Craw Info
  • 首页
  • 归档
  • 分类
  • 标签
  • 关于

CVE-2023-34124

描述: The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics:
2025-07-22
其他
#attackerkb.com

CVE-2023-36846

描述: A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system
2025-07-22
其他
#attackerkb.com

The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file

链接: https://github.com/advisories/GHSA-vh36-c3hc-6876 CVSS 评分: 9.8 参考链接: https://nvd.nist.gov/vuln/detail/CVE-2015-10137 https://packetstormsecurity.com/files/131413 https://packetstormsecurity.com
2025-07-22
安全公告
#Github Advisory

The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file

链接: https://github.com/advisories/GHSA-jj57-5w64-pjmg CVSS 评分: 9.8 参考链接: https://nvd.nist.gov/vuln/detail/CVE-2012-10020 https://packetstormsecurity.com/files/113576 https://plugins.trac.wordpress.
2025-07-22
安全公告
#Github Advisory

parisneo/lollms Remote Code Execution Vulnerability

漏洞信息漏洞名称: parisneo/lollms Remote Code Execution Vulnerability 漏洞编号: CVE: CVE-2024-3121 漏洞类型: 命令执行 漏洞等级: 高危 漏洞描述: 该漏洞存在于parisneo/lollms的create_conda_env函数中,允许攻击者执行远程代码。lollms是一个用于机器学习的库,广泛应
2025-07-22
Github Poc
#命令执行 #CVE-2024:github search

blackbird:利用网名和邮箱获取信息的OSINT情报获取工具

公众号: Z1Sec 链接: https://mp.weixin.qq.com/s/JIupCAatqWFi9gimMOBcZg
2025-07-22
微信公众号
#mp.weixin.qq.com #Z1Sec

渗透Tips:找盲SSRF的FUZZ技巧

公众号: Z1Sec 链接: https://mp.weixin.qq.com/s/NbrLnKNTtD4SVZqCIwfAeg
2025-07-22
微信公众号
#mp.weixin.qq.com #Z1Sec

Appsmith 权限提升漏洞

漏洞信息漏洞名称: Appsmith 权限提升漏洞 漏洞编号: CVE: CVE-2024-55963 漏洞类型: 权限提升 漏洞等级: 高危 漏洞描述: Appsmith是一个开源的、低代码平台,用于构建内部工具和应用程序,广泛应用于企业级服务中,支持快速开发和部署。该平台因其易用性和灵活性,在开发者社区中颇受欢迎。此次发现的漏洞存在于Appsmith的/api/v1&#
2025-07-22
Github Poc
#projectdiscovery/nuclei-templates:github issues #权限提升

GIGABYTE GDrv Driver 权限提升漏洞

漏洞信息漏洞名称: GIGABYTE GDrv Driver 权限提升漏洞 漏洞编号: CVE: CVE-2018-19323 漏洞类型: 权限提升 漏洞等级: 严重 漏洞描述: ### 受影响产品GIGABYTE APP Center、AORUS GRAPHICS ENGINE、XTREME GAMING ENGINE和OC GURU II是技嘉科技推出的软件套件,主要用于硬件监控、超频和系
2025-07-22
Github Poc
#projectdiscovery/nuclei-templates:github issues #权限提升

HVV神器Hfish开源蜜罐搭建

公众号: 网安独行侠 链接: https://mp.weixin.qq.com/s/-SMLvSWYz-OG_KrjCulsAw
2025-07-22
微信公众号
#mp.weixin.qq.com #网安独行侠
1…6364656667…232

搜索

Hexo Fluid