漏洞库 第423页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2017-14135: OpenDreambox 2.0.0 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2017-14135: OpenDreambox 2.0.0 – Remote Code Execution

漏洞标题 CVE-2017-14135: OpenDreambox 2.0.0 - Remote Code Execution 漏洞描述 OpenDreambox 2.0.0 is susceptible to remote code execution via the webadmin plugin. Remote attackers ca...
Atlassian Confluence CVE-2023-22515 权限提升漏洞 (阶段1: 属性修改)-渗透云记 - 专注于网络安全与技术分享

Atlassian Confluence CVE-2023-22515 权限提升漏洞 (阶段1: 属性修改)

漏洞标题 Atlassian Confluence CVE-2023-22515 权限提升漏洞 (阶段1: 属性修改) 漏洞描述 Atlassian Confluence CVE-2023-22515 权限提升漏洞 (阶段1: 属性修改) 日期: 2024-02-07 | 影响软件:...
CVE-2022-22963: Spring Cloud Function SPEL 远程命令执行漏洞-渗透云记 - 专注于网络安全与技术分享

CVE-2022-22963: Spring Cloud Function SPEL 远程命令执行漏洞

漏洞标题 CVE-2022-22963: Spring Cloud Function SPEL 远程命令执行漏洞 漏洞描述 Spring Cloud Function 是基于Spring Boot 的函数计算框架,它抽象出所有传输细节和基础架构,允许开发人员保...
CVE-2020-12124: WAVLINK WN530H4 live_api.cgi - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2020-12124: WAVLINK WN530H4 live_api.cgi – Command Injection

漏洞标题 CVE-2020-12124: WAVLINK WN530H4 live_api.cgi - Command Injection 漏洞描述 A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLIN...
CVE-2024-36837: CRMEB v.5.2.2 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-36837: CRMEB v.5.2.2 – SQL Injection

漏洞标题 CVE-2024-36837: CRMEB v.5.2.2 - SQL Injection 漏洞描述 SQL Injection vulnerability in CRMEB v.5.2.2 allows a remote attacker to obtain sensitive information via the getPro...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年12月14日 02:21
20
CVE-2017-17762: Episerver 7 - Blind XML External Entity Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2017-17762: Episerver 7 – Blind XML External Entity Injection

漏洞标题 CVE-2017-17762: Episerver 7 - Blind XML External Entity Injection 漏洞描述 Episerver 7 patch 4 and earlier contains an XML external entity (XXE) caused by processing craft...
CVE-2023-34659: JeecgBoot 3.5.0 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2023-34659: JeecgBoot 3.5.0 – SQL Injection

漏洞标题 CVE-2023-34659: JeecgBoot 3.5.0 - SQL Injection 漏洞描述 jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show in...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年5月9日 20:59
30
CVE-2022-1916: WordPress Active Products Tables for WooCommerce <1.0.5 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-1916: WordPress Active Products Tables for WooCommerce <1.0.5 - Cross-Site Scripting

漏洞标题 CVE-2022-1916: WordPress Active Products Tables for WooCommerce <1.0.5 - Cross-Site Scripting 漏洞描述 WordPress Active Products Tables for WooCommerce plugin prior to ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年2月2日 01:25
10
CVE-2020-8512: IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2020-8512: IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting

漏洞标题 CVE-2020-8512: IceWarp WebMail Server <=11.4.4.1 - Cross-Site Scripting 漏洞描述 IceWarp Webmail Server through 11.4.4.1 contains a cross-site scripting vulnerability i...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年8月25日 05:13
10
CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read

漏洞标题 CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read 漏洞描述 Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser t...
CVE-2017-6090: PhpColl 2.5.1 Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享

CVE-2017-6090: PhpColl 2.5.1 Arbitrary File Upload

漏洞标题 CVE-2017-6090: PhpColl 2.5.1 Arbitrary File Upload 漏洞描述 PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file wit...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2017年5月26日 05:10
20
CVE-2023-43325: MooSocial 3.1.8 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-43325: MooSocial 3.1.8 – Cross-Site Scripting

漏洞标题 CVE-2023-43325: MooSocial 3.1.8 - Cross-Site Scripting 漏洞描述 A reflected cross-site scripting (XSS) vulnerability exisits in the data[redirect_url] parameter on user lo...
CVE-2022-22947: Spring Cloud Gateway Code Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-22947: Spring Cloud Gateway Code Injection

漏洞标题 CVE-2022-22947: Spring Cloud Gateway Code Injection 漏洞描述 Applications using Spring Cloud Gateway prior to 3.1.1+ and 3.0.7+ are vulnerable to a code injection attack w...
CVE-2020-10199: Nexus Repository before 3.21.2 allows JavaEL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2020-10199: Nexus Repository before 3.21.2 allows JavaEL Injection

漏洞标题 CVE-2020-10199: Nexus Repository before 3.21.2 allows JavaEL Injection 漏洞描述 漏洞触发需要任意账户权限 body="Nexus Repository Manager" app="Nexus-Reposito...
CVE-2024-48360: Qualitor <= v8.24 - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2024-48360: Qualitor <= v8.24 - Server-Side Request Forgery

漏洞标题 CVE-2024-48360: Qualitor <= v8.24 - Server-Side Request Forgery 漏洞描述 Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年12月28日 14:45
10
CVE-2017-18536: WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2017-18536: WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting

漏洞标题 CVE-2017-18536: WordPress Stop User Enumeration <=1.3.7 - Cross-Site Scripting 漏洞描述 WordPress Stop User Enumeration 1.3.7 and earlier are vulnerable to unauthentica...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2017年6月17日 03:37
00