unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2022-4656
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack. CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:32 +0000 UTC Push: 2023-02-14 02:07:34 +0000 UTC |
Live-Hack-CVE/CVE-2022-4628
The Easy PayPal Buy Now Button WordPress plugin before 1.7.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:28 +0000 UTC Push: 2023-02-14 02:07:30 +0000 UTC |
Live-Hack-CVE/CVE-2022-4580
The Twenty20 Image Before-After WordPress plugin through 1.5.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:24 +0000 UTC Push: 2023-02-14 02:07:27 +0000 UTC |
Live-Hack-CVE/CVE-2022-4562
The Meks Flexible Shortcodes WordPress plugin before 1.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:20 +0000 UTC Push: 2023-02-14 02:07:23 +0000 UTC |
Live-Hack-CVE/CVE-2022-4551
The Rich Table of Contents WordPress plugin through 1.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:16 +0000 UTC Push: 2023-02-14 02:07:19 +0000 UTC |
Live-Hack-CVE/CVE-2022-4546
The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:12 +0000 UTC Push: 2023-02-14 02:07:15 +0000 UTC |
Live-Hack-CVE/CVE-2022-4512
The Better Font Awesome WordPress plugin before 2.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. CVE project by @Sn0wAlice
Create: 2023-02-14 02:07:04 +0000 UTC Push: 2023-02-14 02:07:10 +0000 UTC |
Live-Hack-CVE/CVE-2022-4488
The Widgets on Pages WordPress plugin through 1.6.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:58 +0000 UTC Push: 2023-02-14 02:07:02 +0000 UTC |
Live-Hack-CVE/CVE-2022-4473
The Widget Shortcode WordPress plugin through 0.3.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as adm CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:54 +0000 UTC Push: 2023-02-14 02:06:57 +0000 UTC |
Live-Hack-CVE/CVE-2022-4471
The YARPP WordPress plugin through 5.30.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:50 +0000 UTC Push: 2023-02-14 02:06:53 +0000 UTC |
Live-Hack-CVE/CVE-2022-4458
The amr shortcode any widget WordPress plugin through 4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:46 +0000 UTC Push: 2023-02-14 02:06:48 +0000 UTC |
Live-Hack-CVE/CVE-2022-4448
The GiveWP WordPress plugin before 2.24.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:42 +0000 UTC Push: 2023-02-14 02:06:45 +0000 UTC |
Live-Hack-CVE/CVE-2022-4445
The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:39 +0000 UTC Push: 2023-02-14 02:06:41 +0000 UTC |
Live-Hack-CVE/CVE-2022-40022
Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:35 +0000 UTC Push: 2023-02-14 02:06:37 +0000 UTC |
Live-Hack-CVE/CVE-2022-3891
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones. CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:31 +0000 UTC Push: 2023-02-14 02:06:34 +0000 UTC |
Live-Hack-CVE/CVE-2023-23937
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. The upload functionality for updating user profile does not properly validate the file content-type, allowing any authenticated user to bypass this security check by adding a valid signature (p.e. GIF89) and CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:27 +0000 UTC Push: 2023-02-14 02:06:30 +0000 UTC |
Live-Hack-CVE/CVE-2021-37374
** UNSUPPORTED WHEN ASSIGNED ** Cross Site Scripting (XSS) vulnerability in Teradek Clip all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates t CVE project by @Sn0wAlice
Create: 2023-02-14 02:06:24 +0000 UTC Push: 2023-02-14 02:06:26 +0000 UTC |
Live-Hack-CVE/CVE-2022-45725
Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request CVE project by @Sn0wAlice
Create: 2023-02-13 23:54:53 +0000 UTC Push: 2023-02-13 23:54:55 +0000 UTC |
Live-Hack-CVE/CVE-2022-45724
Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an unauthenticated page to force the server to generate a SESSION_ID, and using this SESSION_ID an attacker can then perform authenticated requests. CVE project by @Sn0wAlice
Create: 2023-02-13 23:54:49 +0000 UTC Push: 2023-02-13 23:54:51 +0000 UTC |
Live-Hack-CVE/CVE-2021-37315
Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations. CVE project by @Sn0wAlice
Create: 2023-02-13 23:54:43 +0000 UTC Push: 2023-02-13 23:54:45 +0000 UTC |
Previous
378
379
380
381
382
383
384
385
Next