• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    迪恩网络公众号

CVE漏洞

RSS
  • CVE-2021-30074
    CVE-2021-30074
    docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code Blocks and mishandles the character.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:13 | 回复:0
  • CVE-2021-21529
    CVE-2021-21529
    Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to caus ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:15 | 回复:0
  • CVE-2021-21532
    CVE-2021-21532
    Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management s ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:7 | 回复:0
  • CVE-2021-21533
    CVE-2021-21533
    Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users that ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:9 | 回复:0
  • CVE-2021-30127
    CVE-2021-30127
    TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP port 8181, which is arguably inconsistent with the It is only available on the l ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:19 | 回复:0
  • CVE-2021-28832
    CVE-2021-28832
    VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:21 | 回复:0
  • CVE-2021-29261
    CVE-2021-29261
    The unofficial Svelte extension before 104.8.0 for Visual Studio Code allows attackers to execute arbitrary code via a crafted workspace configuration.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:10 | 回复:0
  • CVE-2021-29996
    CVE-2021-29996
    Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by opening .md files containing a mutation Cross Site Scripting (XSS) payload.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:7 | 回复:0
  • CVE-2021-30055
    CVE-2021-30055
    A SQL injection vulnerability in Knowage Suite version 7.1 exists in the documentexecution/url analytics driver component via the 'par_year' parameter when running a report.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:10 | 回复:0
  • CVE-2021-30056
    CVE-2021-30056
    Knowage Suite before 7.4 is vulnerable to reflected cross-site scripting (XSS). An attacker can inject arbitrary web script in /restful-services/publish via the 'EXEC_FROM' parameter that can ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:9 | 回复:0
  • CVE-2021-30057
    CVE-2021-30057
    A stored HTML injection vulnerability exists in Knowage Suite version 7.1. An attacker can inject arbitrary HTML in /restful-services/2.0/analyticalDrivers via the 'LABEL' and 'NAME' p ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:5 | 回复:0
  • CVE-2021-30058
    CVE-2021-30058
    Knowage Suite before 7.4 is vulnerable to cross-site scripting (XSS). An attacker can inject arbitrary external script in '/knowagecockpitengine/api/1.0/pages/execute' via the 'SBI_HOST&#3 ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:9 | 回复:0
  • CVE-2021-30109
    CVE-2021-30109
    Froala Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent Cross-site scripting (XSS) vulnerability within the hyperlink creat ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:20 | 回复:0
  • CVE-2020-4792
    CVE-2020-4792
    IBM Edge 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cre ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:23 | 回复:0
  • CVE-2020-4997
    CVE-2020-4997
    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:13 | 回复:0
  • CVE-2021-24150
    CVE-2021-24150
    The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:9 | 回复:0
  • CVE-2021-24152
    CVE-2021-24152
    The All Subscribers setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:14 | 回复:0
  • CVE-2021-24153
    CVE-2021-24153
    A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several f ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:10 | 回复:0
  • CVE-2021-24154
    CVE-2021-24154
    The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_file() function, allowing administrators to download arbitrary files on the web s ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:8 | 回复:0
  • CVE-2021-24155
    CVE-2021-24155
    The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+ ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:6 | 回复:0
  • CVE-2021-24156
    CVE-2021-24156
    Stored Cross-Site Scripting vulnerabilities in Testimonial Rotator 3.0.3 allow low privileged users (Contributor) to inject arbitrary JavaScript code or HTML without approval. This could lead to privi ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:13 | 回复:0
  • CVE-2021-24157
    CVE-2021-24157
    Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:7 | 回复:0
  • CVE-2021-24158
    CVE-2021-24158
    Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:5 | 回复:0
  • CVE-2021-24159
    CVE-2021-24159
    Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPr ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:39 | 回复:0
  • CVE-2021-24160
    CVE-2021-24160
    In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, subscribers could upload zip archives containing malicious PHP files that would get extracted to the /rmp-menu/ directory. These fi ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:20 | 回复:0
  • CVE-2021-24161
    CVE-2021-24161
    In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into uploading a zip archive containing malicious PHP files. The attacke ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:23 | 回复:0
  • CVE-2021-24162
    CVE-2021-24162
    In the Reponsive Menu (free and Pro) WordPress plugins before 4.0.4, attackers could craft a request and trick an administrator into importing all new settings. These settings could be modified to inc ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:12 | 回复:0
  • CVE-2021-24163
    CVE-2021-24163
    The AJAX action, wp_ajax_ninja_forms_sendwp_remote_install_handler, did not have a capability check on it, nor did it have any nonce protection, therefore making it possible for low-level users, such ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:15 | 回复:0
  • CVE-2021-24164
    CVE-2021-24164
    In the Ninja Forms Contact Form WordPress plugin before 3.4.34.1, low-level users, such as subscribers, were able to trigger the action, wp_ajax_nf_oauth, and retrieve the connection url needed to est ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:7 | 回复:0
  • CVE-2021-24165
    CVE-2021-24165
    In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no pro ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:7 | 回复:0
  • CVE-2021-24166
    CVE-2021-24166
    The wp_ajax_nf_oauth_disconnect from the Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress WordPress plugin before 3.4.34 had no nonce protection making it possible for attacker ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:17 | 回复:0
  • CVE-2021-24167
    CVE-2021-24167
    When visiting a site running Web-Stat 1.4.0, the wts_web_stat_load_init function used the visitor’s browser to send an XMLHttpRequest request to https://wts2.one/ajax.htm?action=lookup_WP_accoun ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:9 | 回复:0
  • CVE-2021-24168
    CVE-2021-24168
    The Easy Contact Form Pro WordPress plugin before 1.1.1.9 did not properly sanitise the text fields (such as Email Subject, Email Recipient, etc) when creating or editing a form, leading to an authent ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:13 | 回复:0
  • CVE-2021-24169
    CVE-2021-24169
    This Advanced Order Export For WooCommerce WordPress plugin before 3.1.8 helps you to easily export WooCommerce order data. The tab parameter in the Admin Panel is vulnerable to reflected XSS.……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:16 | 回复:0
  • CVE-2021-24170
    CVE-2021-24170
    The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than was required for its functionality to users with the upload_files capability. T ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:18 | 回复:0
  • CVE-2021-24171
    CVE-2021-24171
    The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extensio ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:6 | 回复:0
  • CVE-2021-24172
    CVE-2021-24172
    The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the DB, plugins, and current .……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:13 | 回复:0
  • CVE-2021-24173
    CVE-2021-24173
    The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross- ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:11 | 回复:0
  • CVE-2021-24174
    CVE-2021-24174
    The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plug ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:11 | 回复:0
  • CVE-2021-24175
    CVE-2021-24175
    The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any u ...……
    作者:菜鸟教程小白 | 时间:2022-2-5 10:29 | 阅读:11 | 回复:0

关注我们

极客给你想要的成长

关注极客中国获取最新资讯

热门推荐
专题导读
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap