Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XML external entity (XXE) attacks via an API request to PageControllerXml.jsp. One can send a request crafted with an XXE payload and achieve outcomes such as reading local server files or denial of service. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-27931.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-23347 | 4.7 MEDIUM | Cross-site Scripting (XSS) |
| CVE-2021-21978 | VMware View Planner 代码问题漏洞 | |
| CVE-2020-25647 | grub2 缓冲区错误漏洞 | |
| CVE-2020-25632 | grub2 资源管理错误漏洞 | |
| CVE-2021-20225 | grub2 缓冲区错误漏洞 | |
| CVE-2021-20233 | grub2 缓冲区错误漏洞 | |
| CVE-2020-29047 | WordPress 代码问题漏洞 | |
| CVE-2021-22877 | Nextcloud 访问控制错误漏洞 | |
| CVE-2021-22878 | Nextcloud Server 跨站脚本漏洞 | |
| CVE-2020-8296 | Nextcloud 安全漏洞 | |
| CVE-2020-27749 | grub2 缓冲区错误漏洞 | |
| CVE-2020-28597 | Epignosis EfrontPro 安全漏洞 | |
| CVE-2020-28591 | Slic3r 缓冲区错误漏洞 | |
| CVE-2020-13558 | WebKitGTK 资源管理错误漏洞 | |
| CVE-2021-22681 | Rockwell Automation RSLogix 500 和 Logix Designer Studio 5000 安全漏洞 | |
| CVE-2021-27839 | Online Invoicing System 注入漏洞 | |
| CVE-2021-27935 | AdGuard 安全漏洞 | |
| CVE-2021-27940 | openark orchestrator 跨站脚本漏洞 | |
| CVE-2021-22666 | FATEK FvDesigner 缓冲区错误漏洞 | |
| CVE-2021-27923 | Pillow 输入验证错误漏洞 |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet