• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    迪恩网络公众号

漏洞

RSS

下级分类:

  • CVE-2022-22116
    CVE-2022-22116
    In Directus, versions 9.0.0-alpha.4 through 9.4.1 are vulnerable to stored Cross-Site Scripting (XSS) vulnerability via SVG file upload in media upload functionality. A low privileged attacker can inj ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:01 | 阅读:17 | 回复:0
  • CVE-2022-22115
    CVE-2022-22115
    In Teedy, versions v1.5 through v1.9 are vulnerable to Stored Cross-Site Scripting (XSS) in the name of a created Tag. Since the Tag name is not being sanitized properly in the edit tag page, a low pr ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:01 | 阅读:16 | 回复:0
  • CVE-2022-22114
    CVE-2022-22114
    In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term search functionality is not sufficiently sanitized while displaying the results of the se ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:01 | 阅读:14 | 回复:0
  • CVE-2022-0158
    CVE-2022-0158
    vim is vulnerable to Heap-based Buffer Overflow……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:01 | 阅读:14 | 回复:0
  • CVE-2022-0157
    CVE-2022-0157
    phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:01 | 阅读:18 | 回复:0
  • CVE-2022-0156
    CVE-2022-0156
    vim is vulnerable to Use After Free……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:15 | 回复:0
  • CVE-2021-44458
    CVE-2021-44458
    Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so ope ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:15 | 回复:0
  • CVE-2021-43951
    CVE-2021-43951
    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view object import configuration details via an Information Disclosure vulnerabili ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:20 | 回复:0
  • CVE-2021-43949
    CVE-2021-43949
    Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to view private objects via a Broken Access Control vulnerability in the Custom Field ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:24 | 回复:0
  • CVE-2021-43297
    CVE-2021-43297
    A deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/ ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:30 | 回复:0
  • CVE-2021-25054
    CVE-2021-25054
    The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:41 | 回复:0
  • CVE-2021-25053
    CVE-2021-25053
    The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:52 | 回复:0
  • CVE-2021-25052
    CVE-2021-25052
    The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus lea ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:50 | 回复:0
  • CVE-2021-25051
    CVE-2021-25051
    The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:61 | 回复:0
  • CVE-2021-25047
    CVE-2021-25047
    The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulnerability in the wdi_apply_changes admin page, allowing an attacker to perform suc ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:94 | 回复:0
  • CVE-2021-25043
    CVE-2021-25043
    The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:143 | 回复:0
  • CVE-2021-25032
    CVE-2021-25032
    The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's sett ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:120 | 回复:0
  • CVE-2021-24949
    CVE-2021-24949
    The WP Search Filters widget of The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not sanitise and escape the option parameter before using it in a SQL statement, which could lead ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:86 | 回复:0
  • CVE-2021-24948
    CVE-2021-24948
    The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrie ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:41 | 回复:0
  • CVE-2021-24862
    CVE-2021-24862
    The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could le ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:37 | 回复:0
  • CVE-2021-23218
    CVE-2021-23218
    When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:30 | 回复:0
  • CVE-2021-23154
    CVE-2021-23154
    In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:28 | 回复:0
  • CVE-2021-44586
    CVE-2021-44586
    An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose sensitive information.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:31 | 回复:0
  • CVE-2022-22847
    CVE-2022-22847
    Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in a configuration that does not require authentication).……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:24 | 回复:0
  • CVE-2022-22846
    CVE-2022-22846
    The dnslib package through 0.9.16 for Python does not verify that the ID value in a DNS reply matches an ID value in a query.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:26 | 回复:0
  • CVE-2022-22845
    CVE-2022-22845
    QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:26 | 回复:0
  • CVE-2022-22844
    CVE-2022-22844
    LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:30 | 回复:0
  • CVE-2022-22836
    CVE-2022-22836
    CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:19 | 回复:0
  • CVE-2022-22827
    CVE-2022-22827
    storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:17 | 回复:0
  • CVE-2022-22826
    CVE-2022-22826
    nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:19 | 回复:0
  • CVE-2022-22825
    CVE-2022-22825
    lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:23 | 回复:0
  • CVE-2022-22824
    CVE-2022-22824
    defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:29 | 回复:0
  • CVE-2022-22823
    CVE-2022-22823
    build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:31 | 回复:0
  • CVE-2022-22822
    CVE-2022-22822
    addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:51 | 回复:0
  • CVE-2022-22821
    CVE-2022-22821
    NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:22 | 回复:0
  • CVE-2022-22817
    CVE-2022-22817
    PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expression could also be used,……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:29 | 回复:0
  • CVE-2022-22816
    CVE-2022-22816
    path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:34 | 回复:0
  • CVE-2022-22815
    CVE-2022-22815
    path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:38 | 回复:0
  • CVE-2022-22702
    CVE-2022-22702
    PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not validate that requests can be made to local ports, allowing an authenticated user ...……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:29 | 回复:0
  • CVE-2022-22701
    CVE-2022-22701
    PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.……
    作者:菜鸟教程小白 | 时间:2022-6-22 22:00 | 阅读:29 | 回复:0

关注我们

极客给你想要的成长

关注极客中国获取最新资讯

热门推荐
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap