unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2022-32748
A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration tool and compromise other devices in the ne CVE project by @Sn0wAlice
Create: 2023-01-31 10:17:19 +0000 UTC Push: 2023-01-31 10:17:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-32747
A CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause legitimate users to be locked out of devices or facilitate backdoor account creation by spoofing a device on the local network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2) CVE project by @Sn0wAlice
Create: 2023-01-31 10:17:15 +0000 UTC Push: 2023-01-31 10:17:18 +0000 UTC |
Live-Hack-CVE/CVE-2022-32512
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause remote code execution when a command which exploits this vulnerability is utilized. Affected Products: CanBRASS (Versions prior to V7.5.1) CVE project by @Sn0wAlice
Create: 2023-01-31 10:17:12 +0000 UTC Push: 2023-01-31 10:17:14 +0000 UTC |
Live-Hack-CVE/CVE-2022-32529
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted log data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0. CVE project by @Sn0wAlice
Create: 2023-01-31 10:17:08 +0000 UTC Push: 2023-01-31 10:17:11 +0000 UTC |
Live-Hack-CVE/CVE-2022-32528
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause access to manipulate and read files in the IGSS project report directory when an attacker sends specific messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170) CVE project by @Sn0wAlice
Create: 2023-01-31 10:17:05 +0000 UTC Push: 2023-01-31 10:17:07 +0000 UTC |
Live-Hack-CVE/CVE-2022-22732
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22) CVE project by @Sn0wAlice
Create: 2023-01-31 10:17:01 +0000 UTC Push: 2023-01-31 10:17:04 +0000 UTC |
Live-Hack-CVE/CVE-2022-32527
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0. CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:58 +0000 UTC Push: 2023-01-31 10:17:00 +0000 UTC |
Live-Hack-CVE/CVE-2022-22731
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause path traversal attacks. Affected Products: EcoStruxure Pow CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:55 +0000 UTC Push: 2023-01-31 10:16:57 +0000 UTC |
Live-Hack-CVE/CVE-2022-32526
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted setting value messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.221 CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:51 +0000 UTC Push: 2023-01-31 10:16:53 +0000 UTC |
Live-Hack-CVE/CVE-2022-0223
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthenticated code execution. Affected Products: EcoStruxure Power Com CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:48 +0000 UTC Push: 2023-01-31 10:16:50 +0000 UTC |
Live-Hack-CVE/CVE-2022-32525
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170) CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:44 +0000 UTC Push: 2023-01-31 10:16:47 +0000 UTC |
Live-Hack-CVE/CVE-2022-32524
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time reduced data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0 CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:41 +0000 UTC Push: 2023-01-31 10:16:43 +0000 UTC |
Live-Hack-CVE/CVE-2022-32522
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Version CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:37 +0000 UTC Push: 2023-01-31 10:16:40 +0000 UTC |
Live-Hack-CVE/CVE-2022-32521
A CWE 502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to the web server. Affected Products: Data Center Expert (Versions prior to V7.9.0) CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:34 +0000 UTC Push: 2023-01-31 10:16:36 +0000 UTC |
Live-Hack-CVE/CVE-2022-32520
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32518. Affected Products: Data Center Expert (Versions prior to V7.9.0) CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:31 +0000 UTC Push: 2023-01-31 10:16:31 +0000 UTC |
Live-Hack-CVE/CVE-2022-32519
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0) CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:27 +0000 UTC Push: 2023-01-31 10:16:29 +0000 UTC |
Live-Hack-CVE/CVE-2022-32516
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions) CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:23 +0000 UTC Push: 2023-01-31 10:16:26 +0000 UTC |
Live-Hack-CVE/CVE-2022-32515
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affected Products: Conext™ ComBox (All Versions) CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:19 +0000 UTC Push: 2023-01-31 10:16:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-32513
A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus Automation Controller - LSS5500SHAC (Version CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:16 +0000 UTC Push: 2023-01-31 10:16:18 +0000 UTC |
Live-Hack-CVE/CVE-2022-26117
An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to access the MySQL databases via the CLI. CVE project by @Sn0wAlice
Create: 2023-01-31 10:16:12 +0000 UTC Push: 2023-01-31 10:16:15 +0000 UTC |
Previous
651
652
653
654
655
656
657
658
Next