unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
BLY-Coder/Python-exploit-CVE-2020-25213
Python exploit for RCE in Wordpress
Create: 2023-01-23 00:54:25 +0000 UTC Push: 2023-01-23 00:54:26 +0000 UTC |
Live-Hack-CVE/CVE-2023-24058
Booked Scheduler 2.5.5 allows authenticated users to create and schedule events for any other user via a modified userId value to reservation_save.php. NOTE: 2.5.5 is a version from 2014. CVE project by @Sn0wAlice
Create: 2023-01-22 19:39:04 +0000 UTC Push: 2023-01-22 19:39:06 +0000 UTC |
Live-Hack-CVE/CVE-2023-24059
Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023. CVE project by @Sn0wAlice
Create: 2023-01-22 19:39:00 +0000 UTC Push: 2023-01-22 19:39:03 +0000 UTC |
Live-Hack-CVE/CVE-2023-0434
Improper Input Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev40. CVE project by @Sn0wAlice
Create: 2023-01-22 14:13:04 +0000 UTC Push: 2023-01-22 14:13:06 +0000 UTC |
Live-Hack-CVE/CVE-2023-24044
A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. CVE project by @Sn0wAlice
Create: 2023-01-22 14:13:00 +0000 UTC Push: 2023-01-22 14:13:03 +0000 UTC |
Live-Hack-CVE/CVE-2023-23457
A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-22 14:12:56 +0000 UTC Push: 2023-01-22 14:12:58 +0000 UTC |
Live-Hack-CVE/CVE-2023-23456
A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file. CVE project by @Sn0wAlice
Create: 2023-01-22 14:12:53 +0000 UTC Push: 2023-01-22 14:12:55 +0000 UTC |
Live-Hack-CVE/CVE-2023-24056
In pkgconf through 1.9.3, variable duplication can cause unbounded string expansion due to incorrect checks in libpkgconf/tuple.c:pkgconf_tuple_parse. For example, a .pc file containing a few hundred bytes can expand to one billion bytes. CVE project by @Sn0wAlice
Create: 2023-01-22 14:12:48 +0000 UTC Push: 2023-01-22 14:12:50 +0000 UTC |
Live-Hack-CVE/CVE-2023-24055
** DISPUTED ** KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password database is not intended to be secure against an attacker who has that l CVE project by @Sn0wAlice
Create: 2023-01-22 14:12:45 +0000 UTC Push: 2023-01-22 14:12:47 +0000 UTC |
Live-Hack-CVE/CVE-2023-22617
A remote attacker might be able to cause infinite recursion in PowerDNS Recursor 4.8.0 via a DNS query that retrieves DS records for a misconfigured domain, because QName minimization is used in QM fallback mode. This is fixed in 4.8.1. CVE project by @Sn0wAlice
Create: 2023-01-22 05:26:32 +0000 UTC Push: 2023-01-22 05:26:34 +0000 UTC |
Live-Hack-CVE/CVE-2023-0433
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. CVE project by @Sn0wAlice
Create: 2023-01-22 02:10:26 +0000 UTC Push: 2023-01-22 02:10:28 +0000 UTC |
Live-Hack-CVE/CVE-2023-22884
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0. CVE project by @Sn0wAlice
Create: 2023-01-21 23:56:15 +0000 UTC Push: 2023-01-21 23:56:17 +0000 UTC |
tin-z/CVE-2021-20294-POC
Create: 2023-01-21 23:28:53 +0000 UTC Push: 2023-01-21 23:28:53 +0000 UTC |
n3m1dotsys/CVE-2023-22809-sudoedit-privesc
A script to automate privilege escalation with CVE-2023-22809 vulnerability
Create: 2023-01-21 23:19:23 +0000 UTC Push: 2023-01-21 23:19:23 +0000 UTC |
0xless/CVE-2022-44900-demo-lab
Demo webapp vulnerable to CVE-2022-44900
Create: 2023-01-21 22:52:59 +0000 UTC Push: 2023-01-21 22:52:59 +0000 UTC |
Marsel-marsel/CVE-2022-45770
LPE exploit via windows driver
Create: 2023-01-21 18:32:02 +0000 UTC Push: 2023-01-21 18:32:03 +0000 UTC |
Live-Hack-CVE/CVE-2023-24038
The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes. CVE project by @Sn0wAlice
Create: 2023-01-21 15:10:05 +0000 UTC Push: 2023-01-21 15:10:08 +0000 UTC |
Live-Hack-CVE/CVE-2020-36655
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file. CVE project by @Sn0wAlice
Create: 2023-01-21 15:10:01 +0000 UTC Push: 2023-01-21 15:10:04 +0000 UTC |
Live-Hack-CVE/CVE-2023-24042
A race condition in LightFTP through 2.2 allows an attacker to achieve path traversal via a malformed FTP request. A handler thread can use an overwritten context->FileName. CVE project by @Sn0wAlice
Create: 2023-01-21 15:09:58 +0000 UTC Push: 2023-01-21 15:10:00 +0000 UTC |
Live-Hack-CVE/CVE-2023-24040
** UNSUPPORTED WHEN ASSIGNED ** dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of available printers. This allows low-privileged local users to inject arbitrary printer names via the $HOME/.printers file. This injection allows th CVE project by @Sn0wAlice
Create: 2023-01-21 15:09:55 +0000 UTC Push: 2023-01-21 15:09:57 +0000 UTC |
Previous
682
683
684
685
686
687
688
689
Next