题 CVE-2023-27847: PrestaShop xipblog - SQL Injection 漏洞描述 In the blog module (xipblog), an anonymous user can perform SQL injection. Even though the module has been patc...