unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2022-47412
Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition. CVE project by @Sn0wAlice
Create: 2023-02-08 06:17:38 +0000 UTC Push: 2023-02-08 06:17:41 +0000 UTC |
Live-Hack-CVE/CVE-2022-4763
The Icon Widget WordPress plugin before 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. CVE project by @Sn0wAlice
Create: 2023-02-08 06:17:32 +0000 UTC Push: 2023-02-08 06:17:35 +0000 UTC |
Live-Hack-CVE/CVE-2022-24990
TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response. CVE project by @Sn0wAlice
Create: 2023-02-08 04:04:07 +0000 UTC Push: 2023-02-08 04:04:10 +0000 UTC |
Live-Hack-CVE/CVE-2022-41313
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="switch_contact" CVE project by @Sn0wAlice
Create: 2023-02-08 04:04:03 +0000 UTC Push: 2023-02-08 04:04:06 +0000 UTC |
Live-Hack-CVE/CVE-2022-41312
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="Switch Descriptio CVE project by @Sn0wAlice
Create: 2023-02-08 04:03:59 +0000 UTC Push: 2023-02-08 04:04:02 +0000 UTC |
Live-Hack-CVE/CVE-2022-41311
A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="webLocationMessag CVE project by @Sn0wAlice
Create: 2023-02-08 04:03:56 +0000 UTC Push: 2023-02-08 04:03:58 +0000 UTC |
Live-Hack-CVE/CVE-2022-40693
A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-08 04:03:52 +0000 UTC Push: 2023-02-08 04:03:55 +0000 UTC |
Live-Hack-CVE/CVE-2022-40691
An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-08 04:03:48 +0000 UTC Push: 2023-02-08 04:03:50 +0000 UTC |
Live-Hack-CVE/CVE-2022-40224
A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-08 04:03:43 +0000 UTC Push: 2023-02-08 04:03:46 +0000 UTC |
Live-Hack-CVE/CVE-2011-10002
A vulnerability classified as critical has been found in weblabyrinth 0.3.1. This affects the function Labyrinth of the file labyrinth.inc.php. The manipulation leads to sql injection. Upgrading to version 0.3.2 is able to address this issue. The name of the patch is 60793fd8c8c4759596d3510641e96ea40e7f60e9. It is reco CVE project by @Sn0wAlice
Create: 2023-02-08 04:03:40 +0000 UTC Push: 2023-02-08 04:03:42 +0000 UTC |
Live-Hack-CVE/CVE-2022-46621
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. CVE project by @Sn0wAlice
Create: 2023-02-08 01:53:23 +0000 UTC Push: 2023-02-08 01:53:25 +0000 UTC |
Live-Hack-CVE/CVE-2022-46620
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. CVE project by @Sn0wAlice
Create: 2023-02-08 01:53:20 +0000 UTC Push: 2023-02-08 01:53:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-45544
Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. CVE project by @Sn0wAlice
Create: 2023-02-08 01:53:16 +0000 UTC Push: 2023-02-08 01:53:18 +0000 UTC |
Live-Hack-CVE/CVE-2018-14632
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management. CVE project by @Sn0wAlice
Create: 2023-02-08 01:53:09 +0000 UTC Push: 2023-02-08 01:53:11 +0000 UTC |
Live-Hack-CVE/CVE-2023-0707
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been rated as critical. Affected by this issue is the function delete_record of the file function.php. The manipulation of the argument id leads to sql injection. VDB-220346 is the identifier assigned to this vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-07 23:39:45 +0000 UTC Push: 2023-02-07 23:39:47 +0000 UTC |
Live-Hack-CVE/CVE-2022-43759
A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any -promoted resource in any cluster. This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10. CVE project by @Sn0wAlice
Create: 2023-02-07 23:39:41 +0000 UTC Push: 2023-02-07 23:39:43 +0000 UTC |
Live-Hack-CVE/CVE-2022-43758
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for user with the ability to add an untrusted Helm catalog or modifying the URL configuration used to download KDM (only admin users by default) This issue affects: SUSE Ranch CVE project by @Sn0wAlice
Create: 2023-02-07 23:39:37 +0000 UTC Push: 2023-02-07 23:39:40 +0000 UTC |
Live-Hack-CVE/CVE-2022-43757
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1. CVE project by @Sn0wAlice
Create: 2023-02-07 23:39:34 +0000 UTC Push: 2023-02-07 23:39:36 +0000 UTC |
Live-Hack-CVE/CVE-2022-43756
A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote attackers to cause denial of service by supplying specially crafted git credentials. This issue affects: SUSE Rancher wrangler version 0.7.3 and prior versions; wrangler versi CVE project by @Sn0wAlice
Create: 2023-02-07 23:39:30 +0000 UTC Push: 2023-02-07 23:39:32 +0000 UTC |
Live-Hack-CVE/CVE-2022-43755
A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after the token was renewed. This issue affects: SUSE Rancher Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1. CVE project by @Sn0wAlice
Create: 2023-02-07 23:39:26 +0000 UTC Push: 2023-02-07 23:39:28 +0000 UTC |
Previous
401
402
403
404
405
406
407
408
Next