
Repository curata di write-up di ricerca sulle vulnerabilità con CVE assegnati, che dettagliano le debolezze scoperte, l'impatto e le misure correttive in varie applicazioni.
Qui catalogo le vulnerabilità che ho scoperto, i relativi write-up con i dettagli delle debolezze e gli approfondimenti sul loro impatto e sulla loro mitigazione.
| ID CVE | Titolo della vulnerabilità | Gravità/CVSS | Pubblicazione | Write-up |
|---|---|---|---|---|
| N.A. | Microsoft Security Response Center (MSRC) Classifica dei Security Researcher Q1 2026 #192 | N/A | Apr 2026 | Pagina dei riconoscimenti ufficiali |
| N.A. | 3 x Riconoscimento di Security Researcher MSRC per Microsoft Online Services | N/A | Mar 2026 | Pagina dei riconoscimenti ufficiali |
| CVE-2025-63918 | wmjordan PDFPatcher <= 1.1.3.4663 Directory Traversal nella funzionalità di esportazione immagini | 6.2 | Nov 17, 2025 | Leggi il write-up completo |
| CVE-2025-63917 | wmjordan PDFPatcher <= 1.1.3.4663 XML External Entity (XXE) Injection | 7.1 | Nov 17, 2025 | Leggi il write-up completo |
| CVE-2025-63916 | luotengyuan MyScreenTools <= 2.2.1.0 OS Command Injection nello strumento di compressione GIF | 8.1 | Nov 17, 2025 | Leggi il write-up completo |
| N.A. | Microsoft 365 Copilot For Work: esfiltrazione di dati immagine da SharePoint | Bassa | Mar 22, 2025 | Leggi il write-up completo |
| CVE-2025-1548 | iteachyou Dreamer CMS(梦想家 CMS 内容管理系统)4.1.3 Remote File Inclusion | 5.1 | Feb 21, 2025 | Leggi il write-up completo |
| CVE-2025-1543 | iteachyou Dreamer CMS(梦想家 CMS 内容管理系统)4.1.3 Path Traversal | 5.3 | Feb 21, 2025 | Leggi il write-up completo |
| CVE-2025-1084 | Mindskip xzs-mysql (武汉思维跳跃科技有限公司 - 学之思开源考试系统) 3.9.0 Cross-Site Request Forgery (CSRF) |
Desidero esprimere la mia gratitudine ai fornitori e ai team di sicurezza che hanno collaborato durante il processo di divulgazione responsabile. La vostra dedizione al miglioramento della sicurezza delle applicazioni è inestimabile.
| 3.9 |
| Feb 6, 2025 |
| Leggi il write-up completo |
| CVE-2025-1083 | Mindskip xzs-mysql (武汉思维跳跃科技有限公司 - 学之思开源考试系统) 3.9.0 CORS Misconfiguration | 2.8 | Feb 6, 2025 | Leggi il write-up completo |
| CVE-2025-1082 | Mindskip xzs-mysql (武汉思维跳跃科技有限公司 - 学之思开源考试系统) 3.9.0 Stored Cross Site Scripting (XSS) | 3.5 | Feb 6, 2025 | Leggi il write-up completo |
| CVE-2024-13199 | Mtons mblog 3.5.0 Reflected Cross Site Scripting (XSS) nella funzione di ricerca | 3.2 | Jan 8, 2025 | Leggi il write-up completo |
| CVE-2024-13198 | Mtons mblog 3.5.0 Observable Response Discrepancy nel login | 3.4 | Jan 8, 2025 | Leggi il write-up completo |
| CVE-2024-13032 | Antabot White-Jotter 0.2.2 Server-Side Request Forgery (SSRF) | 5.1 | Dec 29, 2024 | Leggi il write-up completo |
| CVE-2024-13031 | Antabot White-Jotter 0.2.2 Reflected Cross-Site Scripting (XSS) | 5.1 | Dec 29, 2024 | Leggi il write-up completo |
| CVE-2024-13029 | Antabot White-Jotter 0.2.2 Server-Side Request Forgery (SSRF) | 5.3 | Dec 29, 2024 | Leggi il write-up completo |
| CVE-2024-13028 | Antabot White-Jotter 0.2.2 Observable Response Discrepancy | 6.3 | Dec 29, 2024 | Leggi il write-up completo |
| CVE-2024-12995 | Ruifang-Tech (上海锐昉科技有限公司) Rebuild 3.8.6 Stored Cross Site Scripting (XSS) | 5.3 | Dec 27, 2024 | Leggi il write-up completo |
| CVE-2024-12990 | Ruifang-Tech (上海锐昉科技有限公司) Rebuild 3.8.6 Open Redirect | 5.3 | Dec 27, 2024 | Leggi il write-up completo |
| CVE-2024-55452 | Dromara UJCMS <= 9.6.3 Reindirizzamento arbitrario di URL tramite upload di Block Item | 5.4 | Dec 17, 2024 | Leggi il write-up completo |
| CVE-2024-55451 | Dromara UJCMS <= 9.6.3 Stored Cross Site Scripting (XSS) autenticato basato su SVG | 4.8 | Dec 17, 2024 | Leggi il write-up completo |
| CVE-2024-12665 | Ruifang-Tech (上海锐昉科技有限公司) Rebuild 3.8.5 Stored Cross Site Scripting (XSS) nell'upload degli allegati dei commenti delle attività | 3.5 | Dec 16, 2024 | Leggi il write-up completo |
| CVE-2024-12664 | Ruifang-Tech (上海锐昉科技有限公司) Rebuild 3.8.5 Stored Cross Site Scripting (XSS) nei commenti delle attività di progetto | 3.5 | Dec 16, 2024 | Leggi il write-up completo |
| CVE-2024-12663 | FunnyZPC mee-admin 1.6 Observable Response Discrepancy nel nome utente di login | 3.7 | Dec 16, 2024 | Leggi il write-up completo |
| CVE-2024-12483 | Dromara UJCMS <= 9.6.3 Insecure Direct Object Reference (IDOR) sull'ID utente /users/id | 3.7 | Dec 11, 2024 | Leggi il write-up completo |