unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2023-24220
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml. CVE project by @Sn0wAlice
Create: 2023-02-17 20:15:51 +0000 UTC Push: 2023-02-17 20:15:53 +0000 UTC |
Live-Hack-CVE/CVE-2023-24219
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml. CVE project by @Sn0wAlice
Create: 2023-02-17 20:15:48 +0000 UTC Push: 2023-02-17 20:15:50 +0000 UTC |
Live-Hack-CVE/CVE-2023-23695
Dell Secure Connect Gateway (SCG) version 5.14.00.12 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information. CVE project by @Sn0wAlice
Create: 2023-02-17 20:15:44 +0000 UTC Push: 2023-02-17 20:15:46 +0000 UTC |
Live-Hack-CVE/CVE-2023-0887
A vulnerability was found in phjounin TFTPD64-SE 4.64 and classified as critical. This issue affects some unknown processing of the file tftpd64_svc.exe. The manipulation leads to unquoted search path. An attack has to be approached locally. The associated identifier of this vulnerability is VDB-221351. CVE project by @Sn0wAlice
Create: 2023-02-17 20:15:41 +0000 UTC Push: 2023-02-17 20:15:43 +0000 UTC |
Live-Hack-CVE/CVE-2023-0883
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-opos/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the p CVE project by @Sn0wAlice
Create: 2023-02-17 20:15:37 +0000 UTC Push: 2023-02-17 20:15:39 +0000 UTC |
Live-Hack-CVE/CVE-2023-0882
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse.This issue affects Single Connect: 2.16. CVE project by @Sn0wAlice
Create: 2023-02-17 20:15:34 +0000 UTC Push: 2023-02-17 20:15:36 +0000 UTC |
LycsHub/CVE-2020-5245
Create: 2023-02-17 17:55:45 +0000 UTC Push: 2023-02-17 17:55:46 +0000 UTC |
LycsHub/CVE-2018-18893
Create: 2023-02-17 17:48:14 +0000 UTC Push: 2023-02-17 17:48:15 +0000 UTC |
Live-Hack-CVE/CVE-2023-0878
Cross-site Scripting (XSS) - Generic in GitHub repository nuxt/framework prior to 3.2.1. CVE project by @Sn0wAlice
Create: 2023-02-17 14:46:05 +0000 UTC Push: 2023-02-17 14:46:07 +0000 UTC |
Live-Hack-CVE/CVE-2023-0879
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12. CVE project by @Sn0wAlice
Create: 2023-02-17 14:46:01 +0000 UTC Push: 2023-02-17 14:46:03 +0000 UTC |
Live-Hack-CVE/CVE-2023-0877
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11. CVE project by @Sn0wAlice
Create: 2023-02-17 14:45:57 +0000 UTC Push: 2023-02-17 14:45:59 +0000 UTC |
Live-Hack-CVE/CVE-2023-0880
Misinterpretation of Input in GitHub repository thorsten/phpmyfaq prior to 3.1.11. CVE project by @Sn0wAlice
Create: 2023-02-17 14:45:53 +0000 UTC Push: 2023-02-17 14:45:56 +0000 UTC |
Live-Hack-CVE/CVE-2020-9453
In Epson iProjection v2.30, the driver file EMP_MPAU.sys allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402406 and IOCtl 0x9C40240A. (0x9C402402 has only a NULL pointer dereference.) This affects \Device\EMPMPAUIO an CVE project by @Sn0wAlice
Create: 2023-02-17 14:45:49 +0000 UTC Push: 2023-02-17 14:45:51 +0000 UTC |
Live-Hack-CVE/CVE-2018-25009
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16(). CVE project by @Sn0wAlice
Create: 2023-02-17 14:45:45 +0000 UTC Push: 2023-02-17 14:45:47 +0000 UTC |
Live-Hack-CVE/CVE-2018-3912
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack. The strcpy call overflows the destination buffer, which has a size of 128 bytes. An attacker can s CVE project by @Sn0wAlice
Create: 2023-02-17 14:45:42 +0000 UTC Push: 2023-02-17 14:45:44 +0000 UTC |
Therootkitsec/-CVE-2017-7269
Create: 2023-02-17 08:31:27 +0000 UTC Push: 2023-02-17 08:31:41 +0000 UTC |
Live-Hack-CVE/CVE-2015-10077
A vulnerability was found in webbuilders-group silverstripe-kapost-bridge 0.3.3. It has been declared as critical. Affected by this vulnerability is the function index/getPreview of the file code/control/KapostService.php. The manipulation leads to sql injection. The attack can be launched remotely. Upgrading to versio CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:41 +0000 UTC Push: 2023-02-17 07:58:43 +0000 UTC |
Live-Hack-CVE/CVE-2022-4903
A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remotely. Upgrading to version 7.0.71 is able to address this issue. The name of the CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:37 +0000 UTC Push: 2023-02-17 07:58:39 +0000 UTC |
Live-Hack-CVE/CVE-2023-24344
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:34 +0000 UTC Push: 2023-02-17 07:58:36 +0000 UTC |
Live-Hack-CVE/CVE-2023-24343
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:30 +0000 UTC Push: 2023-02-17 07:58:33 +0000 UTC |
Previous
609
610
611
612
613
614
615
616
Next