unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2022-4759
The GigPress WordPress plugin before 2.3.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:48 +0000 UTC Push: 2023-02-14 02:07:50 +0000 UTC |
Live-Hack-CVE/CVE-2022-4745
The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example. CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:44 +0000 UTC Push: 2023-02-14 02:07:46 +0000 UTC |
Live-Hack-CVE/CVE-2022-4682
The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:39 +0000 UTC Push: 2023-02-14 02:07:42 +0000 UTC |
Live-Hack-CVE/CVE-2022-4678
The TemplatesNext ToolKit WordPress plugin before 3.2.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:36 +0000 UTC Push: 2023-02-14 02:07:38 +0000 UTC |
Live-Hack-CVE/CVE-2022-4656
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:32 +0000 UTC Push: 2023-02-14 02:07:34 +0000 UTC |
Live-Hack-CVE/CVE-2022-4628
The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:28 +0000 UTC Push: 2023-02-14 02:07:30 +0000 UTC |
Live-Hack-CVE/CVE-2022-4580
The Twenty20 Image Before-After WordPress plugin through 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:24 +0000 UTC Push: 2023-02-14 02:07:27 +0000 UTC |
Live-Hack-CVE/CVE-2022-4562
The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:20 +0000 UTC Push: 2023-02-14 02:07:23 +0000 UTC |
Live-Hack-CVE/CVE-2022-4551
The Rich Table of Contents WordPress plugin through 1.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:16 +0000 UTC Push: 2023-02-14 02:07:19 +0000 UTC |
Live-Hack-CVE/CVE-2022-4546
The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:12 +0000 UTC Push: 2023-02-14 02:07:15 +0000 UTC |
Live-Hack-CVE/CVE-2022-4512
The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:04 +0000 UTC Push: 2023-02-14 02:07:10 +0000 UTC |
Live-Hack-CVE/CVE-2022-4488
The Widgets on Pages WordPress plugin through 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:58 +0000 UTC Push: 2023-02-14 02:07:02 +0000 UTC |
Live-Hack-CVE/CVE-2022-4473
The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:54 +0000 UTC Push: 2023-02-14 02:06:57 +0000 UTC |
Live-Hack-CVE/CVE-2022-4471
The YARPP WordPress plugin through 5.30.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:50 +0000 UTC Push: 2023-02-14 02:06:53 +0000 UTC |
Live-Hack-CVE/CVE-2022-4458
The amr shortcode any widget WordPress plugin through 4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:46 +0000 UTC Push: 2023-02-14 02:06:48 +0000 UTC |
Live-Hack-CVE/CVE-2022-4448
The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:42 +0000 UTC Push: 2023-02-14 02:06:45 +0000 UTC |
Live-Hack-CVE/CVE-2022-4445
The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:39 +0000 UTC Push: 2023-02-14 02:06:41 +0000 UTC |
Live-Hack-CVE/CVE-2022-40022
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:35 +0000 UTC Push: 2023-02-14 02:06:37 +0000 UTC |
Live-Hack-CVE/CVE-2022-3891
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones. CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:31 +0000 UTC Push: 2023-02-14 02:06:34 +0000 UTC |
Live-Hack-CVE/CVE-2023-23937
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updating user profile does not properly validate the file content-type, allowing any authenticated user to bypass this security check by adding a valid signature (p.e. GIF89) and CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:27 +0000 UTC Push: 2023-02-14 02:06:30 +0000 UTC |
Previous
378
379
380
381
382
383
384
385
Next