unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2023-24343
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:30 +0000 UTC Push: 2023-02-17 07:58:33 +0000 UTC |
Live-Hack-CVE/CVE-2023-24346
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the wan_connected parameter at /goform/formEasySetupWizard3. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:27 +0000 UTC Push: 2023-02-17 07:58:29 +0000 UTC |
Live-Hack-CVE/CVE-2023-24345
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetWanDhcpplus. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:24 +0000 UTC Push: 2023-02-17 07:58:26 +0000 UTC |
Live-Hack-CVE/CVE-2023-24347
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formSetWanDhcpplus. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:20 +0000 UTC Push: 2023-02-17 07:58:22 +0000 UTC |
Live-Hack-CVE/CVE-2023-25151
opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements for the `http.server.request_content_length`, `http.server.response_content_lengt CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:14 +0000 UTC Push: 2023-02-17 07:58:16 +0000 UTC |
Live-Hack-CVE/CVE-2023-0821
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:10 +0000 UTC Push: 2023-02-17 07:58:13 +0000 UTC |
Live-Hack-CVE/CVE-2022-47703
TIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware Version MV8.003, and Hardware Version CPF906-V5.0_LCD_20200513. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:06 +0000 UTC Push: 2023-02-17 07:58:09 +0000 UTC |
Live-Hack-CVE/CVE-2022-44299
SiteServerCMS 7.1.3 sscms has a file read vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:02 +0000 UTC Push: 2023-02-17 07:58:05 +0000 UTC |
Live-Hack-CVE/CVE-2022-0637
There was an open redirection vulnerability pollbot, which was used in https://pollbot.services.mozilla.com/ and https://pollbot.stage.mozaws.net/ An attacker could have redirected anyone to malicious sites. CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:58 +0000 UTC Push: 2023-02-17 07:58:01 +0000 UTC |
Live-Hack-CVE/CVE-2021-43529
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures. CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:55 +0000 UTC Push: 2023-02-17 07:57:57 +0000 UTC |
Live-Hack-CVE/CVE-2021-23980
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comme CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:52 +0000 UTC Push: 2023-02-17 07:57:54 +0000 UTC |
Live-Hack-CVE/CVE-2020-6817
bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}). CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:48 +0000 UTC Push: 2023-02-17 07:57:51 +0000 UTC |
Live-Hack-CVE/CVE-2019-17003
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed. CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:45 +0000 UTC Push: 2023-02-17 07:57:47 +0000 UTC |
Live-Hack-CVE/CVE-2020-12413
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites. CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:41 +0000 UTC Push: 2023-02-17 07:57:43 +0000 UTC |
Live-Hack-CVE/CVE-2023-25150
Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the content of other users files. It is recommend CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:37 +0000 UTC Push: 2023-02-17 07:57:40 +0000 UTC |
Live-Hack-CVE/CVE-2023-0751
When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key f CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:34 +0000 UTC Push: 2023-02-17 07:57:36 +0000 UTC |
DanielRuf/CVE-2023-23752
Create: 2023-02-17 06:43:32 +0000 UTC Push: 2023-02-17 06:43:33 +0000 UTC |
Live-Hack-CVE/CVE-2022-21216
Insufficient granularity of access control in out-of-band management in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a privileged user to potentially enable escalation of privilege via adjacent network access. CVE project by @Sn0wAlice
Create: 2023-02-17 05:44:04 +0000 UTC Push: 2023-02-17 05:44:07 +0000 UTC |
Live-Hack-CVE/CVE-2022-36278
Insufficient control flow management in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. CVE project by @Sn0wAlice
Create: 2023-02-17 05:44:01 +0000 UTC Push: 2023-02-17 05:44:03 +0000 UTC |
Live-Hack-CVE/CVE-2022-33892
Path traversal in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access. CVE project by @Sn0wAlice
Create: 2023-02-17 05:43:57 +0000 UTC Push: 2023-02-17 05:44:00 +0000 UTC |
Previous
381
382
383
384
385
386
387
388
Next