漏洞库 第248页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2023-38952: ZKTeco BioTime <= 9.0.1 - Privilege Escalation-渗透云记 - 专注于网络安全与技术分享

CVE-2023-38952: ZKTeco BioTime <= 9.0.1 - Privilege Escalation

漏洞标题 CVE-2023-38952: ZKTeco BioTime <= 9.0.1 - Privilege Escalation 漏洞描述 BioTime default employee credentials (password 123456) allow login. Sessions are not role-valida...
CVE-2022-1442: WordPress Metform <=2.1.3 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2022-1442: WordPress Metform <=2.1.3 - Information Disclosure

漏洞标题 CVE-2022-1442: WordPress Metform <=2.1.3 - Information Disclosure 漏洞描述 WordPress Metform plugin through 2.1.3 is susceptible to information disclosure due to improp...
CVE-2021-45811: osTicket 1.15.x - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-45811: osTicket 1.15.x – SQL Injection

漏洞标题 CVE-2021-45811: osTicket 1.15.x - SQL Injection 漏洞描述 A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket ...
CVE-2025-11833: Post SMTP <= 3.6.0 - Email Log Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2025-11833: Post SMTP <= 3.6.0 - Email Log Disclosure

漏洞标题 CVE-2025-11833: Post SMTP <= 3.6.0 - Email Log Disclosure 漏洞描述 Post SMTP WordPress plugin <= 3.6.0 contains an unauthorized data access vulnerability caused by m...
CVE-2018-2893: Oracle WebLogic Server - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2018-2893: Oracle WebLogic Server – Remote Code Execution

漏洞标题 CVE-2018-2893: Oracle WebLogic Server - Remote Code Execution 漏洞描述 The Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services) versio...
CVE-2023-27639: PrestaShop TshirteCommerce - Directory Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2023-27639: PrestaShop TshirteCommerce – Directory Traversal

漏洞标题 CVE-2023-27639: PrestaShop TshirteCommerce - Directory Traversal 漏洞描述 The Custom Product Designer (tshirtecommerce) module for PrestaShop allows HTTP requests to be fo...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月6日 07:20
30
CVE-2022-44290: WebTareas 2.4p5 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-44290: WebTareas 2.4p5 – SQL Injection

漏洞标题 CVE-2022-44290: WebTareas 2.4p5 - SQL Injection 漏洞描述 webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstag...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年5月21日 22:00
30
CVE-2021-25281: SaltStack Salt <3002.5 - Auth Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2021-25281: SaltStack Salt <3002.5 - Auth Bypass

漏洞标题 CVE-2021-25281: SaltStack Salt <3002.5 - Auth Bypass 漏洞描述 SaltStack Salt before 3002.5 does not honor eauth credentials for the wheel_async client, allowing attacke...
CVE-2025-32813: Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request-渗透云记 - 专注于网络安全与技术分享

CVE-2025-32813: Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request

漏洞标题 CVE-2025-32813: Infoblox NetMRI < 7.6.1 - Unauthenticated Command Injection in get_saml_request 漏洞描述 An issue was discovered in Infoblox NETMRI before 7.6.1. Remote...
CVE-2018-17082: Apache2 - Transfer-Encoding Chunked XSS-渗透云记 - 专注于网络安全与技术分享

CVE-2018-17082: Apache2 – Transfer-Encoding Chunked XSS

漏洞标题 CVE-2018-17082: Apache2 - Transfer-Encoding Chunked XSS 漏洞描述 Apache2 PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 contain a ref...
CVE-2023-26256: STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2023-26256: STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion

漏洞标题 CVE-2023-26256: STAGIL Navigation for Jira Menu & Themes <2.0.52 - Local File Inclusion 漏洞描述 STAGIL Navigation for Jira Menu & Themes plugin before 2.0.52 i...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月12日 23:13
10
CVE-2022-40684: Fortinet FortiOS admin 远程命令执行漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2022-40684: Fortinet FortiOS admin 远程命令执行漏洞

漏洞标题 CVE-2022-40684: Fortinet FortiOS admin 远程命令执行漏洞 漏洞描述 Fortinet 周一指出,上周修补的 CVE-2022-40684 身份验证绕过安全漏洞,正在野外被广泛利用。作为管理界面上的一...
CVE-2021-20323: Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-20323: Keycloak 10.0.0 – 18.0.0 – Cross-Site Scripting

漏洞标题 CVE-2021-20323: Keycloak 10.0.0 - 18.0.0 - Cross-Site Scripting 漏洞描述 Keycloak 10.0.0 to 18.0.0 contains a cross-site scripting vulnerability via the client-registratio...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年2月24日 22:00
00
CVE-2025-0108: PAN-OS Management Interface - Path Confusion to Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-0108: PAN-OS Management Interface – Path Confusion to Authentication Bypass

漏洞标题 CVE-2025-0108: PAN-OS Management Interface - Path Confusion to Authentication Bypass 漏洞描述 A vulnerability in PAN-OS management interface allows authentication bypass t...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月10日 18:45
20
CVE-2018-3714: node-srv - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2018-3714: node-srv – Local File Inclusion

漏洞标题 CVE-2018-3714: node-srv - Local File Inclusion 漏洞描述 node-srv is vulnerable to local file inclusion due to lack of url validation, which allows a malicious user to read...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2018年6月27日 07:32
30
CVE-2023-30212: OURPHP <= 7.2.0 - Cross Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-30212: OURPHP <= 7.2.0 - Cross Site Scripting

漏洞标题 CVE-2023-30212: OURPHP <= 7.2.0 - Cross Site Scripting 漏洞描述 OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php. PoC代码