unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2022-4158
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the site's CVE project by @Sn0wAlice
Create: 2022-12-27 16:37:12 +0000 UTC Push: 2022-12-27 16:37:14 +0000 UTC |
Live-Hack-CVE/CVE-2022-4157
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to an SQL query in export-votes-all.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configuratio CVE project by @Sn0wAlice
Create: 2022-12-27 16:37:09 +0000 UTC Push: 2022-12-27 16:37:11 +0000 UTC |
Live-Hack-CVE/CVE-2022-4156
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQL query in ajax-functions-backend.php. This may allow malicious users with at least author privilege to leak sensitive information from the CVE project by @Sn0wAlice
Create: 2022-12-27 16:37:05 +0000 UTC Push: 2022-12-27 16:37:07 +0000 UTC |
Live-Hack-CVE/CVE-2022-4155
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurati CVE project by @Sn0wAlice
Create: 2022-12-27 16:37:01 +0000 UTC Push: 2022-12-27 16:37:04 +0000 UTC |
Live-Hack-CVE/CVE-2022-4154
The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the sit CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:58 +0000 UTC Push: 2022-12-27 16:37:00 +0000 UTC |
Live-Hack-CVE/CVE-2022-4153
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an SQL query in get-data-create-upload-v10.php. This may allow malicious users with at least author privilege to leak sensitive information from CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:54 +0000 UTC Push: 2022-12-27 16:36:57 +0000 UTC |
Live-Hack-CVE/CVE-2022-4152
The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's datab CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:51 +0000 UTC Push: 2022-12-27 16:36:53 +0000 UTC |
Live-Hack-CVE/CVE-2022-4151
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the sit CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:20 +0000 UTC Push: 2022-12-27 16:36:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-4150
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitiv CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:17 +0000 UTC Push: 2022-12-27 16:36:19 +0000 UTC |
Live-Hack-CVE/CVE-2022-4120
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:14 +0000 UTC Push: 2022-12-27 16:36:16 +0000 UTC |
Live-Hack-CVE/CVE-2022-4117
The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection. CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:10 +0000 UTC Push: 2022-12-27 16:36:12 +0000 UTC |
Live-Hack-CVE/CVE-2022-4110
The Eventify™ WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:06 +0000 UTC Push: 2022-12-27 16:36:08 +0000 UTC |
Live-Hack-CVE/CVE-2022-4047
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE CVE project by @Sn0wAlice
Create: 2022-12-27 16:36:03 +0000 UTC Push: 2022-12-27 16:36:05 +0000 UTC |
Live-Hack-CVE/CVE-2022-4042
The Paytium: Mollie payment forms & donations WordPress plugin through 4.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE project by @Sn0wAlice
Create: 2022-12-27 16:35:59 +0000 UTC Push: 2022-12-27 16:36:01 +0000 UTC |
Live-Hack-CVE/CVE-2022-3840
The Login for Google Apps WordPress plugin before 3.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE project by @Sn0wAlice
Create: 2022-12-27 16:35:56 +0000 UTC Push: 2022-12-27 16:35:58 +0000 UTC |
Live-Hack-CVE/CVE-2022-3835
The Kwayy HTML Sitemap WordPress plugin before 4.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE project by @Sn0wAlice
Create: 2022-12-27 16:35:52 +0000 UTC Push: 2022-12-27 16:35:54 +0000 UTC |
Live-Hack-CVE/CVE-2020-12069
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), the password-hashing feature requires insufficient computational effort. CVE project by @Sn0wAlice
Create: 2022-12-27 16:35:35 +0000 UTC Push: 2022-12-27 16:35:37 +0000 UTC |
Live-Hack-CVE/CVE-2020-12067
In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password. CVE project by @Sn0wAlice
Create: 2022-12-27 16:35:31 +0000 UTC Push: 2022-12-27 16:35:33 +0000 UTC |
Live-Hack-CVE/CVE-2021-4281
A vulnerability was found in Brave UX for-the-badge and classified as critical. Affected by this issue is some unknown functionality of the file .github/workflows/combine-prs.yml. The manipulation leads to os command injection. The name of the patch is 55b5a234c0fab935df5fb08365bc8fe9c37cf46b. It is recommended to appl CVE project by @Sn0wAlice
Create: 2022-12-27 16:35:27 +0000 UTC Push: 2022-12-27 16:35:29 +0000 UTC |
Live-Hack-CVE/CVE-2020-11101
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges. CVE project by @Sn0wAlice
Create: 2022-12-27 16:35:24 +0000 UTC Push: 2022-12-27 16:35:26 +0000 UTC |
Previous
596
597
598
599
600
601
602
603
Next