unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
NetJBS/CVE-2017-0055-PoC
This it's a PoC of Departament of justice VDP. By rootkit
Create: 2023-01-17 05:55:56 +0000 UTC Push: 2023-01-17 05:56:15 +0000 UTC |
Live-Hack-CVE/CVE-2022-47630
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger dangerous read side effects or obtain sensitive information about microarchitectural state. CVE project by @Sn0wAlice
Create: 2023-01-17 05:14:22 +0000 UTC Push: 2023-01-17 05:14:25 +0000 UTC |
Live-Hack-CVE/CVE-2023-0327
A vulnerability was found in saemorris TheRadSystem. It has been classified as problematic. Affected is an unknown function of the file users.php. The manipulation of the argument q leads to cross site scripting. It is possible to launch the attack remotely. VDB-218454 is the identifier assigned to this vulnerability. CVE project by @Sn0wAlice
Create: 2023-01-17 05:14:17 +0000 UTC Push: 2023-01-17 05:14:20 +0000 UTC |
Live-Hack-CVE/CVE-2015-10057
A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file inc/class.securelogin.php of the component Password Reset Handler. The manipulation leads to improper access controls. Upgrading to version 0.2 is able CVE project by @Sn0wAlice
Create: 2023-01-17 05:14:13 +0000 UTC Push: 2023-01-17 05:14:16 +0000 UTC |
Live-Hack-CVE/CVE-2015-10056
A vulnerability was found in 2071174A vinylmap. It has been classified as critical. Affected is the function contact of the file recordstoreapp/views.py. The manipulation leads to sql injection. The name of the patch is b07b79a1e92cc62574ba0492cce000ef4a7bd25f. It is recommended to apply a patch to fix this issue. The CVE project by @Sn0wAlice
Create: 2023-01-17 05:14:08 +0000 UTC Push: 2023-01-17 05:14:11 +0000 UTC |
Live-Hack-CVE/CVE-2015-10055
A vulnerability was found in PictureThisWebServer and classified as critical. This issue affects the function router.post of the file routes/user.js. The manipulation of the argument username/password leads to sql injection. The name of the patch is 68b9dc346e88b494df00d88c7d058e96820e1479. It is recommended to apply a CVE project by @Sn0wAlice
Create: 2023-01-17 04:09:05 +0000 UTC Push: 2023-01-17 04:09:07 +0000 UTC |
Live-Hack-CVE/CVE-2015-10054
A vulnerability, which was classified as critical, was found in githuis P2Manage. This affects the function Execute of the file PTwoManage/Database.cs. The manipulation of the argument sql leads to sql injection. The name of the patch is 717380aba80002414f82d93c770035198b7858cc. It is recommended to apply a patch to fi CVE project by @Sn0wAlice
Create: 2023-01-17 04:09:00 +0000 UTC Push: 2023-01-17 04:09:04 +0000 UTC |
Live-Hack-CVE/CVE-2014-125080
A vulnerability has been found in frontaccounting faplanet and classified as critical. This vulnerability affects unknown code. The manipulation leads to path traversal. The name of the patch is a5dcd87f46080a624b1a9ad4b0dd035bbd24ac50. It is recommended to apply a patch to fix this issue. VDB-218398 is the identifier CVE project by @Sn0wAlice
Create: 2023-01-17 04:08:56 +0000 UTC Push: 2023-01-17 04:08:58 +0000 UTC |
Live-Hack-CVE/CVE-2022-4658
The RSSImport WordPress plugin through 4.6.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. CVE project by @Sn0wAlice
Create: 2023-01-17 01:59:11 +0000 UTC Push: 2023-01-17 01:59:14 +0000 UTC |
Live-Hack-CVE/CVE-2022-4655
The Welcart e-Commerce WordPress plugin before 2.8.9 does not validate and escapes one of its shortcode attributes, which could allow users with a role as low as a contributor to perform a Stored Cross-Site Scripting attack. CVE project by @Sn0wAlice
Create: 2023-01-17 01:59:07 +0000 UTC Push: 2023-01-17 01:59:10 +0000 UTC |
Live-Hack-CVE/CVE-2022-4653
The Greenshift WordPress plugin before 4.8.9 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. CVE project by @Sn0wAlice
Create: 2023-01-17 01:59:02 +0000 UTC Push: 2023-01-17 01:59:06 +0000 UTC |
Live-Hack-CVE/CVE-2022-4648
The Real Testimonials WordPress plugin before 2.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:59 +0000 UTC Push: 2023-01-17 01:59:01 +0000 UTC |
Live-Hack-CVE/CVE-2022-4578
The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:54 +0000 UTC Push: 2023-01-17 01:58:57 +0000 UTC |
Live-Hack-CVE/CVE-2022-4571
The Seriously Simple Podcasting WordPress plugin before 2.19.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:50 +0000 UTC Push: 2023-01-17 01:58:53 +0000 UTC |
Live-Hack-CVE/CVE-2022-4549
The Tickera WordPress plugin before 3.5.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:46 +0000 UTC Push: 2023-01-17 01:58:49 +0000 UTC |
Live-Hack-CVE/CVE-2022-4547
The Conditional Payment Methods for WooCommerce WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by [high privilege users such as admin|users with a role as low as admin. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:41 +0000 UTC Push: 2023-01-17 01:58:44 +0000 UTC |
Live-Hack-CVE/CVE-2022-4544
The MashShare WordPress plugin before 3.8.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:38 +0000 UTC Push: 2023-01-17 01:58:40 +0000 UTC |
Live-Hack-CVE/CVE-2022-4508
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:33 +0000 UTC Push: 2023-01-17 01:58:36 +0000 UTC |
Live-Hack-CVE/CVE-2022-4507
The Real Cookie Banner WordPress plugin before 3.4.10 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:29 +0000 UTC Push: 2023-01-17 01:58:32 +0000 UTC |
Live-Hack-CVE/CVE-2022-4487
The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins CVE project by @Sn0wAlice
Create: 2023-01-17 01:58:25 +0000 UTC Push: 2023-01-17 01:58:27 +0000 UTC |
Previous
1058
1059
1060
1061
1062
1063
1064
1065
Next