高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| Unknown | Awesome Weather Widget | 3.0.2 ~ 3.0.2 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2021-24473 | User Profile Picture < 2.6.0 - Arbitrary User Picture Change/Deletion via IDOR | |
| CVE-2021-24444 | TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24371 | RSVPMaker < 8.7.3 - Authenticated (admin+) SSRF | |
| CVE-2021-24425 | myStickymenu < 2.5.2 - Authenticated Stored XSS | |
| CVE-2021-24428 | RSS for Yandex Turbo <= 1.30 - Authenticated Stored XSS | |
| CVE-2021-24430 | Speed Booster Pack 4.2.0-beta - Authenticated (admin+) RCE | |
| CVE-2021-24443 | Youzify < 1.0.7 - Stored Cross-Site Scripting via Biography | |
| CVE-2021-24448 | Profile Builder < 3.4.8 - Authenticated Stored XSS | |
| CVE-2021-24450 | ProfilePress < 3.1.8 - Authenticated Stored XSS | |
| CVE-2021-24455 | Tutor LMS < 1.9.2 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24464 | YouTube Embed, Playlist and Popup < 2.3.9 - Contributor+ Stored XSS | |
| CVE-2021-24468 | Leaflet Map < 3.0.0 - Contributor+ Stored XSS | |
| CVE-2021-24470 | Yada Wiki < 3.4.1 - Contributor+ Stored XSS | |
| CVE-2021-24504 | WP LMS <= 1.1.2 - Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24476 | Steam Group Viewer <= 2.1 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24477 | Migrate Users <= 1.0.1 - CSRF to Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24478 | Bookshelf <= 2.0.4 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24479 | DrawBlog <= 0.90 - Authenticated Stored Cross-Site Scripting (XSS) | |
| CVE-2021-24480 | Event Geek <= 2.5.2 - Stored Cross-site Scripting (XSS) | |
| CVE-2021-24481 | Any Hostname <= 1.0.6 - Authenticated Stored Cross-Site Scripting (XSS) |
Showing 20 of 26 CVEs. View all on vendor page →
まだコメントはありません