unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2023-0022
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on t CVE project by @Sn0wAlice
Create: 2023-01-10 14:36:39 +0000 UTC Push: 2023-01-10 14:36:42 +0000 UTC |
Live-Hack-CVE/CVE-2023-0018
Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload. Once these reports are viewable, anyone who opens thos CVE project by @Sn0wAlice
Create: 2023-01-10 14:36:34 +0000 UTC Push: 2023-01-10 14:36:38 +0000 UTC |
Live-Hack-CVE/CVE-2023-0017
An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data on the current system. This could all CVE project by @Sn0wAlice
Create: 2023-01-10 14:36:30 +0000 UTC Push: 2023-01-10 14:36:33 +0000 UTC |
Live-Hack-CVE/CVE-2023-0015
In SAP BusinessObjects Business Intelligence Platform (Web Intelligence user interface) - version 420, some calls return json with wrong content type in the header of the response. As a result, a custom application that calls directly the jsp of Web Intelligence DHTML may be vulnerable to XSS attacks. On successful exp CVE project by @Sn0wAlice
Create: 2023-01-10 14:36:26 +0000 UTC Push: 2023-01-10 14:36:29 +0000 UTC |
Live-Hack-CVE/CVE-2022-4391
The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:46 +0000 UTC Push: 2023-01-10 10:09:48 +0000 UTC |
Live-Hack-CVE/CVE-2022-4301
The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:42 +0000 UTC Push: 2023-01-10 10:09:45 +0000 UTC |
Live-Hack-CVE/CVE-2022-4103
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:39 +0000 UTC Push: 2023-01-10 10:09:41 +0000 UTC |
Live-Hack-CVE/CVE-2022-4196
The Multi Step Form WordPress plugin before 1.7.8 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:35 +0000 UTC Push: 2023-01-10 10:09:37 +0000 UTC |
Live-Hack-CVE/CVE-2022-4102
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug. CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:30 +0000 UTC Push: 2023-01-10 10:09:33 +0000 UTC |
Live-Hack-CVE/CVE-2022-3417
The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentionally or not) a malicious settings file and a suitable gadget chain is present on the blog. CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:26 +0000 UTC Push: 2023-01-10 10:09:29 +0000 UTC |
Live-Hack-CVE/CVE-2022-3343
The WPQA Builder WordPress plugin before 5.9.3 (which is a companion plugin used with Discy and Himer WordPress themes) incorrectly tries to validate that a user already follows another in the wpqa_following_you_ajax action, allowing a user to inflate their score on the site by having another user send repeated follow CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:21 +0000 UTC Push: 2023-01-10 10:09:25 +0000 UTC |
Live-Hack-CVE/CVE-2022-3923
The ActiveCampaign for WooCommerce WordPress plugin through 1.9.6 does not have authorisation check when cleaning up its error logs via an AJAX action, which could allow any authenticated users, such as subscriber to call it and remove error logs. CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:17 +0000 UTC Push: 2023-01-10 10:09:20 +0000 UTC |
Live-Hack-CVE/CVE-2022-3416
The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup) CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:13 +0000 UTC Push: 2023-01-10 10:09:16 +0000 UTC |
Live-Hack-CVE/CVE-2022-4497
The Jetpack CRM WordPress plugin before 5.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:09 +0000 UTC Push: 2023-01-10 10:09:11 +0000 UTC |
Live-Hack-CVE/CVE-2022-4491
The WP-Table Reloaded WordPress plugin through 1.9.4 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high privilege users such a CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:06 +0000 UTC Push: 2023-01-10 10:09:08 +0000 UTC |
Live-Hack-CVE/CVE-2022-4479
The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as CVE project by @Sn0wAlice
Create: 2023-01-10 10:09:01 +0000 UTC Push: 2023-01-10 10:09:04 +0000 UTC |
Live-Hack-CVE/CVE-2022-4468
The WP Recipe Maker WordPress plugin before 8.6.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin CVE project by @Sn0wAlice
Create: 2023-01-10 10:08:57 +0000 UTC Push: 2023-01-10 10:08:58 +0000 UTC |
Live-Hack-CVE/CVE-2022-4426
The Mautic Integration for WooCommerce WordPress plugin before 1.0.3 does not have proper CSRF check when updating settings, and does not ensure that the options to be updated belong to the plugin, allowing attackers to make a logged in admin change arbitrary blog options via a CSRF attack. CVE project by @Sn0wAlice
Create: 2023-01-10 10:08:52 +0000 UTC Push: 2023-01-10 10:08:55 +0000 UTC |
Live-Hack-CVE/CVE-2022-4394
The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE project by @Sn0wAlice
Create: 2023-01-10 10:08:48 +0000 UTC Push: 2023-01-10 10:08:51 +0000 UTC |
Live-Hack-CVE/CVE-2022-4393
The ImageLinks Interactive Image Builder for WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. CVE project by @Sn0wAlice
Create: 2023-01-10 10:08:43 +0000 UTC Push: 2023-01-10 10:08:47 +0000 UTC |
Previous
527
528
529
530
531
532
533
534
Next