漏洞库 第538页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2024-1209: LearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignments-渗透云记 - 专注于网络安全与技术分享

CVE-2024-1209: LearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignments

漏洞标题 CVE-2024-1209: LearnDash LMS < 4.10.2 - Sensitive Information Exposure via assignments 漏洞描述 The LearnDash LMS plugin for WordPress is vulnerable to Sensitive Inform...
Apache Struts S2-053 ONGL表达式注入漏洞(CVE-2017-12611)-渗透云记 - 专注于网络安全与技术分享

Apache Struts S2-053 ONGL表达式注入漏洞(CVE-2017-12611)

漏洞标题 Apache Struts S2-053 ONGL表达式注入漏洞(CVE-2017-12611) 漏洞描述 Apache Struts S2-053 ONGL表达式注入漏洞(CVE-2017-12611) PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2017年2月1日 13:26
00
CVE-2023-46805: Ivanti ICS - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2023-46805: Ivanti ICS – Authentication Bypass

漏洞标题 CVE-2023-46805: Ivanti ICS - Authentication Bypass 漏洞描述 An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure al...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年4月13日 18:53
10
CVE-2022-4140: WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access-渗透云记 - 专注于网络安全与技术分享

CVE-2022-4140: WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access

漏洞标题 CVE-2022-4140: WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access 漏洞描述 WordPress Welcart e-Commerce plugin before 2.8.5 is susceptible to arbitrary file ac...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年1月13日 14:50
00
CVE-2020-11981: Apache Airflow <=1.10.10 - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2020-11981: Apache Airflow <=1.10.10 - Command Injection

漏洞标题 CVE-2020-11981: Apache Airflow <=1.10.10 - Command Injection 漏洞描述 An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an ...
CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read

漏洞标题 CVE-2024-23897: Jenkins < 2.441 - Arbitrary File Read 漏洞描述 Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser t...
CVE-2017-17451: WordPress Mailster <=1.5.4 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2017-17451: WordPress Mailster <=1.5.4 - Cross-Site Scripting

漏洞标题 CVE-2017-17451: WordPress Mailster <=1.5.4 - Cross-Site Scripting 漏洞描述 WordPress Mailster 1.5.4 and before contains a cross-site scripting vulnerability in the unsu...
CVE-2023-20888: VMware Aria Operations for Networks - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2023-20888: VMware Aria Operations for Networks – Remote Code Execution

漏洞标题 CVE-2023-20888: VMware Aria Operations for Networks - Remote Code Execution 漏洞描述 Aria Operations for Networks contains an authenticated deserialization vulnerability. ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年4月21日 12:42
00
CVE-2022-1933: WordPress CDI <5.1.9 - Cross Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2022-1933: WordPress CDI <5.1.9 - Cross Site Scripting

漏洞标题 CVE-2022-1933: WordPress CDI <5.1.9 - Cross Site Scripting 漏洞描述 WordPress CDI plugin prior to 5.1.9 contains a cross-site scripting vulnerability. The plugin does n...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2022年1月19日 00:51
00
CVE-2020-8982: Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享

CVE-2020-8982: Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Read

漏洞标题 CVE-2020-8982: Citrix ShareFile StorageZones <=5.10.x - Arbitrary File Read 漏洞描述 Citrix ShareFile StorageZones (aka storage zones) Controller versions through at le...
Apache OFBiz CVE-2024-38856 未授权代码执行漏洞-渗透云记 - 专注于网络安全与技术分享

Apache OFBiz CVE-2024-38856 未授权代码执行漏洞

漏洞标题 Apache OFBiz CVE-2024-38856 未授权代码执行漏洞 漏洞描述 Apache OFBiz存在未授权代码执行漏洞,该漏洞是由于ProgramExport接口对用户的权限校验不当导致的。 PoC代码 暂无
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年11月28日 21:14
10
CVE-2017-14622: WordPress 2kb Amazon Affiliates Store <2.1.1 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2017-14622: WordPress 2kb Amazon Affiliates Store <2.1.1 - Cross-Site Scripting

漏洞标题 CVE-2017-14622: WordPress 2kb Amazon Affiliates Store <2.1.1 - Cross-Site Scripting 漏洞描述 WordPress 2kb Amazon Affiliates Store plugin before 2.1.1 contains multiple...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2017年3月18日 14:00
20
CVE-2023-38952: ZKTeco BioTime <= 9.0.1 - Privilege Escalation-渗透云记 - 专注于网络安全与技术分享

CVE-2023-38952: ZKTeco BioTime <= 9.0.1 - Privilege Escalation

漏洞标题 CVE-2023-38952: ZKTeco BioTime <= 9.0.1 - Privilege Escalation 漏洞描述 BioTime default employee credentials (password 123456) allow login. Sessions are not role-valida...
CVE-2022-3477: WordPress tagDiv Composer < 3.5 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享

CVE-2022-3477: WordPress tagDiv Composer < 3.5 - Authentication Bypass

漏洞标题 CVE-2022-3477: WordPress tagDiv Composer < 3.5 - Authentication Bypass 漏洞描述 The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress the...
CVE-2020-28976: WordPress Canto 1.3.0 - Blind Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享

CVE-2020-28976: WordPress Canto 1.3.0 – Blind Server-Side Request Forgery

漏洞标题 CVE-2020-28976: WordPress Canto 1.3.0 - Blind Server-Side Request Forgery 漏洞描述 WordPress Canto plugin 1.3.0 is susceptible to blind server-side request forgery. An att...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2020年8月7日 09:02
20
Adobe Commerce CVE-2024-34102 XML外部实体注入漏洞-渗透云记 - 专注于网络安全与技术分享

Adobe Commerce CVE-2024-34102 XML外部实体注入漏洞

漏洞标题 Adobe Commerce CVE-2024-34102 XML外部实体注入漏洞 漏洞描述 Adobe Commerce 存在XML外部实体注入漏洞,此漏洞是由于程序未充分验证用户输入estimate-shipping-methods的数据所导致...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2024年12月6日 05:33
00