Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | ThemeREX Addons plugin before 2020-03-09 for WordPress contains an access control vulnerability in the /trx_addons/v2/get/sc_layout REST API endpoint, allowing any users to execute PHP functions because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter, letting attackers execute arbitrary PHP functions, exploit requires no authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10257.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-9758 | LiveZilla Live Chat 跨站脚本漏洞 | |
| CVE-2016-6918 | Lexmark Markvision Enterprise 代码问题漏洞 | |
| CVE-2020-8987 | Avast AntiTrack和AVG Technologies Antitrack 信任管理问题漏洞 | |
| CVE-2016-1487 | Lexmark Markvision Enterprise 代码问题漏洞 | |
| CVE-2011-4538 | 多款Lexmark产品信息泄露漏洞 | |
| CVE-2011-3269 | 多款Lexmark产品信息泄露漏洞 | |
| CVE-2020-10192 | Munkireport 跨站脚本漏洞 | |
| CVE-2020-10191 | Munkireport 跨站脚本漏洞 | |
| CVE-2020-10190 | Munkireport SQL注入漏洞 | |
| CVE-2014-1634 | Magento Advanced Newsletter SQL注入漏洞 | |
| CVE-2020-10247 | MISP 跨站脚本漏洞 | |
| CVE-2020-10246 | MISP 跨站脚本漏洞 | |
| CVE-2019-19614 | Halvotec Information Services RAQuest 注入漏洞 | |
| CVE-2020-10244 | JPaseto 加密问题漏洞 | |
| CVE-2020-10250 | BWA Technology DiREX-Pro 操作系统命令注入漏洞 | |
| CVE-2020-10249 | BWA Technology DiREX-Pro 信息泄露漏洞 | |
| CVE-2020-10248 | BWA Technology DiREX-Pro 信息泄露漏洞 | |
| CVE-2016-11021 | D-Link DCS-930L 操作系统命令注入漏洞 | |
| CVE-2015-7338 | AcyMailing Joomla Component SQL注入漏洞 | |
| CVE-2015-7339 | JCE Joomla Component 代码问题漏洞 |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet