• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    公众号

CVE漏洞

RSS
  • CVE-2022-31374
    CVE-2022-31374
    An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:159 | 回复:0
  • CVE-2022-32414
    CVE-2022-32414
    Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:144 | 回复:0
  • CVE-2022-33119
    CVE-2022-33119
    NUUO Network Video Recorder NVRsolo v03.06.02 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via login.php.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:123 | 回复:0
  • CVE-2022-33139
    CVE-2022-33139
    A vulnerability has been identified in SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All v ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:159 | 回复:0
  • CVE-2022-23342
    CVE-2022-23342
    The Hyland Onbase Application Server releases prior to 20.3.58.1000 and OnBase releases 21.1.1.1000 through 21.1.15.1000 are vulnerable to a username enumeration vulnerability. An attacker can obtain ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:157 | 回复:0
  • CVE-2022-25585
    CVE-2022-25585
    Unioncms v1.0.13 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Default settings.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:150 | 回复:0
  • CVE-2022-29774
    CVE-2022-29774
    iSpyConnect iSpy v7.2.2.0 is vulnerable to path traversal.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:119 | 回复:0
  • CVE-2022-29775
    CVE-2022-29775
    iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:163 | 回复:0
  • CVE-2022-31478
    CVE-2022-31478
    The UserTakeOver plugin before 4.0.1 for ILIAS allows an attacker to list all users via the search function.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:199 | 回复:0
  • CVE-2022-33048
    CVE-2022-33048
    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:175 | 回复:0
  • CVE-2022-33049
    CVE-2022-33049
    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:147 | 回复:0
  • CVE-2022-33055
    CVE-2022-33055
    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:330 | 回复:0
  • CVE-2022-33056
    CVE-2022-33056
    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:129 | 回复:0
  • CVE-2021-41924
    CVE-2021-41924
    Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:115 | 回复:0
  • CVE-2022-1596
    CVE-2022-1596
    Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:176 | 回复:0
  • CVE-2022-1665
    CVE-2022-1665
    A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:161 | 回复:0
  • CVE-2022-1833
    CVE-2022-1833
    A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwid ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:152 | 回复:0
  • CVE-2022-22979
    CVE-2022-22979
    In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the cachin ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:169 | 回复:0
  • CVE-2022-23171
    CVE-2022-23171
    AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows c ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:203 | 回复:0
  • CVE-2022-26147
    CVE-2022-26147
    The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:192 | 回复:0
  • CVE-2022-27867
    CVE-2022-27867
    A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:176 | 回复:0
  • CVE-2022-27868
    CVE-2022-27868
    A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:182 | 回复:0
  • CVE-2022-27869
    CVE-2022-27869
    A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries when parsing the TIFF file. This vulnerability can be exploited to execute arbitrar ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:166 | 回复:0
  • CVE-2022-27870
    CVE-2022-27870
    A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing TGA file. This vulnerability may be exploited to execute arbitrary code.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:177 | 回复:0
  • CVE-2022-27871
    CVE-2022-27871
    Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulner ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:184 | 回复:0
  • CVE-2022-27872
    CVE-2022-27872
    A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fa ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:234 | 回复:0
  • CVE-2022-2068
    CVE-2022-2068
    In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command inje ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:522 | 回复:0
  • CVE-2022-30874
    CVE-2022-30874
    There is a Cross Site Scripting Stored (XSS) vulnerability in NukeViet CMS before 4.5.02.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:263 | 回复:0
  • CVE-2022-31786
    CVE-2022-31786
    IdeaLMS 2022 allows reflected Cross Site Scripting (XSS) via the IdeaLMS/Class/Assessment/ PATH_INFO.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:206 | 回复:0
  • CVE-2022-32973
    CVE-2022-32973
    An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:303 | 回复:0
  • CVE-2022-32974
    CVE-2022-32974
    An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:255 | 回复:0
  • CVE-2022-33995
    CVE-2022-33995
    A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:265 | 回复:0
  • CVE-2022-34008
    CVE-2022-34008
    Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:266 | 回复:0
  • CVE-2021-39006
    CVE-2021-39006
    IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 213549.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:285 | 回复:0
  • CVE-2021-36761
    CVE-2021-36761
    The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:237 | 回复:0
  • CVE-2021-40510
    CVE-2021-40510
    XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:230 | 回复:0
  • CVE-2021-40511
    CVE-2021-40511
    OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:225 | 回复:0
  • CVE-2022-31095
    CVE-2022-31095
    discourse-chat is a chat plugin for the Discourse application. Versions prior to 0.4 are vulnerable to an exposure of sensitive information, where an attacker who knows the message ID for a channel th ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:307 | 回复:0
  • CVE-2017-20082
    CVE-2017-20082
    A vulnerability, which was classified as problematic, has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. This issue affects some unknown processing. The manipulation leads to backdoor. ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:296 | 回复:0
  • CVE-2017-20083
    CVE-2017-20083
    A vulnerability, which was classified as critical, was found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. Affected is an unknown function of the component SSH Server. The manipulation leads to b ...……
    作者:菜鸟教程小白 | 时间:2022-6-23 09:07 | 阅读:280 | 回复:0

关注我们

极客给你想要的成长

关注极客中国获取最新资讯

热门推荐
专题导读
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap