unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2020-11074
In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6. CVE project by @Sn0wAlice
Create: 2023-01-28 01:14:30 +0000 UTC Push: 2023-01-28 01:14:33 +0000 UTC |
Live-Hack-CVE/CVE-2020-4074
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6. CVE project by @Sn0wAlice
Create: 2023-01-28 01:14:26 +0000 UTC Push: 2023-01-28 01:14:29 +0000 UTC |
Live-Hack-CVE/CVE-2020-12424
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78. CVE project by @Sn0wAlice
Create: 2023-01-28 01:14:23 +0000 UTC Push: 2023-01-28 01:14:25 +0000 UTC |
Live-Hack-CVE/CVE-2020-12406
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. CVE project by @Sn0wAlice
Create: 2023-01-28 01:14:19 +0000 UTC Push: 2023-01-28 01:14:21 +0000 UTC |
Live-Hack-CVE/CVE-2020-12415
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78. CVE project by @Sn0wAlice
Create: 2023-01-28 01:14:15 +0000 UTC Push: 2023-01-28 01:14:18 +0000 UTC |
Live-Hack-CVE/CVE-2020-12418
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0. CVE project by @Sn0wAlice
Create: 2023-01-28 01:14:12 +0000 UTC Push: 2023-01-28 01:14:14 +0000 UTC |
Live-Hack-CVE/CVE-2022-47016
A null pointer dereference issue was discovered in function window_pane_set_event in window.c in tmux 3.0 thru 3.3 and later, allows attackers to cause denial of service or other unspecified impacts. CVE project by @Sn0wAlice
Create: 2023-01-28 00:09:20 +0000 UTC Push: 2023-01-28 00:09:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-47021
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts. CVE project by @Sn0wAlice
Create: 2023-01-28 00:09:14 +0000 UTC Push: 2023-01-28 00:09:17 +0000 UTC |
Live-Hack-CVE/CVE-2022-47024
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts. CVE project by @Sn0wAlice
Create: 2023-01-28 00:09:10 +0000 UTC Push: 2023-01-28 00:09:13 +0000 UTC |
Live-Hack-CVE/CVE-2022-44718
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is CVE project by @Sn0wAlice
Create: 2023-01-28 00:09:06 +0000 UTC Push: 2023-01-28 00:09:09 +0000 UTC |
Live-Hack-CVE/CVE-2022-44717
An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 1 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is CVE project by @Sn0wAlice
Create: 2023-01-28 00:09:02 +0000 UTC Push: 2023-01-28 00:09:05 +0000 UTC |
Live-Hack-CVE/CVE-2022-44715
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:58 +0000 UTC Push: 2023-01-28 00:09:01 +0000 UTC |
Live-Hack-CVE/CVE-2022-44298
SiteServer CMS 7.1.3 is vulnerable to SQL Injection. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:54 +0000 UTC Push: 2023-01-28 00:08:57 +0000 UTC |
Live-Hack-CVE/CVE-2022-44029
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 6 of 6. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:51 +0000 UTC Push: 2023-01-28 00:08:53 +0000 UTC |
Live-Hack-CVE/CVE-2022-44028
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 5 of 6. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:46 +0000 UTC Push: 2023-01-28 00:08:49 +0000 UTC |
Live-Hack-CVE/CVE-2022-44027
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 4 of 6. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:42 +0000 UTC Push: 2023-01-28 00:08:45 +0000 UTC |
Live-Hack-CVE/CVE-2022-44026
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 3 of 6. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:39 +0000 UTC Push: 2023-01-28 00:08:41 +0000 UTC |
Live-Hack-CVE/CVE-2022-44025
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 2 of 6. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:35 +0000 UTC Push: 2023-01-28 00:08:37 +0000 UTC |
Live-Hack-CVE/CVE-2022-44024
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 1 of 6. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:31 +0000 UTC Push: 2023-01-28 00:08:33 +0000 UTC |
Live-Hack-CVE/CVE-2023-23492
The Login with Phone Number WordPress Plugin, version < 1.4.2, is affected by an authenticated SQL injection vulnerability in the 'ID' parameter of its 'lwp_forgot_password' action. CVE project by @Sn0wAlice
Create: 2023-01-28 00:08:25 +0000 UTC Push: 2023-01-28 00:08:28 +0000 UTC |
Previous
1152
1153
1154
1155
1156
1157
1158
1159
Next