漏洞库 第324页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2018-10735: Nagios XI commandline.php SQL Inject-渗透云记 - 专注于网络安全与技术分享

CVE-2018-10735: Nagios XI commandline.php SQL Inject

漏洞标题 CVE-2018-10735: Nagios XI commandline.php SQL Inject 漏洞描述 Nagios XI commandline.php SQL Inject PoC代码
CVE-2022-0150: WordPress Accessibility Helper <0.6.0.7 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-0150: WordPress Accessibility Helper <0.6.0.7 - Cross-Site Scripting

漏洞标题 CVE-2022-0150: WordPress Accessibility Helper <0.6.0.7 - Cross-Site Scripting 漏洞描述 WordPress Accessibility Helper plugin before 0.6.0.7 contains a cross-site script...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年6月27日 02:58
20
CVE-2024-48248: NAKIVO Backup & Replication任意文件读取漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2024-48248: NAKIVO Backup & Replication任意文件读取漏洞

漏洞标题 CVE-2024-48248: NAKIVO Backup & Replication任意文件读取漏洞 漏洞描述 NAKIVO Backup & Replication 是一款专注于虚拟化、云端及混合环境的备份与灾难恢复的解决方案。攻击...
CVE-2010-1302: Joomla! Component DW Graph - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2010-1302: Joomla! Component DW Graph – Local File Inclusion

漏洞标题 CVE-2010-1302: Joomla! Component DW Graph - Local File Inclusion 漏洞描述 A directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) co...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2010年12月20日 02:18
20
CVE-2022-1910: WordPress Shortcodes and Extra Features for Phlox <2.9.8 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-1910: WordPress Shortcodes and Extra Features for Phlox <2.9.8 - Cross-Site Scripting

漏洞标题 CVE-2022-1910: WordPress Shortcodes and Extra Features for Phlox <2.9.8 - Cross-Site Scripting 漏洞描述 WordPress Shortcodes and extra features plugin for the Phlox the...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年1月19日 09:49
20
CVE-2021-45811: osTicket 1.15.x - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-45811: osTicket 1.15.x – SQL Injection

漏洞标题 CVE-2021-45811: osTicket 1.15.x - SQL Injection 漏洞描述 A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年12月19日 14:54
20
CVE-2021-25282: SaltStack Salt Unautherenticated Remote Command Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-25282: SaltStack Salt Unautherenticated Remote Command Execution

漏洞标题 CVE-2021-25282: SaltStack Salt Unautherenticated Remote Command Execution 漏洞描述 An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_r...
CVE-2023-25573: Metersphere - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2023-25573: Metersphere – Arbitrary File Read

漏洞标题 CVE-2023-25573: Metersphere - Arbitrary File Read 漏洞描述 Metersphere is an open source continuous testing platform. In affected versions an improper access control vulne...
CVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-61757: Oracle Identity Manager REST WebServices – Authentication Bypass

漏洞标题 CVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication Bypass 漏洞描述 Vulnerability in the Identity Manager product of Oracle Fusion Middleware (compon...
CVE-2020-17518: Apache Flink 1.5.1 - Local File Inclusion-渗透云记 - 专注于网络安全与技术分享

CVE-2020-17518: Apache Flink 1.5.1 – Local File Inclusion

漏洞标题 CVE-2020-17518: Apache Flink 1.5.1 - Local File Inclusion 漏洞描述 Apache Flink 1.5.1 is vulnerable to local file inclusion because of a REST handler that allows file uplo...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年5月12日 00:48
20
CVE-2021-24666: WordPress Podlove Podcast Publisher <3.5.6 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24666: WordPress Podlove Podcast Publisher <3.5.6 - SQL Injection

漏洞标题 CVE-2021-24666: WordPress Podlove Podcast Publisher <3.5.6 - SQL Injection 漏洞描述 WordPress Podlove Podcast Publisher plugin before 3.5.6 is susceptible to SQL inject...
CVE-2021-21972: VMware vSphere Client (HTML5) - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-21972: VMware vSphere Client (HTML5) – Remote Code Execution

漏洞标题 CVE-2021-21972: VMware vSphere Client (HTML5) - Remote Code Execution 漏洞描述 VMware vCenter vSphere Client (HTML5) contains a remote code execution vulnerability in a vC...
CVE-2024-3922: Dokan Pro <= 3.10.3 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-3922: Dokan Pro <= 3.10.3 - SQL Injection

漏洞标题 CVE-2024-3922: Dokan Pro <= 3.10.3 - SQL Injection 漏洞描述 The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all ...
CVE-2023-43326: MooSocial 3.1.8 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-43326: MooSocial 3.1.8 – Cross-Site Scripting

漏洞标题 CVE-2023-43326: MooSocial 3.1.8 - Cross-Site Scripting 漏洞描述 A reflected cross-site scripting (XSS) vulnerability exisits in multiple url of mooSocial v3.1.8 which allo...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年5月2日 13:15
20
CVE-2025-49596: MCP Inspector < 0.14.0 UnauthenticatedRemote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-49596: MCP Inspector < 0.14.0 UnauthenticatedRemote Code Execution

漏洞标题 CVE-2025-49596: MCP Inspector < 0.14.0 UnauthenticatedRemote Code Execution 漏洞描述 The MCP inspector is a developer tool for testing and debugging MCP servers. Versio...
CVE-2023-46574: TOTOLINK A3700R - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-46574: TOTOLINK A3700R – Command Injection

漏洞标题 CVE-2023-46574: TOTOLINK A3700R - Command Injection 漏洞描述 An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the ...