CVE PUSH ⚠️
431 subscribers
2 videos
752 links
Github CVE push
Github CVE 推送
Cve/Rce/Exploit/Redteam/漏洞利用/红队

Channel push 24/7 (real time)
频道全天候推送(实时)

This channel will be used to push CVEs.
If you need CVE and red team resource push please join @CVEhub
该频道将用于推送 CVE。需要CVE和红队资源推送请加入 @CVEhub
Download Telegram
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-3368
Github: https://github.com/Wh04m1001/CVE-2022-3368
Describe:
A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avira Security version 1.1.72.30556.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-42899
Github: https://github.com/iamsanjay/CVE-2022-42899
Describe:
Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read and stack overflow issues when opening crafted SKP files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-40674
Github: https://github.com/nidhi7598/-expat_2.1.0_CVE-2022-40674
Describe:
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-21970
Github: https://github.com/Malwareman007/CVE-2022-21970
Describe:
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21954.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-29303
Github: https://github.com/trhacknon/CVE-2022-29303-Exploit
Describe:
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
👍1
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/38e48ba4205196e042db8f832a7789b76ee61c5e
commitUpdate log:
Merge pull request #225 from evilAdan0s/main

去除弱特征:过时UA头
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-2402
Github: https://github.com/SecurityAndStuff/CVE-2022-2402
Describe:
The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-1000
Github: https://github.com/yonggui-li/CVE-2022-1000_poc
Describe:
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/38e48ba4205196e042db8f832a7789b76ee61c5e
commitUpdate log:
Merge pull request #225 from evilAdan0s/main

去除弱特征:过时UA头
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-36663
Github: https://github.com/Qeisi/CVE-2022-36663-PoC
Describe:
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
** mimikatz ** 🔧Tool update
Tools name:mimikatz
Tools url:https://github.com/gentilkiwi/mimikatz/commit/c78b1cf37c517ae9d0e872447bb103da9fa6034a
commitUpdate log:
Revert to Visual Studio 2013 (due to an error in Microsoft headers, can't build in Win32)