Category: CVSS3 - HIGH
CVE-2022-41035

Microsoft Edge (Chromium-based) Spoofing Vulnerability.Read More ...

Continue Reading
CVE-2022-41081

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22035, CVE-2022-24504, CVE-2022-30198, CVE-2022-33634, CVE-2022-38000, CVE-2022-38047 ...

Continue Reading
CVE-2022-41036

Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41037, CVE-2022-41038.Read More ...

Continue Reading
CVE-2022-41037

Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41036, CVE-2022-41038.Read More ...

Continue Reading
CVE-2022-41038

Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41036, CVE-2022-41037.Read More ...

Continue Reading
CVE-2022-41042

Visual Studio Code Information Disclosure Vulnerability.Read More ...

Continue Reading
CVE-2022-41083

Visual Studio Code Elevation of Privilege Vulnerability.Read More ...

Continue Reading
Weak Password Requirements

etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess o ...

Continue Reading
Hyperledger: Remote denial of service in HyperLedger Fabric

How to reproduce 1.Bring up the test network.(https://hyperledger-fabric.readthedocs.io/en/latest/test_network.html#bring-up-the-test-network) 2.Run the PoC. ```bash go run poc.go -server=192.168.0.20 ...

Continue Reading
Reddit: Unrestricted File Upload on reddit.secure.force.com

## Summary: Reddit.secure.force.com is Reddit SalesForce instance. Attacker is able to send attachments of disallowed filetypes to this server. The attacker is able to send malicious documents such as ...

Continue Reading
Load more