unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2023-0655
SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses. CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:43 +0000 UTC Push: 2023-02-14 14:27:46 +0000 UTC |
Live-Hack-CVE/CVE-2023-25614
SAP NetWeaver AS ABAP (BSP Framework) application - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allow an unauthenticated attacker to inject the code that can be executed by the application over the network. On successful exploitation it can gain access to the sensitive information which le CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:40 +0000 UTC Push: 2023-02-14 14:27:42 +0000 UTC |
Live-Hack-CVE/CVE-2023-24530
SAP BusinessObjects Business Intelligence Platform (CMC) - versions 420, 430, allows an authenticated admin user to upload malicious code that can be executed by the application over the network. On successful exploitation, attacker can perform operations that may completely compromise the application causing high impa CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:37 +0000 UTC Push: 2023-02-14 14:27:39 +0000 UTC |
Live-Hack-CVE/CVE-2023-24529
Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an attacker CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:33 +0000 UTC Push: 2023-02-14 14:27:35 +0000 UTC |
Live-Hack-CVE/CVE-2023-24528
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel doc CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:30 +0000 UTC Push: 2023-02-14 14:27:32 +0000 UTC |
Live-Hack-CVE/CVE-2023-24525
SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application. CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:26 +0000 UTC Push: 2023-02-14 14:27:28 +0000 UTC |
Live-Hack-CVE/CVE-2023-24524
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability. CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:22 +0000 UTC Push: 2023-02-14 14:27:25 +0000 UTC |
Live-Hack-CVE/CVE-2023-24523
An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:19 +0000 UTC Push: 2023-02-14 14:27:21 +0000 UTC |
Live-Hack-CVE/CVE-2023-24522
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This may lead to a limited impact on CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:15 +0000 UTC Push: 2023-02-14 14:27:18 +0000 UTC |
Live-Hack-CVE/CVE-2023-24521
Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:12 +0000 UTC Push: 2023-02-14 14:27:14 +0000 UTC |
Live-Hack-CVE/CVE-2023-23860
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensitive information or expose CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:08 +0000 UTC Push: 2023-02-14 14:27:10 +0000 UTC |
Live-Hack-CVE/CVE-2023-23859
SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information. CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:04 +0000 UTC Push: 2023-02-14 14:27:07 +0000 UTC |
Live-Hack-CVE/CVE-2023-23858
Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to somewh CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:01 +0000 UTC Push: 2023-02-14 14:27:03 +0000 UTC |
Live-Hack-CVE/CVE-2023-23856
In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:57 +0000 UTC Push: 2023-02-14 14:26:59 +0000 UTC |
Live-Hack-CVE/CVE-2023-23855
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it has a low impact to confidentiality, integr CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:54 +0000 UTC Push: 2023-02-14 14:26:56 +0000 UTC |
Live-Hack-CVE/CVE-2023-23854
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:50 +0000 UTC Push: 2023-02-14 14:26:52 +0000 UTC |
Live-Hack-CVE/CVE-2023-23853
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensit CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:45 +0000 UTC Push: 2023-02-14 14:26:49 +0000 UTC |
Live-Hack-CVE/CVE-2023-23852
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:42 +0000 UTC Push: 2023-02-14 14:26:44 +0000 UTC |
Live-Hack-CVE/CVE-2023-23851
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their con CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:37 +0000 UTC Push: 2023-02-14 14:26:40 +0000 UTC |
Live-Hack-CVE/CVE-2023-0025
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources. CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:34 +0000 UTC Push: 2023-02-14 14:26:36 +0000 UTC |
Previous
397
398
399
400
401
402
403
404
Next