Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | spider-flow | 0.4.3 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | SpiderFlow Crawler Platform - Remote Code Execution | https://github.com/Cappricio-Securities/CVE-2024-0195 | POC Details |
| 2 | CVE-2024-0195 Improper Control of Generation of Code ('Code Injection') | https://github.com/fa-rrel/CVE-2024-0195-SpiderFlow | POC Details |
| 3 | None | https://github.com/MuhammadWaseem29/CVE-2024-0195-SpiderFlow | POC Details |
| 4 | None | https://github.com/hack-with-rohit/CVE-2024-0195-SpiderFlow | POC Details |
| 5 | CVE-2024-0195 Improper Control of Generation of Code ('Code Injection') | https://github.com/gh-ost00/CVE-2024-0195-SpiderFlow | POC Details |
| 6 | A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file src/main/java/org/spiderflow/controller/FunctionController.java. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249510 is the identifier assigned to this vulnerability. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-0195.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-26159 | 7.3 HIGH | Follow Redirects 安全漏洞 |
| CVE-2024-0196 | 6.3 MEDIUM | Magic-Api code injection |
| CVE-2023-26157 | 5.5 MEDIUM | libredwg 安全漏洞 |
| CVE-2015-10128 | 3.5 LOW | rt-prettyphoto Plugin rt-prettyphoto.php royal_prettyphoto_plugin_links cross site scripti |
| CVE-2023-49558 | YASM 安全漏洞 | |
| CVE-2023-49557 | YASM 安全漏洞 | |
| CVE-2023-49556 | yasm 安全漏洞 | |
| CVE-2023-49555 | YASM 安全漏洞 | |
| CVE-2023-49554 | YASM 安全漏洞 | |
| CVE-2023-49553 | Cesanta MJS 安全漏洞 | |
| CVE-2023-49552 | Cesanta MJS 安全漏洞 | |
| CVE-2023-49551 | Cesanta MJS 安全漏洞 | |
| CVE-2023-49550 | Cesanta MJS 安全漏洞 | |
| CVE-2023-49549 | Cesanta MJS 安全漏洞 | |
| CVE-2023-50020 | Open5GS 安全漏洞 | |
| CVE-2023-50019 | Open5GS 安全漏洞 | |
| CVE-2020-26625 | Gila CMS SQL注入漏洞 | |
| CVE-2020-26624 | Gila CMS SQL注入漏洞 | |
| CVE-2020-26623 | Gila CMS SQL注入漏洞 | |
| CVE-2023-47458 | SpringBlade 安全漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet