idkwastaken

3 exploits Active since Aug 2023
CVE-2024-38063 NOMISEC CRITICAL WORKING POC
Windows TCP/IP < - RCE
Windows TCP/IP Remote Code Execution Vulnerability
CVSS 9.8
CVE-2023-38831 NOMISEC HIGH WORKING POC
WinRAR CVE-2023-38831 Exploit
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.
CVSS 7.8
CVE-2023-32560 NOMISEC CRITICAL WORKING POC
Ivanti Avalanche < 6.4.1 - Out-of-Bounds Write
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.
CVSS 9.8