unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2020-21119
SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code. CVE project by @Sn0wAlice
Create: 2023-02-16 07:25:03 +0000 UTC Push: 2023-02-16 07:25:05 +0000 UTC |
Live-Hack-CVE/CVE-2020-19825
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges. CVE project by @Sn0wAlice
Create: 2023-02-16 07:25:00 +0000 UTC Push: 2023-02-16 07:25:02 +0000 UTC |
Live-Hack-CVE/CVE-2021-38239
SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders parameter to /api/sys_msg/list/1/10. CVE project by @Sn0wAlice
Create: 2023-02-16 07:24:56 +0000 UTC Push: 2023-02-16 07:24:58 +0000 UTC |
BKreisel/CVE-2022-41343
Create: 2023-02-16 07:17:55 +0000 UTC Push: 2023-02-16 07:17:55 +0000 UTC |
cataiovita/CVE-2023-0669
CVE-2023-0669 GoAnywhere MFT command injection vulnerability
Create: 2023-02-16 07:00:18 +0000 UTC Push: 2023-02-16 07:00:19 +0000 UTC |
Live-Hack-CVE/CVE-2023-23462
Libpeconv – integer overflow, before commit 75b1565 (30/11/2022). CVE project by @Sn0wAlice
Create: 2023-02-16 06:18:13 +0000 UTC Push: 2023-02-16 06:18:16 +0000 UTC |
Live-Hack-CVE/CVE-2023-23461
Libpeconv – access violation, before commit b076013 (30/11/2022). CVE project by @Sn0wAlice
Create: 2023-02-16 06:18:09 +0000 UTC Push: 2023-02-16 06:18:12 +0000 UTC |
Live-Hack-CVE/CVE-2023-23459
Priority Windows may allow Command Execution via SQL Injection using an unspecified method. CVE project by @Sn0wAlice
Create: 2023-02-16 06:18:06 +0000 UTC Push: 2023-02-16 06:18:08 +0000 UTC |
Live-Hack-CVE/CVE-2022-47508
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos. CVE project by @Sn0wAlice
Create: 2023-02-16 06:18:02 +0000 UTC Push: 2023-02-16 06:18:04 +0000 UTC |
Live-Hack-CVE/CVE-2022-47504
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:58 +0000 UTC Push: 2023-02-16 06:18:00 +0000 UTC |
Live-Hack-CVE/CVE-2022-38111
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:54 +0000 UTC Push: 2023-02-16 06:17:57 +0000 UTC |
Live-Hack-CVE/CVE-2023-23836
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands. CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:50 +0000 UTC Push: 2023-02-16 06:17:52 +0000 UTC |
Live-Hack-CVE/CVE-2023-0697
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High) CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:31 +0000 UTC Push: 2023-02-16 06:17:33 +0000 UTC |
Live-Hack-CVE/CVE-2023-0696
Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:27 +0000 UTC Push: 2023-02-16 06:17:30 +0000 UTC |
Live-Hack-CVE/CVE-2023-0698
Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:23 +0000 UTC Push: 2023-02-16 06:17:26 +0000 UTC |
HritikThapa7/CVE-2023-31711
Zero-day Vulnerability in ZKTEco biometric fingerprint reader.
Create: 2023-02-16 04:27:52 +0000 UTC Push: 2023-05-31 16:15:36 +0000 UTC |
Live-Hack-CVE/CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it). CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:45 +0000 UTC Push: 2023-02-16 04:06:48 +0000 UTC |
Live-Hack-CVE/CVE-2022-44267
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:41 +0000 UTC Push: 2023-02-16 04:06:44 +0000 UTC |
Live-Hack-CVE/CVE-2022-46892
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:35 +0000 UTC Push: 2023-02-16 04:06:38 +0000 UTC |
Live-Hack-CVE/CVE-2021-27568
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:30 +0000 UTC Push: 2023-02-16 04:06:32 +0000 UTC |
Previous
387
388
389
390
391
392
393
394
Next