unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2023-20527
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:33 +0000 UTC Push: 2023-01-11 19:12:36 +0000 UTC |
Live-Hack-CVE/CVE-2023-20525
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:28 +0000 UTC Push: 2023-01-11 19:12:31 +0000 UTC |
Live-Hack-CVE/CVE-2023-20523
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:23 +0000 UTC Push: 2023-01-11 19:12:26 +0000 UTC |
Live-Hack-CVE/CVE-2023-0161
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:18 +0000 UTC Push: 2023-01-11 19:12:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-23814
Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:14 +0000 UTC Push: 2023-01-11 19:12:17 +0000 UTC |
Live-Hack-CVE/CVE-2022-23813
The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a confidential compute environment. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:09 +0000 UTC Push: 2023-01-11 19:12:12 +0000 UTC |
Live-Hack-CVE/CVE-2021-46767
Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:04 +0000 UTC Push: 2023-01-11 19:12:08 +0000 UTC |
Live-Hack-CVE/CVE-2023-22952
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:00 +0000 UTC Push: 2023-01-11 19:12:03 +0000 UTC |
Live-Hack-CVE/CVE-2022-34440
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. CVE project by @Sn0wAlice
Create: 2023-01-11 19:11:56 +0000 UTC Push: 2023-01-11 19:11:59 +0000 UTC |
Live-Hack-CVE/CVE-2022-34441
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. CVE project by @Sn0wAlice
Create: 2023-01-11 19:11:51 +0000 UTC Push: 2023-01-11 19:11:55 +0000 UTC |
Live-Hack-CVE/CVE-2022-34330
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 22 CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:53 +0000 UTC Push: 2023-01-11 14:52:56 +0000 UTC |
Live-Hack-CVE/CVE-2022-43392
A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request. CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:38 +0000 UTC Push: 2023-01-11 14:52:41 +0000 UTC |
Live-Hack-CVE/CVE-2022-43390
A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request. CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:34 +0000 UTC Push: 2023-01-11 14:52:37 +0000 UTC |
Live-Hack-CVE/CVE-2023-22958
The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter. CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:29 +0000 UTC Push: 2023-01-11 14:52:33 +0000 UTC |
Live-Hack-CVE/CVE-2022-48253
nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used. CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:26 +0000 UTC Push: 2023-01-11 14:52:28 +0000 UTC |
Live-Hack-CVE/CVE-2022-43519
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect Enterprise Orchestrator instance. An attacker could exploit these vulnerabilities to obtain and modify s CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:19 +0000 UTC Push: 2023-01-11 14:52:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-43526
Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victi CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:15 +0000 UTC Push: 2023-01-11 14:52:18 +0000 UTC |
Live-Hack-CVE/CVE-2022-43525
Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victi CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:10 +0000 UTC Push: 2023-01-11 14:52:13 +0000 UTC |
Live-Hack-CVE/CVE-2022-43524
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:06 +0000 UTC Push: 2023-01-11 14:52:09 +0000 UTC |
Live-Hack-CVE/CVE-2023-22959
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName). CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:02 +0000 UTC Push: 2023-01-11 14:52:05 +0000 UTC |
Previous
521
522
523
524
525
526
527
528
Next