渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an affec CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-46354
#CVE_2022
创建者:Live-Hack-CVE
项目描述:A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of an affec CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-46354
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-46354: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:Windows Graphics Component Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41121, CVE-2022-44680, CVE-2022-44697. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-44671
#CVE_2022
创建者:Live-Hack-CVE
项目描述:Windows Graphics Component Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41121, CVE-2022-44680, CVE-2022-44697. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-44671
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-44671: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:Windows Error Reporting Elevation of Privilege Vulnerability. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-44669
#CVE_2022
创建者:Live-Hack-CVE
项目描述:Windows Error Reporting Elevation of Privilege Vulnerability. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-44669
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-44669: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:wr0x00
项目描述:A python-based network security penetration testing tool.一款基于python的web安全渗透测试集成工具
项目链接:https://github.com/wr0x00/Lizard
#渗透 #cve #cve_2018_9995 #cve_2021_21907 #exp #exploit #hacking_tool #hackweb #password #poc #scanning #shodan_python #termux_hacking #termux_tool #webshell
创建者:wr0x00
项目描述:A python-based network security penetration testing tool.一款基于python的web安全渗透测试集成工具
项目链接:https://github.com/wr0x00/Lizard
#渗透 #cve #cve_2018_9995 #cve_2021_21907 #exp #exploit #hacking_tool #hackweb #password #poc #scanning #shodan_python #termux_hacking #termux_tool #webshell
GitHub
GitHub - wr0x00/Lizard: A python-based network security penetration testing tool.一款基于python的web安全渗透测试集成工具
A python-based network security penetration testing tool.一款基于python的web安全渗透测试集成工具 - wr0x00/Lizard
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-45688
#CVE_2022
创建者:Live-Hack-CVE
项目描述:A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-45688
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-45688: A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers…
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data. CVE project by @Sn0wAlice - GitHub - Live...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-4446
#CVE_2022
创建者:Live-Hack-CVE
项目描述:PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-4446
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-4446: This repository contains a collection of data files on known Common Vulnerabilities and Exposures…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-38124
#CVE_2022
创建者:Live-Hack-CVE
项目描述:Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-38124
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-38124: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-44303
#CVE_2022
创建者:Live-Hack-CVE
项目描述:Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-44303
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-44303: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsing ICAP request. The exploit can be triggered remotely by an attacker. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-45871
#CVE_2022
创建者:Live-Hack-CVE
项目描述:A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the service may crash while parsing ICAP request. The exploit can be triggered remotely by an attacker. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-45871
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-45871: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. T CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-39320
#CVE_2022
创建者:Live-Hack-CVE
项目描述:FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. T CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-39320
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-39320: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
👍1
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting u CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-41272
#CVE_2022
创建者:Live-Hack-CVE
项目描述:An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting u CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-41272
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-41272: An unauthenticated attacker over the network can attach to an open interface exposed through…
An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make ...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-41273
#CVE_2022
创建者:Live-Hack-CVE
项目描述:Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-41273
#CVE_2022
GitHub
Live-Hack-CVE/CVE-2022-41273
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing attack, with little impact on confidentiality CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-41275
#CVE_2022
创建者:Live-Hack-CVE
项目描述:In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing attack, with little impact on confidentiality CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-41275
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-41275: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1 CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-20487
#CVE_2022
创建者:Live-Hack-CVE
项目描述:In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1 CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-20487
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-20487: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1 CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-20491
#CVE_2022
创建者:Live-Hack-CVE
项目描述:In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-1 CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-20491
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-20491: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-41268
#CVE_2022
创建者:Live-Hack-CVE
项目描述:In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-41268
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-41268: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-36534
#rce
创建者:Live-Hack-CVE
项目描述:Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-36534
#rce
GitHub
GitHub - Live-Hack-CVE/CVE-2022-36534: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-31625
#rce
创建者:Live-Hack-CVE
项目描述:In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-31625
#rce
GitHub
GitHub - Live-Hack-CVE/CVE-2022-31625: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detached and reclaim resources early. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-1195
#CVE_2022
创建者:Live-Hack-CVE
项目描述:A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or sixpack device is detached and reclaim resources early. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-1195
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-1195: A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This…
A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker with a user privilege to cause a denial of service (DOS) when the mkiss or si...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-1353
#CVE_2022
创建者:Live-Hack-CVE
项目描述:A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information. CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-1353
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-1353: This repository contains a collection of data files on known Common Vulnerabilities and Exposures…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...
渗透/安全推送中心 @cvebird
创建者:Live-Hack-CVE
项目描述:Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing Respon CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-25836
#CVE_2022
创建者:Live-Hack-CVE
项目描述:Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure Connections Passkey Pairing with the pairing Respon CVE project by @Sn0wAlice
项目链接:https://github.com/Live-Hack-CVE/CVE-2022-25836
#CVE_2022
GitHub
GitHub - Live-Hack-CVE/CVE-2022-25836: This repository contains a collection of data files on known Common Vulnerabilities and…
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file is in JSON format and contains detailed information about the vulnerability, such...