unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2023-22332
Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of 3.5 series, All versions of 3.4 series, and CVE project by @Sn0wAlice
Create: 2023-01-30 20:04:00 +0000 UTC Push: 2023-01-30 20:04:03 +0000 UTC |
Live-Hack-CVE/CVE-2023-22322
Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed. CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:57 +0000 UTC Push: 2023-01-30 20:03:59 +0000 UTC |
Live-Hack-CVE/CVE-2023-22333
Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script. CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:53 +0000 UTC Push: 2023-01-30 20:03:56 +0000 UTC |
Live-Hack-CVE/CVE-2023-22324
SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained. CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:49 +0000 UTC Push: 2023-01-30 20:03:52 +0000 UTC |
Live-Hack-CVE/CVE-2022-46359
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure. CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:45 +0000 UTC Push: 2023-01-30 20:03:48 +0000 UTC |
Live-Hack-CVE/CVE-2022-46358
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure. CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:42 +0000 UTC Push: 2023-01-30 20:03:44 +0000 UTC |
Live-Hack-CVE/CVE-2022-46357
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure. CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:37 +0000 UTC Push: 2023-01-30 20:03:40 +0000 UTC |
Live-Hack-CVE/CVE-2022-46356
Potential vulnerabilities have been identified in HP Security Manager which may allow escalation of privilege, arbitrary code execution, and information disclosure. CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:34 +0000 UTC Push: 2023-01-30 20:03:36 +0000 UTC |
Live-Hack-CVE/CVE-2023-0474
Use after free in GuestView in Google Chrome prior to 109.0.5414.119 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a Chrome web app. (Chromium security severity: Medium) CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:30 +0000 UTC Push: 2023-01-30 20:03:32 +0000 UTC |
Live-Hack-CVE/CVE-2023-0473
Type Confusion in ServiceWorker API in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:26 +0000 UTC Push: 2023-01-30 20:03:28 +0000 UTC |
Live-Hack-CVE/CVE-2023-0472
Use after free in WebRTC in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:23 +0000 UTC Push: 2023-01-30 20:03:25 +0000 UTC |
Live-Hack-CVE/CVE-2023-0471
Use after free in WebTransport in Google Chrome prior to 109.0.5414.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVE project by @Sn0wAlice
Create: 2023-01-30 20:03:19 +0000 UTC Push: 2023-01-30 20:03:21 +0000 UTC |
Live-Hack-CVE/CVE-2022-27596
A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build 20221215 and later QTS 5.0.1.2234 build 202 CVE project by @Sn0wAlice
Create: 2023-01-30 14:39:18 +0000 UTC Push: 2023-01-30 14:39:21 +0000 UTC |
Live-Hack-CVE/CVE-2023-24612
The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option. CVE project by @Sn0wAlice
Create: 2023-01-30 14:39:09 +0000 UTC Push: 2023-01-30 14:39:11 +0000 UTC |
Live-Hack-CVE/CVE-2022-48303
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters. CVE project by @Sn0wAlice
Create: 2023-01-30 14:39:05 +0000 UTC Push: 2023-01-30 14:39:07 +0000 UTC |
Live-Hack-CVE/CVE-2023-24623
Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses. CVE project by @Sn0wAlice
Create: 2023-01-30 14:39:01 +0000 UTC Push: 2023-01-30 14:39:03 +0000 UTC |
Live-Hack-CVE/CVE-2023-24622
isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF. CVE project by @Sn0wAlice
Create: 2023-01-30 14:38:57 +0000 UTC Push: 2023-01-30 14:39:00 +0000 UTC |
Live-Hack-CVE/CVE-2022-25967
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data. CVE project by @Sn0wAlice
Create: 2023-01-30 14:38:54 +0000 UTC Push: 2023-01-30 14:38:56 +0000 UTC |
Live-Hack-CVE/CVE-2022-25936
Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable. CVE project by @Sn0wAlice
Create: 2023-01-30 14:38:51 +0000 UTC Push: 2023-01-30 14:38:53 +0000 UTC |
l00neyhacker/CVE-2023-23132
CVE-2023-23132
Create: 2023-01-30 12:17:44 +0000 UTC Push: 2023-01-30 12:17:44 +0000 UTC |
Previous
657
658
659
660
661
662
663
664
Next