unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2021-28021
Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file. CVE project by @Sn0wAlice
Create: 2023-02-01 09:25:11 +0000 UTC Push: 2023-02-01 09:25:13 +0000 UTC |
Live-Hack-CVE/CVE-2022-28041
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. CVE project by @Sn0wAlice
Create: 2023-02-01 09:25:07 +0000 UTC Push: 2023-02-01 09:25:09 +0000 UTC |
Live-Hack-CVE/CVE-2022-28042
stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. CVE project by @Sn0wAlice
Create: 2023-02-01 09:25:04 +0000 UTC Push: 2023-02-01 09:25:06 +0000 UTC |
Live-Hack-CVE/CVE-2023-24956
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /cha.php. CVE project by @Sn0wAlice
Create: 2023-02-01 09:24:58 +0000 UTC Push: 2023-02-01 09:25:01 +0000 UTC |
Live-Hack-CVE/CVE-2023-24241
Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php. CVE project by @Sn0wAlice
Create: 2023-02-01 09:24:55 +0000 UTC Push: 2023-02-01 09:24:57 +0000 UTC |
Live-Hack-CVE/CVE-2023-23924
Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with arbitrary CVE project by @Sn0wAlice
Create: 2023-02-01 09:24:52 +0000 UTC Push: 2023-02-01 09:24:54 +0000 UTC |
Live-Hack-CVE/CVE-2023-0341
A stack buffer overflow exists in the ec_glob function of editorconfig-core-c before v0.12.6 which allowed an attacker to arbitrarily write to the stack and possibly allows remote code execution. editorconfig-core-c v0.12.6 resolved this vulnerability by bound checking all write operations over the p_pcre buffer. CVE project by @Sn0wAlice
Create: 2023-02-01 09:24:48 +0000 UTC Push: 2023-02-01 09:24:50 +0000 UTC |
Live-Hack-CVE/CVE-2022-48161
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request. CVE project by @Sn0wAlice
Create: 2023-02-01 09:24:44 +0000 UTC Push: 2023-02-01 09:24:47 +0000 UTC |
Halcy0nic/CVE-2022-44318
Proof of concept for CVE-2022-44318
Create: 2023-02-01 09:00:33 +0000 UTC Push: 2023-02-01 09:00:34 +0000 UTC |
Halcy0nic/CVE-2022-43343
Proof of concept for (CVE-2022-43343)
Create: 2023-02-01 08:33:57 +0000 UTC Push: 2023-02-01 08:33:57 +0000 UTC |
Halcy0nic/CVE-2022-44311
Proof of concept for CVE-2022-44311
Create: 2023-02-01 07:53:39 +0000 UTC Push: 2023-02-01 07:53:40 +0000 UTC |
Live-Hack-CVE/CVE-2019-4308
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from error messages IBM X-Force ID: 161034. CVE project by @Sn0wAlice
Create: 2023-02-01 07:14:32 +0000 UTC Push: 2023-02-01 07:14:35 +0000 UTC |
Live-Hack-CVE/CVE-2019-4473
Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984. CVE project by @Sn0wAlice
Create: 2023-02-01 07:14:29 +0000 UTC Push: 2023-02-01 07:14:31 +0000 UTC |
Live-Hack-CVE/CVE-2019-4310
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 161036. CVE project by @Sn0wAlice
Create: 2023-02-01 07:14:25 +0000 UTC Push: 2023-02-01 07:14:27 +0000 UTC |
Live-Hack-CVE/CVE-2019-4298
IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access which could allow a local user to perform actions they should not have privileges to execute. IBM X-Force ID: 160764. CVE project by @Sn0wAlice
Create: 2023-02-01 07:14:22 +0000 UTC Push: 2023-02-01 07:14:24 +0000 UTC |
Live-Hack-CVE/CVE-2019-4299
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugging is enabled. IBM X-Force ID: 160765. CVE project by @Sn0wAlice
Create: 2023-02-01 07:14:18 +0000 UTC Push: 2023-02-01 07:14:20 +0000 UTC |
Live-Hack-CVE/CVE-2020-16242
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts. CVE project by @Sn0wAlice
Create: 2023-02-01 07:14:15 +0000 UTC Push: 2023-02-01 07:14:17 +0000 UTC |
Live-Hack-CVE/CVE-2020-26137
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116. CVE project by @Sn0wAlice
Create: 2023-02-01 07:14:11 +0000 UTC Push: 2023-02-01 07:14:13 +0000 UTC |
Live-Hack-CVE/CVE-2019-4383
When using IBM Spectrum Protect Plus 10.1.0, 10.1.2, and 10.1.3 to protect Oracle or MongoDB databases, a redirected restore operation may result in an escalation of user privileges. IBM X-Force ID: 162165. CVE project by @Sn0wAlice
Create: 2023-02-01 07:14:08 +0000 UTC Push: 2023-02-01 07:14:10 +0000 UTC |
Halcy0nic/CVE-2022-36752
Proof of concept for CVE-2022-36752
Create: 2023-02-01 07:14:06 +0000 UTC Push: 2023-02-01 07:14:07 +0000 UTC |
Previous
1130
1131
1132
1133
1134
1135
1136
1137
Next