漏洞库 第435页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2022-31101: Prestashop Blockwishlist 2.1.0 SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-31101: Prestashop Blockwishlist 2.1.0 SQL Injection

漏洞标题 CVE-2022-31101: Prestashop Blockwishlist 2.1.0 SQL Injection 漏洞描述 Prestashop Blockwishlist module version 2.1.0 suffers from a remote authenticated SQL injection vulne...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年11月22日 00:15
10
CVE-2021-25085: WOOF WordPress plugin - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-25085: WOOF WordPress plugin – Cross-Site Scripting

漏洞标题 CVE-2021-25085: WOOF WordPress plugin - Cross-Site Scripting 漏洞描述 The WOOF WordPress plugin does not sanitize or escape the woof_redraw_elements parameter before refle...
CVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2019-19824: TOTOLINK Realtek SD Routers – Remote Command Injection

漏洞标题 CVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command Injection 漏洞描述 TOTOLINK Realtek SDK based routers may allow an authenticated attacker to execute arbitrary...
CVE-2024-6845: SmartSearchWP < 2.4.6 - OpenAI Key Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2024-6845: SmartSearchWP < 2.4.6 - OpenAI Key Disclosure

漏洞标题 CVE-2024-6845: SmartSearchWP < 2.4.6 - OpenAI Key Disclosure 漏洞描述 The plugin does not have proper authorization in one of its REST endpoint, allowing unauthenticate...
CVE-2013-7285: XStream <1.4.6/1.4.10 - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2013-7285: XStream <1.4.6/1.4.10 - Remote Code Execution

漏洞标题 CVE-2013-7285: XStream <1.4.6/1.4.10 - Remote Code Execution 漏洞描述 Xstream API before 1.4.6 and 1.4.10 is susceptible to remote code execution. If the security frame...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2013年11月10日 06:44
20
CVE-2022-29316: Complete Online Job Search System 1.0 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-29316: Complete Online Job Search System 1.0 – Cross-Site Scripting

漏洞标题 CVE-2022-29316: Complete Online Job Search System 1.0 - Cross-Site Scripting 漏洞描述 Complete Online Job Search System 1.0 contains a cross-site scripting vulnerability v...
CVE-2021-24239: WordPress Pie Register <3.7.0.1 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24239: WordPress Pie Register <3.7.0.1 - Cross-Site Scripting

漏洞标题 CVE-2021-24239: WordPress Pie Register <3.7.0.1 - Cross-Site Scripting 漏洞描述 WordPress Pie Register plugin before 3.7.0.1 is susceptible to cross-site scripting. The...
CVE-2019-5127: YouPHPTube Encoder 2.3 - Remote Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2019-5127: YouPHPTube Encoder 2.3 – Remote Command Injection

漏洞标题 CVE-2019-5127: YouPHPTube Encoder 2.3 - Remote Command Injection 漏洞描述 YouPHPTube Encoder 2.3 is susceptible to a command injection vulnerability which could allow an a...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2019年10月12日 01:58
00
CVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2024-24329: TotoLink Router setPortForwardRules – Command Injection

漏洞标题 CVE-2024-24329: TotoLink Router setPortForwardRules - Command Injection 漏洞描述 TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vuln...
CVE-2014-2323: Lighttpd 1.4.34 SQL Injection and Path Traversal-渗透云记 - 专注于网络安全与技术分享

CVE-2014-2323: Lighttpd 1.4.34 SQL Injection and Path Traversal

漏洞标题 CVE-2014-2323: Lighttpd 1.4.34 SQL Injection and Path Traversal 漏洞描述 A SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attacke...
CVE-2022-2414: Dogtag PKI XML实体注入漏洞 CVE-2022-2414-渗透云记 - 专注于网络安全与技术分享

CVE-2022-2414: Dogtag PKI XML实体注入漏洞 CVE-2022-2414

漏洞标题 CVE-2022-2414: Dogtag PKI XML实体注入漏洞 CVE-2022-2414 漏洞描述 Dogtag PKI 的XML解析器存在安全漏洞,该漏洞源于在分析 XML 文档时访问外部实体可能会导致 XML 外部实体 (XXE)...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年11月30日 08:36
80
CVE-2021-24472: Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2021-24472: Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery

漏洞标题 CVE-2021-24472: Onair2 < 3.9.9.2 & KenthaRadio < 2.0.2 - Remote File Inclusion/Server-Side Request Forgery 漏洞描述 Onair2 < 3.9.9.2 and KenthaRadio < 2.0....
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年9月4日 00:09
20
CVE-2019-7139: Magento - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2019-7139: Magento – SQL Injection

漏洞标题 CVE-2019-7139: Magento - SQL Injection 漏洞描述 An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which cause...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2019年10月27日 12:00
30
CVE-2024-54763: ipTIME A2004 - Unauthorized Access-渗透云记 - 专注于网络安全与技术分享

CVE-2024-54763: ipTIME A2004 – Unauthorized Access

漏洞标题 CVE-2024-54763: ipTIME A2004 - Unauthorized Access 漏洞描述 An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtai...
CVE-2014-4539: Movies <= 0.6 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2014-4539: Movies <= 0.6 - Cross-Site Scripting

漏洞标题 CVE-2014-4539: Movies <= 0.6 - Cross-Site Scripting 漏洞描述 A cross-site scripting vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attac...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2014年4月16日 09:34
00
CVE-2022-25481: ThinkPHP 5.0.24 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享

CVE-2022-25481: ThinkPHP 5.0.24 – Information Disclosure

漏洞标题 CVE-2022-25481: ThinkPHP 5.0.24 - Information Disclosure 漏洞描述 ThinkPHP 5.0.24 is susceptible to information disclosure. This version was configured without the PATHINF...