unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2021-4297
A vulnerability has been found in trampgeek jobe up to 1.6.4 and classified as problematic. This vulnerability affects the function runs_post of the file application/controllers/Restapi.php. The manipulation of the argument sourcefilename leads to an unknown weakness. Upgrading to version 1.6.5 is able to address this CVE project by @Sn0wAlice
Create: 2023-01-02 05:58:44 +0000 UTC Push: 2023-01-02 05:58:47 +0000 UTC |
Live-Hack-CVE/CVE-2015-10006
A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is some unknown functionality of the file app/controller/insertarSliderAjax.php. The manipulation of the argument imagetitle leads to cross site scripting. The attack may be launched remotely. The name of CVE project by @Sn0wAlice
Create: 2023-01-02 03:48:41 +0000 UTC Push: 2023-01-02 03:48:44 +0000 UTC |
Live-Hack-CVE/CVE-2013-10006
A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is the function HTTPAuthorized of the file src/bitcoinrpc.cpp. The manipulation of the argument strUserPass/strRPCUserColonPass leads to observable timing discrepancy. Upgrading to version 0.8.4rc2 is a CVE project by @Sn0wAlice
Create: 2023-01-02 03:48:37 +0000 UTC Push: 2023-01-02 03:48:40 +0000 UTC |
Live-Hack-CVE/CVE-2010-10002
** UNSUPPPORTED WHEN ASSIGNED **** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-module-openid. Affected is an unknown function of the file templates/consumer.php of the component OpenID Handler. The manipulation of the argument AuthState leads to c CVE project by @Sn0wAlice
Create: 2023-01-02 03:48:33 +0000 UTC Push: 2023-01-02 03:48:35 +0000 UTC |
Live-Hack-CVE/CVE-2023-22551
The FTP (aka "Implementation of a simple FTP client and server") project through 96c1a35 allows remote attackers to cause a denial of service (memory consumption) by engaging in client activity, such as establishing and then terminating a connection. This occurs because malloc is used but free is not. CVE project by @Sn0wAlice
Create: 2023-01-02 03:48:29 +0000 UTC Push: 2023-01-02 03:48:32 +0000 UTC |
philippedixon/CVE-2018-15473
Create: 2023-01-02 03:31:24 +0000 UTC Push: 2023-01-02 03:31:24 +0000 UTC |
Live-Hack-CVE/CVE-2023-0029
A vulnerability was found in Multilaser RE708 RE1200R4GC-2T2R-V3_v3411b_MUL029B. It has been rated as problematic. This issue affects some unknown processing of the component Telnet Service. The manipulation leads to denial of service. The attack may be initiated remotely. The identifier VDB-217169 was assigned to this CVE project by @Sn0wAlice
Create: 2023-01-01 23:28:20 +0000 UTC Push: 2023-01-01 23:28:22 +0000 UTC |
houseofxyz/CVE-2020-17382
Create: 2023-01-01 21:49:07 +0000 UTC Push: 2023-01-01 21:49:08 +0000 UTC |
Live-Hack-CVE/CVE-2022-47952
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to open" often indicates that a file does not exist, whereas "does not refer to a network namespace path" often indicates that a file exists. NO CVE project by @Sn0wAlice
Create: 2023-01-01 20:13:26 +0000 UTC Push: 2023-01-01 20:13:29 +0000 UTC |
Live-Hack-CVE/CVE-2021-41823
The Web Application Firewall (WAF) in Kemp LoadMaster 7.2.54.1 allows certain uses of onmouseover to bypass an XSS protection mechanism. CVE project by @Sn0wAlice
Create: 2023-01-01 20:13:22 +0000 UTC Push: 2023-01-01 20:13:25 +0000 UTC |
Live-Hack-CVE/CVE-2022-48198
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the attacker-controlled time_ref_topic parameter. CVE project by @Sn0wAlice
Create: 2023-01-01 20:13:12 +0000 UTC Push: 2023-01-01 20:13:15 +0000 UTC |
Live-Hack-CVE/CVE-2022-47634
M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LINK-2867. CVE project by @Sn0wAlice
Create: 2023-01-01 20:13:08 +0000 UTC Push: 2023-01-01 20:13:10 +0000 UTC |
Live-Hack-CVE/CVE-2022-45213
perfSONAR before 4.4.6 inadvertently supports the parse option for a file:// URL. CVE project by @Sn0wAlice
Create: 2023-01-01 20:13:04 +0000 UTC Push: 2023-01-01 20:13:06 +0000 UTC |
Live-Hack-CVE/CVE-2022-45027
perfSONAR before 4.4.6, when performing participant discovery, incorrectly uses an HTTP request header value to determine a local address. CVE project by @Sn0wAlice
Create: 2023-01-01 20:13:00 +0000 UTC Push: 2023-01-01 20:13:02 +0000 UTC |
Live-Hack-CVE/CVE-2022-40711
PrimeKey EJBCA 7.9.0.2 Community allows stored XSS in the End Entity section. A user with the RA Administrator role can inject an XSS payload to target higher-privilege users. CVE project by @Sn0wAlice
Create: 2023-01-01 20:12:56 +0000 UTC Push: 2023-01-01 20:12:59 +0000 UTC |
Live-Hack-CVE/CVE-2022-37787
An issue was discovered in WeCube platform 3.2.2. A DOM XSS vulnerability has been found on the plugin database execution page. CVE project by @Sn0wAlice
Create: 2023-01-01 20:12:52 +0000 UTC Push: 2023-01-01 20:12:55 +0000 UTC |
Live-Hack-CVE/CVE-2022-37786
An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the [Home / Admin / Resources] page, the [Home / Admin / System Params] page, and the [Home / Design / Basekey Configuration] page. CVE project by @Sn0wAlice
Create: 2023-01-01 20:12:48 +0000 UTC Push: 2023-01-01 20:12:50 +0000 UTC |
Live-Hack-CVE/CVE-2022-37785
An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins. CVE project by @Sn0wAlice
Create: 2023-01-01 20:12:44 +0000 UTC Push: 2023-01-01 20:12:47 +0000 UTC |
Live-Hack-CVE/CVE-2022-34324
Multiple SQL injections in Sage XRT Business Exchange 12.4.302 allow an authenticated attacker to inject malicious data in SQL queries: Add Currencies, Payment Order, and Transfer History. CVE project by @Sn0wAlice
Create: 2023-01-01 20:12:40 +0000 UTC Push: 2023-01-01 20:12:43 +0000 UTC |
Live-Hack-CVE/CVE-2022-34323
Multiple XSS issues were discovered in Sage XRT Business Exchange 12.4.302 that allow an attacker to execute JavaScript code in the context of other users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Filters and Display model features (OnlineBanking > We CVE project by @Sn0wAlice
Create: 2023-01-01 20:12:36 +0000 UTC Push: 2023-01-01 20:12:38 +0000 UTC |
Previous
768
769
770
771
772
773
774
775
Next