CVE Notify
18.5K subscribers
4 photos
163K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2024-30128
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.

🎖@cveNotify
🚨 CVE-2019-5544
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

🎖@cveNotify
🚨 CVE-2021-1647
Microsoft Defender Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-26411
Internet Explorer Memory Corruption Vulnerability

🎖@cveNotify
🚨 CVE-2021-27059
Microsoft Office Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-27085
Internet Explorer Remote Code Execution Vulnerability

🎖@cveNotify
🚨 CVE-2021-28310
Win32k Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-31199
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-31201
Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-31955
Windows Kernel Information Disclosure Vulnerability

🎖@cveNotify
🚨 CVE-2021-31956
Windows NTFS Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2021-33739
Microsoft DWM Core Library Elevation of Privilege Vulnerability

🎖@cveNotify
🚨 CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

🎖@cveNotify
🔥1