unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2021-3521
There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signature." RPM does not check the binding signature of subkeys prior to importing them. If an attacker is able to add or socially engineer another party to add a malicious subkey to a legitimate public ke CVE project by @Sn0wAlice
Create: 2022-12-28 08:33:49 +0000 UTC Push: 2022-12-28 08:33:51 +0000 UTC |
Live-Hack-CVE/CVE-2022-37016
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. CVE project by @Sn0wAlice
Create: 2022-12-28 07:52:50 +0000 UTC Push: 2022-12-28 07:52:52 +0000 UTC |
Live-Hack-CVE/CVE-2021-31875
** DISPUTED ** In mjs_json.c in Cesanta MongooseOS mJS 1.26, a maliciously formed JSON string can trigger an off-by-one heap-based buffer overflow in mjs_json_parse, which can potentially lead to redirection of control flow. NOTE: the original reporter disputes the significance of this finding because "there isn’t very CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:44 +0000 UTC Push: 2022-12-27 23:01:46 +0000 UTC |
Live-Hack-CVE/CVE-2022-4748
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the argument deletefile leads to path traversal. The name of the patch is 5 CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:40 +0000 UTC Push: 2022-12-27 23:01:42 +0000 UTC |
Live-Hack-CVE/CVE-2019-25087
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The n CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:37 +0000 UTC Push: 2022-12-27 23:01:39 +0000 UTC |
Live-Hack-CVE/CVE-2019-25086
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely. Upgradi CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:33 +0000 UTC Push: 2022-12-27 23:01:35 +0000 UTC |
Live-Hack-CVE/CVE-2018-25049
A vulnerability was found in email-existence. It has been rated as problematic. Affected by this issue is some unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The name of the patch is 0029ba71b6ad0d8ec0baa2ecc6256d038bdd9b56. It is recommended to apply a CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:30 +0000 UTC Push: 2022-12-27 23:01:32 +0000 UTC |
Live-Hack-CVE/CVE-2015-10005
A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is 89c8620157 CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:26 +0000 UTC Push: 2022-12-27 23:01:28 +0000 UTC |
Live-Hack-CVE/CVE-2022-4755
A vulnerability was found in FlatPress and classified as problematic. This issue affects the function main of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component Media Manager Plugin. The manipulation of the argument mm-newgallery-name leads to cross site scripting. The attack may be in CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:23 +0000 UTC Push: 2022-12-27 23:01:25 +0000 UTC |
Live-Hack-CVE/CVE-2021-4284
A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknown part. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.0 is able to address this issue. The name CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:19 +0000 UTC Push: 2022-12-27 23:01:21 +0000 UTC |
Live-Hack-CVE/CVE-2021-4283
A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation of the argument key leads to cross site scripting. The attack may be launched remotely. Upgrading to CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:16 +0000 UTC Push: 2022-12-27 23:01:18 +0000 UTC |
Live-Hack-CVE/CVE-2021-4282
A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 14.0.6.25 is able to address this issu CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:12 +0000 UTC Push: 2022-12-27 23:01:14 +0000 UTC |
Live-Hack-CVE/CVE-2019-25088
A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 5 CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:09 +0000 UTC Push: 2022-12-27 23:01:11 +0000 UTC |
Live-Hack-CVE/CVE-2021-4287
A vulnerability, which was classified as problematic, was found in ReFirm Labs binwalk up to 2.3.2. Affected is an unknown function of the file src/binwalk/modules/extractor.py of the component Archive Extraction Handler. The manipulation leads to symlink following. It is possible to launch the attack remotely. Upgradi CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:05 +0000 UTC Push: 2022-12-27 23:01:07 +0000 UTC |
Live-Hack-CVE/CVE-2021-4286
A vulnerability, which was classified as problematic, has been found in cocagne pysrp up to 1.0.16. This issue affects the function calculate_x of the file srp/_ctsrp.py. The manipulation leads to information exposure through discrepancy. Upgrading to version 1.0.17 is able to address this issue. The name of the patch CVE project by @Sn0wAlice
Create: 2022-12-27 23:01:02 +0000 UTC Push: 2022-12-27 23:01:04 +0000 UTC |
Live-Hack-CVE/CVE-2021-4285
A vulnerability classified as problematic was found in Nagios NCPA. This vulnerability affects unknown code of the file agent/listener/templates/tail.html. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 2.4.0 is able to address this issue. CVE project by @Sn0wAlice
Create: 2022-12-27 23:00:59 +0000 UTC Push: 2022-12-27 23:01:01 +0000 UTC |
Live-Hack-CVE/CVE-2019-25089
A vulnerability has been found in Morgawr Muon 0.1.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file src/muon/handler.clj. The manipulation leads to insufficiently random values. The attack can be launched remotely. Upgrading to version 0.2.0-indev is able to addres CVE project by @Sn0wAlice
Create: 2022-12-27 23:00:55 +0000 UTC Push: 2022-12-27 23:00:57 +0000 UTC |
jgamblin/2022CVEReview
2022 CVE Data Review
Create: 2022-12-27 22:02:44 +0000 UTC Push: 2023-01-02 03:56:21 +0000 UTC |
Live-Hack-CVE/CVE-2022-23530
GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to v0.1.8 are vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package. Extracting files using shutil.unpack_archive() from a potentially malicious tarball without validating that the destination file path is with CVE project by @Sn0wAlice
Create: 2022-12-27 19:29:52 +0000 UTC Push: 2022-12-27 19:29:54 +0000 UTC |
Live-Hack-CVE/CVE-2022-45404
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107. CVE project by @Sn0wAlice
Create: 2022-12-27 18:45:42 +0000 UTC Push: 2022-12-27 18:45:44 +0000 UTC |
Previous
568
569
570
571
572
573
574
575
Next