CVE HUB ๐Ÿ‘พ
789 subscribers
19.3K links
Github Red team resource push
Github ็บข้˜Ÿ่ต„ๆบๆŽจ้€
Cve/Rce/Exploit/Redteam/ๆผๆดžๅˆฉ็”จ/็บข้˜Ÿ

Channel push 24/7 (real time)
้ข‘้“ๅ…จๅคฉๅ€™ๆŽจ้€(ๅฎžๆ—ถ)
Download Telegram
๐Ÿ‘พCVE SERVICE ๐Ÿท#CVE
Mumber: CVE-2022-35899
Github: https://github.com/AngeloPioAmirante/CVE-2022-35899
Describe:
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.
๐Ÿ‘พKEYWORD SERVICE ๐Ÿท#exploit
Name: Void-WareC
Github: https://github.com/Zywuss/Void-WareC
๐Ÿ‘พCVE SERVICE ๐Ÿท#CVE
Mumber: CVE-2022-22965
Github: https://github.com/sunnyvale-it/CVE-2022-22965-PoC
Describe:
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.