• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    迪恩网络公众号

CVE漏洞

RSS
  • CVE-2021-24223
    CVE-2021-24223
    The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be h ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:19 | 回复:0
  • CVE-2021-24224
    CVE-2021-24224
    The EFBP_verify_upload_file AJAX action of the Easy Form Builder WordPress plugin through 1.0, available to authenticated users, does not have any security in place to verify uploaded files, allowing ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:16 | 回复:0
  • CVE-2021-24225
    CVE-2021-24225
    The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the Seasons Calendars page before outputing it in an A tag, leading to a reflected XSS issue……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:19 | 回复:0
  • CVE-2021-24226
    CVE-2021-24226
    In the AccessAlly WordPress plugin before 3.5.7, the file resource/frontend/product/product-shortcode.php responsible for the shortcode is dumping serialize($_SERVER), which contains all environment ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:29 | 回复:0
  • CVE-2021-24227
    CVE-2021-24227
    The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that could be abused by anyone visiting the site. Using this attack vector, an attac ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:13 | 回复:0
  • CVE-2021-24228
    CVE-2021-24228
    The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin before 1.7.2. The WordPress login form (wp-login.php) is hooked by the plugin and of ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:13 | 回复:0
  • CVE-2021-24229
    CVE-2021-24229
    The Jetpack Scan team identified a Reflected Cross-Site Scripting via the patreon_save_attachment_patreon_level AJAX action of the Patreon WordPress plugin before 1.7.2. This AJAX hook is used to upda ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:28 | 回复:0
  • CVE-2021-24230
    CVE-2021-24230
    The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged in user overwrite or create arbitrary user ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:15 | 回复:0
  • CVE-2021-24231
    CVE-2021-24231
    The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0, allowing attackers to make a logged administrator disconnect the site from Pat ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:22 | 回复:0
  • CVE-2021-25925
    CVE-2021-25925
    in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not being validated properly when processed by the server. Therefore, an attacker can ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:20 | 回复:0
  • CVE-2021-25926
    CVE-2021-25926
    In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an atta ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:21 | 回复:0
  • CVE-2019-17656
    CVE-2019-17656
    A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated re ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:9 | 回复:0
  • CVE-2020-15942
    CVE-2020-15942
    An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker t ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:17 | 回复:0
  • CVE-2021-22190
    CVE-2021-22190
    A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:18 | 回复:0
  • CVE-2021-24024
    CVE-2021-24024
    A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and below may allow a remote authenticated attacker to ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:31 | 回复:0
  • CVE-2021-27486
    CVE-2021-27486
    FATEK Automation WinProladder Versions 3.30 and prior is vulnerable to an integer underflow, which may cause an out-of-bounds write and allow an attacker to execute arbitrary code.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:25 | 回复:0
  • CVE-2021-3465
    CVE-2021-3465
    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:19 | 回复:0
  • CVE-2020-15734
    CVE-2020-15734
    An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate the browser's file upload capability into accessing other files in the same directory or sub-direct ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:5 | 回复:0
  • CVE-2020-7924
    CVE-2020-7924
    Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in acce ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:15 | 回复:0
  • CVE-2020-4920
    CVE-2020-4920
    IBM Jazz Team Server products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality p ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:21 | 回复:0
  • CVE-2020-4964
    CVE-2020-4964
    IBM Jazz Team Server products contain an undisclosed vulnerability that could allow an authenticated user to present a customized message on the application which could be used to phish other users. I ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:21 | 回复:0
  • CVE-2020-4965
    CVE-2020-4965
    IBM Jazz Team Server products use weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 192422.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:13 | 回复:0
  • CVE-2021-20519
    CVE-2021-20519
    IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentia ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:17 | 回复:0
  • CVE-2020-15390
    CVE-2020-15390
    pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:18 | 回复:0
  • CVE-2021-23270
    CVE-2021-23270
    In Gargoyle OS 1.12.0, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:11 | 回复:0
  • CVE-2021-29302
    CVE-2021-29302
    TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 = 2020.06 contains a buffer overflow vulnerability in the httpd process in the body message. The attack vector is: The attacker can get shell of the route ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:11 | 回复:0
  • CVE-2021-29357
    CVE-2021-29357
    The ECT Provider component in OutSystems Platform Server 10 before 10.0.1104.0 and 11 before 11.9.0 (and LifeTime management console before 11.7.0) allows SSRF for arbitrary outbound HTTP requests.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:27 | 回复:0
  • CVE-2021-3125
    CVE-2021-3125
    In TP-Link TL-XDR3230 1.0.12, TL-XDR1850 1.0.9, TL-XDR1860 1.0.14, TL-XDR3250 1.0.2, TL-XDR6060 Turbo 1.1.8, TL-XDR5430 1.0.11, and possibly others, when IPv6 is used, a routing loop can occur t ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:6 | 回复:0
  • CVE-2021-3128
    CVE-2021-3128
    In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASUS routers with firmware 3.0.0.4.386.42095 or 9.0.0.4.386.41994, when IPv6 is used, a routing loop can occur that generates excessive netwo ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:6 | 回复:0
  • CVE-2019-15059
    CVE-2019-15059
    In Liberty lisPBX 2.0-4, configuration backup files can be retrieved remotely from /backup/lispbx-CONF-YYYY-MM-DD.tar or /backup/lispbx-CDR-YYYY-MM-DD.tar without authentication or authorization. Thes ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:15 | 回复:0
  • CVE-2021-21524
    CVE-2021-21524
    Dell SRM versions prior to 4.5.0.1 and Dell SMR versions prior to 4.5.0.1 contain an Untrusted Deserialization Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerabili ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:15 | 回复:0
  • CVE-2021-21545
    CVE-2021-21545
    Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could be potentially exploited to gain arbitrary code execution on the system with pri ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:24 | 回复:0
  • CVE-2021-21394
    CVE-2021-21394
    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:21 | 回复:0
  • CVE-2021-22497
    CVE-2021-22497
    Advanced Authentication versions prior to 6.3 SP4 have a potential broken authentication due to improper session management issue.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:38 | 回复:0
  • CVE-2021-3163
    CVE-2021-3163
    ** DISPUTED ** A vulnerability in the HTML editor of Slab Quill 4.8.0 allows an attacker to execute arbitrary JavaScript by storing an XSS payload (a crafted onloadstart attribute of an IMG element) i ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:15 | 回复:0
  • CVE-2021-21392
    CVE-2021-21392
    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 request ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:20 | 回复:0
  • CVE-2021-21393
    CVE-2021-21393
    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:13 | 回复:0
  • CVE-2021-29429
    CVE-2021-29429
    In Gradle before version 7.0, files created with open permissions in the system temporary directory can allow an attacker to access information downloaded by Gradle. Some builds could be vulnerable to ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:16 | 回复:0
  • CVE-2021-30030
    CVE-2021-30030
    Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:24 | 回复:0
  • CVE-2021-30034
    CVE-2021-30034
    Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:32 | 阅读:16 | 回复:0

关注我们

极客给你想要的成长

关注极客中国获取最新资讯

热门推荐
专题导读
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap