CVE PUSH ⚠️
430 subscribers
2 videos
752 links
Github CVE push
Github CVE 推送
Cve/Rce/Exploit/Redteam/漏洞利用/红队

Channel push 24/7 (real time)
频道全天候推送(实时)

This channel will be used to push CVEs.
If you need CVE and red team resource push please join @CVEhub
该频道将用于推送 CVE。需要CVE和红队资源推送请加入 @CVEhub
Download Telegram
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-29303
Github: https://github.com/trhacknon/CVE-2022-29303-Exploit
Describe:
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
👍1
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/38e48ba4205196e042db8f832a7789b76ee61c5e
commitUpdate log:
Merge pull request #225 from evilAdan0s/main

去除弱特征:过时UA头
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-2402
Github: https://github.com/SecurityAndStuff/CVE-2022-2402
Describe:
The vulnerability in the driver dlpfde.sys enables a user logged into the system to perform system calls leading to kernel stack overflow, resulting in a system crash, for instance, a BSOD.
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-1000
Github: https://github.com/yonggui-li/CVE-2022-1000_poc
Describe:
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
** fscan ** 🔧Tool update
Tools name:fscan
Tools url:https://github.com/shadow1ng/fscan/commit/38e48ba4205196e042db8f832a7789b76ee61c5e
commitUpdate log:
Merge pull request #225 from evilAdan0s/main

去除弱特征:过时UA头
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-36663
Github: https://github.com/Qeisi/CVE-2022-36663-PoC
Describe:
Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.
** mimikatz ** 🔧Tool update
Tools name:mimikatz
Tools url:https://github.com/gentilkiwi/mimikatz/commit/c78b1cf37c517ae9d0e872447bb103da9fa6034a
commitUpdate log:
Revert to Visual Studio 2013 (due to an error in Microsoft headers, can't build in Win32)
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-1679
Github: https://github.com/EkamSinghWalia/-Detection-and-Mitigation-for-CVE-2022-1679
Describe:
A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.
** mimikatz ** 🔧Tool update
Tools name:mimikatz
Tools url:https://github.com/gentilkiwi/mimikatz/commit/c78b1cf37c517ae9d0e872447bb103da9fa6034a
commitUpdate log:
Revert to Visual Studio 2013 (due to an error in Microsoft headers, can't build in Win32)
👾CVE SERVICE 🏷#CVE
Mumber: CVE-2022-32938
Github: https://github.com/iCMDgithub/CVE-2022-32938
Describe:
**