unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2018-3912
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack. The strcpy call overflows the destination buffer, which has a size of 128 bytes. An attacker can s CVE project by @Sn0wAlice
Create: 2023-02-17 14:45:42 +0000 UTC Push: 2023-02-17 14:45:44 +0000 UTC |
Therootkitsec/-CVE-2017-7269
Create: 2023-02-17 08:31:27 +0000 UTC Push: 2023-02-17 08:31:41 +0000 UTC |
Live-Hack-CVE/CVE-2015-10077
A vulnerability was found in webbuilders-group silverstripe-kapost-bridge 0.3.3. It has been declared as critical. Affected by this vulnerability is the function index/getPreview of the file code/control/KapostService.php. The manipulation leads to sql injection. The attack can be launched remotely. Upgrading to versio CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:41 +0000 UTC Push: 2023-02-17 07:58:43 +0000 UTC |
Live-Hack-CVE/CVE-2022-4903
A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensitive communication. It is possible to launch the attack remotely. Upgrading to version 7.0.71 is able to address this issue. The name of the CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:37 +0000 UTC Push: 2023-02-17 07:58:39 +0000 UTC |
Live-Hack-CVE/CVE-2023-24344
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWlanGuestSetup. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:34 +0000 UTC Push: 2023-02-17 07:58:36 +0000 UTC |
Live-Hack-CVE/CVE-2023-24343
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSchedule. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:30 +0000 UTC Push: 2023-02-17 07:58:33 +0000 UTC |
Live-Hack-CVE/CVE-2023-24346
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the wan_connected parameter at /goform/formEasySetupWizard3. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:27 +0000 UTC Push: 2023-02-17 07:58:29 +0000 UTC |
Live-Hack-CVE/CVE-2023-24345
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetWanDhcpplus. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:24 +0000 UTC Push: 2023-02-17 07:58:26 +0000 UTC |
Live-Hack-CVE/CVE-2023-24347
D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formSetWanDhcpplus. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:20 +0000 UTC Push: 2023-02-17 07:58:22 +0000 UTC |
Live-Hack-CVE/CVE-2023-25151
opentelemetry-go-contrib is a collection of extensions for OpenTelemetry-Go. The v0.38.0 release of `go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp` uses the `httpconv.ServerRequest` function to annotate metric measurements for the `http.server.request_content_length`, `http.server.response_content_lengt CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:14 +0000 UTC Push: 2023-02-17 07:58:16 +0000 UTC |
Live-Hack-CVE/CVE-2023-0821
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:10 +0000 UTC Push: 2023-02-17 07:58:13 +0000 UTC |
Live-Hack-CVE/CVE-2022-47703
TIANJIE CPE906-3 is vulnerable to password disclosure. This is present on Software Version WEB5.0_LCD_20200513, Firmware Version MV8.003, and Hardware Version CPF906-V5.0_LCD_20200513. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:06 +0000 UTC Push: 2023-02-17 07:58:09 +0000 UTC |
Live-Hack-CVE/CVE-2022-44299
SiteServerCMS 7.1.3 sscms has a file read vulnerability. CVE project by @Sn0wAlice
Create: 2023-02-17 07:58:02 +0000 UTC Push: 2023-02-17 07:58:05 +0000 UTC |
Live-Hack-CVE/CVE-2022-0637
There was an open redirection vulnerability pollbot, which was used in https://pollbot.services.mozilla.com/ and https://pollbot.stage.mozaws.net/ An attacker could have redirected anyone to malicious sites. CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:58 +0000 UTC Push: 2023-02-17 07:58:01 +0000 UTC |
Live-Hack-CVE/CVE-2021-43529
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with DER-encoded DSA or RSA-PSS signatures. CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:55 +0000 UTC Push: 2023-02-17 07:57:57 +0000 UTC |
Live-Hack-CVE/CVE-2021-23980
A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscript, script, textarea, noframes, iframe, or xmp in allowed tags the keyword argument strip_comments=False Note: none of the above tags are in the default allowed tags and strip_comme CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:52 +0000 UTC Push: 2023-02-17 07:57:54 +0000 UTC |
Live-Hack-CVE/CVE-2020-6817
bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}). CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:48 +0000 UTC Push: 2023-02-17 07:57:51 +0000 UTC |
Live-Hack-CVE/CVE-2019-17003
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed. CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:45 +0000 UTC Push: 2023-02-17 07:57:47 +0000 UTC |
Live-Hack-CVE/CVE-2020-12413
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites. CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:41 +0000 UTC Push: 2023-02-17 07:57:43 +0000 UTC |
Live-Hack-CVE/CVE-2023-25150
Nextcloud office/richdocuments is an office suit for the nextcloud server platform. In affected versions the Collabora integration can be tricked to provide access to any file without proper permission validation. As a result any user with access to Collabora can obtain the content of other users files. It is recommend CVE project by @Sn0wAlice
Create: 2023-02-17 07:57:37 +0000 UTC Push: 2023-02-17 07:57:40 +0000 UTC |
Previous
893
894
895
896
897
898
899
900
Next