漏洞库 第3页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2025-2748: Kentico Xperience CMS - Unauthenticated Stored XSS-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2748: Kentico Xperience CMS – Unauthenticated Stored XSS

漏洞标题 CVE-2025-2748: Kentico Xperience CMS - Unauthenticated Stored XSS 漏洞描述 The Kentico Xperience application does not fully validate or filter files uploaded via the multi...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月19日 23:35
20
CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)

漏洞标题 CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected) 漏洞描述 The WordPress Qwizcards plugin before version 3.95 does not sanitise and escape th...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月19日 07:16
00
CVE-2025-34027: Versa Concerto API Path Based - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2025-34027: Versa Concerto API Path Based – Authentication Bypass

漏洞标题 CVE-2025-34027: Versa Concerto API Path Based - Authentication Bypass 漏洞描述 Authentication bypass in the Versa Concerto API, caused by URL decoding inconsistencies. It ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月18日 23:15
30
CVE-2025-6205: DELMIA Apriso - Broken Access Control-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6205: DELMIA Apriso – Broken Access Control

漏洞标题 CVE-2025-6205: DELMIA Apriso - Broken Access Control 漏洞描述 DELMIA Apriso Release 2020 through Release 2025 contains a broken access control vulnerability caused by miss...
CVE-2025-2011: Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2011: Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection

漏洞标题 CVE-2025-2011: Slider & Popup Builder by Depicter <= 3.6.1 - Unauthenticated SQL Injection 漏洞描述 The Slider & Popup Builder by Depicter plugin for WordPress ...
CVE-2025-4009: Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2025-4009: Evertz SDVN 3080ipx-10G – Unauthenticated Arbitrary Command Injection

漏洞标题 CVE-2025-4009: Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command Injection 漏洞描述 The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for...
CVE-2025-27007: OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation-渗透云记 - 专注于网络安全与技术分享

CVE-2025-27007: OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation

漏洞标题 CVE-2025-27007: OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation 漏洞描述 Incorrect Privilege Assignment vulnerability in Brainstorm Force SureTriggers allow...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月16日 13:30
10
CVE-2025-55523: Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download-渗透云记 - 专注于网络安全与技术分享

CVE-2025-55523: Agent-Zero 0.8.0 – 0.9.4 – Arbitrary File Download

漏洞标题 CVE-2025-55523: Agent-Zero 0.8.0 - 0.9.4 - Arbitrary File Download 漏洞描述 Agent-Zero v0.8.0 - 0.9.4 contains a path traversal caused by improper validation in /api/downl...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月16日 02:25
00
CentreStack 存在反序列化漏洞(CVE-2025-30406)-渗透云记 - 专注于网络安全与技术分享

CentreStack 存在反序列化漏洞(CVE-2025-30406)

漏洞标题 CentreStack 存在反序列化漏洞(CVE-2025-30406) 漏洞描述 CVE-2025-30406 是由 CentreStack 门户的硬编码 machineKey使用导致的反序列化漏洞。攻击者可以通过该漏洞获取服务器权限,...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月16日 01:33
30
CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected)

漏洞标题 CVE-2025-6174: WordPress Qwizcards < 3.95 - Cross-Site Scripting (Reflected) 漏洞描述 The WordPress Qwizcards plugin before version 3.95 does not sanitise and escape th...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月15日 17:09
10
CVE-2025-41243: Spring Cloud Gateway Server Webflux - Broken Access Control-渗透云记 - 专注于网络安全与技术分享

CVE-2025-41243: Spring Cloud Gateway Server Webflux – Broken Access Control

漏洞标题 CVE-2025-41243: Spring Cloud Gateway Server Webflux - Broken Access Control 漏洞描述 Spring Cloud Gateway Server Webflux contains a vulnerability caused by unsecured and e...
CVE-2025-46822: Java-springboot-codebase 1.1 - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2025-46822: Java-springboot-codebase 1.1 – Arbitrary File Read

漏洞标题 CVE-2025-46822: Java-springboot-codebase 1.1 - Arbitrary File Read 漏洞描述 OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, appl...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月15日 04:43
40
CVE-2025-22457: Ivanti Connect Secure - Stack-based Buffer Overflow-渗透云记 - 专注于网络安全与技术分享

CVE-2025-22457: Ivanti Connect Secure – Stack-based Buffer Overflow

漏洞标题 CVE-2025-22457: Ivanti Connect Secure - Stack-based Buffer Overflow 漏洞描述 Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, a...
CVE-2025-53833: LaRecipe < 2.8.1 Remote Code Execution via SSTI-渗透云记 - 专注于网络安全与技术分享

CVE-2025-53833: LaRecipe < 2.8.1 Remote Code Execution via SSTI

漏洞标题 CVE-2025-53833: LaRecipe < 2.8.1 Remote Code Execution via SSTI 漏洞描述 LaRecipe is an application that allows users to create documentation with Markdown inside a Lar...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月12日 14:47
30
(CVE-2025-9242) WatchGuard Fireware OS 未授权远程代码执行漏洞-渗透云记 - 专注于网络安全与技术分享

(CVE-2025-9242) WatchGuard Fireware OS 未授权远程代码执行漏洞

漏洞标题 (CVE-2025-9242) WatchGuard Fireware OS 未授权远程代码执行漏洞 漏洞描述 (CVE-2025-9242) WatchGuard Fireware OS 未授权远程代码执行漏洞 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月12日 14:42
10
CVE-2025-2746: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2746: Kentico Xperience 13 CMS – Staging Service Authentication Bypass (WT-2025-0011)

漏洞标题 CVE-2025-2746: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011) 漏洞描述 Before Kentico Xperience 13 Hotfix 173, this vulnerability can be e...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年12月11日 18:28
40