漏洞库 第715页
此分类不是0day,只是做互联网poc收集,不对poc真实性、可用性做保证,不以poc无效等理由反馈退款
CVE-2023-28121: WooCommerce Payments - Unauthorized Admin Access-渗透云记 - 专注于网络安全与技术分享

CVE-2023-28121: WooCommerce Payments – Unauthorized Admin Access

漏洞标题 CVE-2023-28121: WooCommerce Payments - Unauthorized Admin Access 漏洞描述 An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauth...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年9月27日 08:05
30
CVE-2022-25061: TP-Link TL-WR840N - Command Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-25061: TP-Link TL-WR840N – Command Injection

漏洞标题 CVE-2022-25061: TP-Link TL-WR840N - Command Injection 漏洞描述 The TP-Link TL-WR840N(ES)_V6.20_180709 router contains a command injection vulnerability in the oal_setIp6De...
CVE-2021-34427: Eclipse BIRT Viewer - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-34427: Eclipse BIRT Viewer – Remote Code Execution

漏洞标题 CVE-2021-34427: Eclipse BIRT Viewer - Remote Code Execution 漏洞描述 Eclipse BIRT versions 4.8.0 and earlier contain a JSP injection caused by query parameters, letting re...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年3月7日 08:46
20
CVE-2025-2746: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011)-渗透云记 - 专注于网络安全与技术分享

CVE-2025-2746: Kentico Xperience 13 CMS – Staging Service Authentication Bypass (WT-2025-0011)

漏洞标题 CVE-2025-2746: Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0011) 漏洞描述 Before Kentico Xperience 13 Hotfix 173, this vulnerability can be e...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年9月29日 12:25
20
CVE-2018-20462: WordPress JSmol2WP <=1.07 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2018-20462: WordPress JSmol2WP <=1.07 - Cross-Site Scripting

漏洞标题 CVE-2018-20462: WordPress JSmol2WP <=1.07 - Cross-Site Scripting 漏洞描述 WordPress JSmol2WP version 1.07 and earlier is vulnerable to cross-site scripting and allows r...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2018年7月22日 16:03
20
Apache OFBiz webtools/control/xmlrpc 远程代码执行漏洞(CVE-2023-49070)-渗透云记 - 专注于网络安全与技术分享

Apache OFBiz webtools/control/xmlrpc 远程代码执行漏洞(CVE-2023-49070)

漏洞标题 Apache OFBiz webtools/control/xmlrpc 远程代码执行漏洞(CVE-2023-49070) 漏洞描述 Apache OFBiz是一个开源的企业资源规划(ERP)系统,提供了多种商业功能和模块。Apache OFBiz 在...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年10月2日 21:38
00
CVE-2022-3768: WordPress WPSmartContracts <1.3.12 - SQL Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-3768: WordPress WPSmartContracts <1.3.12 - SQL Injection

漏洞标题 CVE-2022-3768: WordPress WPSmartContracts <1.3.12 - SQL Injection 漏洞描述 WordPress WPSmartContracts plugin before 1.3.12 contains a SQL injection vulnerability. The p...
CVE-2021-41773: Apache 2.4.49 - Path Traversal and Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2021-41773: Apache 2.4.49 – Path Traversal and Remote Code Execution

漏洞标题 CVE-2021-41773: Apache 2.4.49 - Path Traversal and Remote Code Execution 漏洞描述 A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2021年3月12日 05:02
20
CVE-2025-55182: React Server Components - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享

CVE-2025-55182: React Server Components – Remote Code Execution

漏洞标题 CVE-2025-55182: React Server Components - Remote Code Execution 漏洞描述 React Server Components 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including react-server-dom-parcel, reac...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年10月10日 08:04
20
CVE-2018-13380: Fortinet FortiOS - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2018-13380: Fortinet FortiOS – Cross-Site Scripting

漏洞标题 CVE-2018-13380: Fortinet FortiOS - Cross-Site Scripting 漏洞描述 Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4.0 to 5.4.12, 5.2 and below versions under SSL VPN web...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2018年8月6日 01:06
30
CVE-2023-4116: PHPJabbers Taxi Booking 2.0 - Cross Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-4116: PHPJabbers Taxi Booking 2.0 – Cross Site Scripting

漏洞标题 CVE-2023-4116: PHPJabbers Taxi Booking 2.0 - Cross Site Scripting 漏洞描述 A vulnerability classified as problematic was found in PHP Jabbers Taxi Booking 2.0. Affected by...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年10月7日 07:21
20
CVE-2022-29078: Node.js Embedded JavaScript 3.1.6 - Template Injection-渗透云记 - 专注于网络安全与技术分享

CVE-2022-29078: Node.js Embedded JavaScript 3.1.6 – Template Injection

漏洞标题 CVE-2022-29078: Node.js Embedded JavaScript 3.1.6 - Template Injection 漏洞描述 Node.js Embedded JavaScript 3.1.6 is susceptible to server-side template injection via sett...
CVE-2021-25161: Aruba Instant Access Point (IAP) - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2021-25161: Aruba Instant Access Point (IAP) – Cross-Site Scripting

漏洞标题 CVE-2021-25161: Aruba Instant Access Point (IAP) - Cross-Site Scripting 漏洞描述 A remote cross-site scripting (xss) vulnerability was discovered in some Aruba Instant Acc...
CVE-2025-46819: Redis  < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read-渗透云记 - 专注于网络安全与技术分享

CVE-2025-46819: Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read

漏洞标题 CVE-2025-46819: Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds Read 漏洞描述 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 ...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2025年10月22日 11:25
00
CVE-2018-5715: SugarCRM 3.5.1 - Cross-Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2018-5715: SugarCRM 3.5.1 – Cross-Site Scripting

漏洞标题 CVE-2018-5715: SugarCRM 3.5.1 - Cross-Site Scripting 漏洞描述 SugarCRM 3.5.1 is vulnerable to cross-site scripting via phprint.php and a parameter name in the query string...
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2018年8月16日 23:05
00
CVE-2023-30212: OURPHP <= 7.2.0 - Cross Site Scripting-渗透云记 - 专注于网络安全与技术分享

CVE-2023-30212: OURPHP <= 7.2.0 - Cross Site Scripting

漏洞标题 CVE-2023-30212: OURPHP <= 7.2.0 - Cross Site Scripting 漏洞描述 OURPHP <= 7.2.0 is vulnerale to Cross Site Scripting (XSS) via /client/manage/ourphp_out.php. PoC代码
云记的头像-渗透云记 - 专注于网络安全与技术分享云记2023年10月15日 08:15
20