unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2022-4237
The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscriber to perform PHAR deserialisation when they can upload a file and a suitable g CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:44 +0000 UTC Push: 2023-01-03 08:06:46 +0000 UTC |
Live-Hack-CVE/CVE-2022-4236
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file via an AJAX action available to any authenticated users, which could allow users with a role as low as subscriber to read arbitrary files on the server. CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:41 +0000 UTC Push: 2023-01-03 08:06:43 +0000 UTC |
Live-Hack-CVE/CVE-2022-4200
The Login with Cognito WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:37 +0000 UTC Push: 2023-01-03 08:06:39 +0000 UTC |
Live-Hack-CVE/CVE-2022-4198
The WP Social Sharing WordPress plugin through 2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:33 +0000 UTC Push: 2023-01-03 08:06:36 +0000 UTC |
Live-Hack-CVE/CVE-2022-4142
The WordPress Filter Gallery Plugin WordPress plugin before 0.1.6 does not properly escape the filters passed in the ufg_gallery_filters ajax action before outputting them on the page, allowing a high privileged user such as an administrator to inject HTML or javascript to the plugin settings page, even when the unfilt CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:29 +0000 UTC Push: 2023-01-03 08:06:32 +0000 UTC |
Live-Hack-CVE/CVE-2022-4140
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:25 +0000 UTC Push: 2023-01-03 08:06:28 +0000 UTC |
Live-Hack-CVE/CVE-2022-4119
The Image Optimizer, Resizer and CDN WordPress plugin before 6.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:21 +0000 UTC Push: 2023-01-03 08:06:24 +0000 UTC |
Live-Hack-CVE/CVE-2022-4114
The Superio WordPress theme does not sanitise and escape some parameters, which could allow users with a role as low as a subscriber to perform Cross-Site Scripting attacks. CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:16 +0000 UTC Push: 2023-01-03 08:06:20 +0000 UTC |
Live-Hack-CVE/CVE-2022-4109
The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite) CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:13 +0000 UTC Push: 2023-01-03 08:06:15 +0000 UTC |
Live-Hack-CVE/CVE-2022-4099
The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:09 +0000 UTC Push: 2023-01-03 08:06:11 +0000 UTC |
Live-Hack-CVE/CVE-2022-4059
The Cryptocurrency Widgets Pack WordPress plugin through 1.8.1 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:05 +0000 UTC Push: 2023-01-03 08:06:07 +0000 UTC |
Live-Hack-CVE/CVE-2022-4057
The Autoptimize WordPress plugin before 3.1.0 uses an easily guessable path to store plugin's exported settings and logs. CVE project by @Sn0wAlice
Create: 2023-01-03 08:06:01 +0000 UTC Push: 2023-01-03 08:06:04 +0000 UTC |
Live-Hack-CVE/CVE-2022-4049
The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. CVE project by @Sn0wAlice
Create: 2023-01-03 08:05:57 +0000 UTC Push: 2023-01-03 08:05:59 +0000 UTC |
Live-Hack-CVE/CVE-2022-3994
The Authenticator WordPress plugin before 1.3.1 does not prevent subscribers from updating a site's feed access token, which may deny other users access to the functionality in certain configurations. CVE project by @Sn0wAlice
Create: 2023-01-03 08:05:54 +0000 UTC Push: 2023-01-03 08:05:56 +0000 UTC |
Live-Hack-CVE/CVE-2022-3936
The Team Members WordPress plugin before 5.2.1 does not sanitize and escapes some of its settings, which could allow high-privilege users such as editors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in a multisite setup). CVE project by @Sn0wAlice
Create: 2023-01-03 08:05:50 +0000 UTC Push: 2023-01-03 08:05:52 +0000 UTC |
Live-Hack-CVE/CVE-2022-3911
The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users, such as subscribe CVE project by @Sn0wAlice
Create: 2023-01-03 08:05:45 +0000 UTC Push: 2023-01-03 08:05:49 +0000 UTC |
Live-Hack-CVE/CVE-2022-3860
The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author. CVE project by @Sn0wAlice
Create: 2023-01-03 08:05:42 +0000 UTC Push: 2023-01-03 08:05:44 +0000 UTC |
Live-Hack-CVE/CVE-2022-3241
The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection CVE project by @Sn0wAlice
Create: 2023-01-03 08:05:38 +0000 UTC Push: 2023-01-03 08:05:41 +0000 UTC |
Live-Hack-CVE/CVE-2015-10011
A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the file resolverapi/endpoints.py. The manipulation leads to improper output neutralization for logs. The name of the patch is 9eba6ba5abd89d0e36a008921eb307fcef8c5311. It is recommended to apply a patch to CVE project by @Sn0wAlice
Create: 2023-01-03 08:05:34 +0000 UTC Push: 2023-01-03 08:05:36 +0000 UTC |
Live-Hack-CVE/CVE-2016-15007
A vulnerability was found in Centralized-Salesforce-Dev-Framework. It has been declared as problematic. Affected by this vulnerability is the function SObjectService of the file src/classes/SObjectService.cls of the component SOQL Handler. The manipulation of the argument orderDirection leads to injection. The name of CVE project by @Sn0wAlice
Create: 2023-01-03 05:55:23 +0000 UTC Push: 2023-01-03 05:55:25 +0000 UTC |
Previous
872
873
874
875
876
877
878
879
Next