CVE-2023-34124 描述: The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2025-07-22 其他 #attackerkb.com
CVE-2023-36846 描述: A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system 2025-07-22 其他 #attackerkb.com
The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file 链接: https://github.com/advisories/GHSA-vh36-c3hc-6876 CVSS 评分: 9.8 参考链接: https://nvd.nist.gov/vuln/detail/CVE-2015-10137 https://packetstormsecurity.com/files/131413 https://packetstormsecurity.com 2025-07-22 安全公告 #Github Advisory
The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file 链接: https://github.com/advisories/GHSA-jj57-5w64-pjmg CVSS 评分: 9.8 参考链接: https://nvd.nist.gov/vuln/detail/CVE-2012-10020 https://packetstormsecurity.com/files/113576 https://plugins.trac.wordpress. 2025-07-22 安全公告 #Github Advisory
parisneo/lollms Remote Code Execution Vulnerability 漏洞信息漏洞名称: parisneo/lollms Remote Code Execution Vulnerability 漏洞编号: CVE: CVE-2024-3121 漏洞类型: 命令执行 漏洞等级: 高危 漏洞描述: 该漏洞存在于parisneo/lollms的create_conda_env函数中,允许攻击者执行远程代码。lollms是一个用于机器学习的库,广泛应 2025-07-22 Github Poc #命令执行 #CVE-2024:github search
blackbird:利用网名和邮箱获取信息的OSINT情报获取工具 公众号: Z1Sec 链接: https://mp.weixin.qq.com/s/JIupCAatqWFi9gimMOBcZg 2025-07-22 微信公众号 #mp.weixin.qq.com #Z1Sec
渗透Tips:找盲SSRF的FUZZ技巧 公众号: Z1Sec 链接: https://mp.weixin.qq.com/s/NbrLnKNTtD4SVZqCIwfAeg 2025-07-22 微信公众号 #mp.weixin.qq.com #Z1Sec
Appsmith 权限提升漏洞 漏洞信息漏洞名称: Appsmith 权限提升漏洞 漏洞编号: CVE: CVE-2024-55963 漏洞类型: 权限提升 漏洞等级: 高危 漏洞描述: Appsmith是一个开源的、低代码平台,用于构建内部工具和应用程序,广泛应用于企业级服务中,支持快速开发和部署。该平台因其易用性和灵活性,在开发者社区中颇受欢迎。此次发现的漏洞存在于Appsmith的/api/v1 2025-07-22 Github Poc #projectdiscovery/nuclei-templates:github issues #权限提升
GIGABYTE GDrv Driver 权限提升漏洞 漏洞信息漏洞名称: GIGABYTE GDrv Driver 权限提升漏洞 漏洞编号: CVE: CVE-2018-19323 漏洞类型: 权限提升 漏洞等级: 严重 漏洞描述: ### 受影响产品GIGABYTE APP Center、AORUS GRAPHICS ENGINE、XTREME GAMING ENGINE和OC GURU II是技嘉科技推出的软件套件,主要用于硬件监控、超频和系 2025-07-22 Github Poc #projectdiscovery/nuclei-templates:github issues #权限提升
HVV神器Hfish开源蜜罐搭建 公众号: 网安独行侠 链接: https://mp.weixin.qq.com/s/-SMLvSWYz-OG_KrjCulsAw 2025-07-22 微信公众号 #mp.weixin.qq.com #网安独行侠