unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2023-23858
Due to insufficient input validation, SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to send a crafted URL to a user, and by clicking the URL, the tricked user accesses SAP and might be directed with the response to somewh CVE project by @Sn0wAlice
Create: 2023-02-14 14:27:01 +0000 UTC Push: 2023-02-14 14:27:03 +0000 UTC |
Live-Hack-CVE/CVE-2023-23856
In SAP BusinessObjects Business Intelligence (Web Intelligence user interface) - version 430, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exploitation CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:57 +0000 UTC Push: 2023-02-14 14:26:59 +0000 UTC |
Live-Hack-CVE/CVE-2023-23855
SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it has a low impact to confidentiality, integr CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:54 +0000 UTC Push: 2023-02-14 14:26:56 +0000 UTC |
Live-Hack-CVE/CVE-2023-23854
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:50 +0000 UTC Push: 2023-02-14 14:26:52 +0000 UTC |
Live-Hack-CVE/CVE-2023-23853
An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or modify some sensit CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:45 +0000 UTC Push: 2023-02-14 14:26:49 +0000 UTC |
Live-Hack-CVE/CVE-2023-23852
SAP Solution Manager (System Monitoring) - version 720, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:42 +0000 UTC Push: 2023-02-14 14:26:44 +0000 UTC |
Live-Hack-CVE/CVE-2023-23851
SAP Business Planning and Consolidation - versions 200, 300, allows an attacker with business authorization to upload any files (including web pages) without the proper file format validation. If other users visit the uploaded malicious web page, the attacker may perform actions on behalf of the users without their con CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:37 +0000 UTC Push: 2023-02-14 14:26:40 +0000 UTC |
Live-Hack-CVE/CVE-2023-0025
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources. CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:34 +0000 UTC Push: 2023-02-14 14:26:36 +0000 UTC |
Live-Hack-CVE/CVE-2023-0024
SAP Solution Manager (BSP Application) - version 720, allows an authenticated attacker to craft a malicious link, which when clicked by an unsuspecting user, can be used to read or modify some sensitive information or craft a payload which may restrict access to the desired resources, resulting in Cross-Site Scripting CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:30 +0000 UTC Push: 2023-02-14 14:26:32 +0000 UTC |
Live-Hack-CVE/CVE-2023-0020
SAP BusinessObjects Business Intelligence platform - versions 420, 430, allows an authenticated attacker to access sensitive information which is otherwise restricted. On successful exploitation, there could be a high impact on confidentiality and limited impact on integrity of the application. CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:27 +0000 UTC Push: 2023-02-14 14:26:29 +0000 UTC |
Live-Hack-CVE/CVE-2023-0019
In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated attacker with minimal privileges to access all the confidential data stored in the database. Successful CVE project by @Sn0wAlice
Create: 2023-02-14 14:26:23 +0000 UTC Push: 2023-02-14 14:26:25 +0000 UTC |
timpen432/-Wh0Am1001-CVE-2023-21753
Create: 2023-02-14 12:43:39 +0000 UTC Push: 2023-02-17 11:43:16 +0000 UTC |
zwlsix/KeePass-CVE-2023-24055
KeePass CVE-2023-24055复现
Create: 2023-02-14 12:01:20 +0000 UTC Push: 2023-02-14 12:01:20 +0000 UTC |
Live-Hack-CVE/CVE-2023-0804
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127. CVE project by @Sn0wAlice
Create: 2023-02-14 09:52:44 +0000 UTC Push: 2023-02-14 09:52:47 +0000 UTC |
Live-Hack-CVE/CVE-2023-0803
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3516, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127. CVE project by @Sn0wAlice
Create: 2023-02-14 09:52:40 +0000 UTC Push: 2023-02-14 09:52:43 +0000 UTC |
Live-Hack-CVE/CVE-2023-0802
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3724, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127. CVE project by @Sn0wAlice
Create: 2023-02-14 09:52:37 +0000 UTC Push: 2023-02-14 09:52:39 +0000 UTC |
Live-Hack-CVE/CVE-2023-0801
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in libtiff/tif_unix.c:368, invoked by tools/tiffcrop.c:2903 and tools/tiffcrop.c:6778, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127. CVE project by @Sn0wAlice
Create: 2023-02-14 09:52:33 +0000 UTC Push: 2023-02-14 09:52:35 +0000 UTC |
Live-Hack-CVE/CVE-2023-0800
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3502, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 33aee127. CVE project by @Sn0wAlice
Create: 2023-02-14 09:52:29 +0000 UTC Push: 2023-02-14 09:52:31 +0000 UTC |
Live-Hack-CVE/CVE-2023-0799
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3701, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e. CVE project by @Sn0wAlice
Create: 2023-02-14 09:52:25 +0000 UTC Push: 2023-02-14 09:52:28 +0000 UTC |
Live-Hack-CVE/CVE-2023-0798
LibTIFF 4.4.0 has an out-of-bounds read in tiffcrop in tools/tiffcrop.c:3400, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit afaabc3e. CVE project by @Sn0wAlice
Create: 2023-02-14 09:52:22 +0000 UTC Push: 2023-02-14 09:52:24 +0000 UTC |
Previous
374
375
376
377
378
379
380
381
Next