unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2023-23836
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands. CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:50 +0000 UTC Push: 2023-02-16 06:17:52 +0000 UTC |
Live-Hack-CVE/CVE-2023-0697
Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 110.0.5481.77 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: High) CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:31 +0000 UTC Push: 2023-02-16 06:17:33 +0000 UTC |
Live-Hack-CVE/CVE-2023-0696
Type confusion in V8 in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:27 +0000 UTC Push: 2023-02-16 06:17:30 +0000 UTC |
Live-Hack-CVE/CVE-2023-0698
Out of bounds read in WebRTC in Google Chrome prior to 110.0.5481.77 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) CVE project by @Sn0wAlice
Create: 2023-02-16 06:17:23 +0000 UTC Push: 2023-02-16 06:17:26 +0000 UTC |
HritikThapa7/CVE-2023-31711
Zero-day Vulnerability in ZKTEco biometric fingerprint reader.
Create: 2023-02-16 04:27:52 +0000 UTC Push: 2023-05-31 16:15:36 +0000 UTC |
Live-Hack-CVE/CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it). CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:45 +0000 UTC Push: 2023-02-16 04:06:48 +0000 UTC |
Live-Hack-CVE/CVE-2022-44267
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert process could be left waiting for stdin input. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:41 +0000 UTC Push: 2023-02-16 04:06:44 +0000 UTC |
Live-Hack-CVE/CVE-2022-46892
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:35 +0000 UTC Push: 2023-02-16 04:06:38 +0000 UTC |
Live-Hack-CVE/CVE-2021-27568
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:30 +0000 UTC Push: 2023-02-16 04:06:32 +0000 UTC |
Live-Hack-CVE/CVE-2023-22807
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:25 +0000 UTC Push: 2023-02-16 04:06:28 +0000 UTC |
Live-Hack-CVE/CVE-2023-22806
LS ELECTRIC XBC-DN32U with operating system version 01.80 transmits sensitive information in cleartext when communicating over its XGT protocol. This could allow an attacker to gain sensitive information such as user credentials. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:21 +0000 UTC Push: 2023-02-16 04:06:24 +0000 UTC |
Live-Hack-CVE/CVE-2023-22805
LS ELECTRIC XBC-DN32U with operating system version 01.80 has improper access control to its read prohibition feature. This could allow a remote attacker to remotely set the feature to lock users out of reading data from the device. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:18 +0000 UTC Push: 2023-02-16 04:06:20 +0000 UTC |
Live-Hack-CVE/CVE-2023-22804
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:14 +0000 UTC Push: 2023-02-16 04:06:16 +0000 UTC |
Live-Hack-CVE/CVE-2023-22803
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to perform critical functions to the PLC. This could allow an attacker to change the PLC's mode arbitrarily. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:10 +0000 UTC Push: 2023-02-16 04:06:12 +0000 UTC |
Live-Hack-CVE/CVE-2023-0361
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:06 +0000 UTC Push: 2023-02-16 04:06:09 +0000 UTC |
Live-Hack-CVE/CVE-2023-0103
If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are outside of the communication buffer, the device stops operating. This could allow an attacker to cause a denial-of-service condition. CVE project by @Sn0wAlice
Create: 2023-02-16 04:06:03 +0000 UTC Push: 2023-02-16 04:06:05 +0000 UTC |
Live-Hack-CVE/CVE-2022-45587
Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial of service. CVE project by @Sn0wAlice
Create: 2023-02-16 04:05:59 +0000 UTC Push: 2023-02-16 04:06:01 +0000 UTC |
Live-Hack-CVE/CVE-2023-0102
LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files. CVE project by @Sn0wAlice
Create: 2023-02-16 04:05:55 +0000 UTC Push: 2023-02-16 04:05:57 +0000 UTC |
Live-Hack-CVE/CVE-2022-45586
Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a denial of service. CVE project by @Sn0wAlice
Create: 2023-02-16 04:05:51 +0000 UTC Push: 2023-02-16 04:05:53 +0000 UTC |
yerodin/CVE-2022-45701
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated) POC Exploit for CVE-2022-45701
Create: 2023-02-16 02:31:32 +0000 UTC Push: 2023-02-16 02:31:32 +0000 UTC |
Previous
364
365
366
367
368
369
370
371
Next