Using CVEmap you can get a list of CVEs with public proofs of concept, that have been marked as exploitable by CISA, are remotely exploitable AND don't have a Nuclei template (yet)!
Flags:
-k / -kev: Marked as exploitable vulnerabilities by CISA
-t=false / -template=false: Has no public Nuclei templates
-poc: Has public published POC
-re / -remote: is remotely exploitable
Credit : @pdiscoveryio
🔸JUST IN: #Bitcoin is about to close the biggest $$$ gain on a monthly candle in its history.
This is more bullish than any month in the last bull market.
#Lazarus exploited a flaw in the Windows AppLocker driver (appid.sys) as a zero-day to gain kernel-level access and turn off security tools.CVE-2024-21338
Beyond BYOVD with an Admin-to-Kernel Zero-Day
https://t.co/irFNz3Dntt
@ryanteck @hackerfantastic Well, way larger dataset, email:pass combo lookup possibility, risk assessment on password lookups, no limit on the API requests, SLA 99.5% uptime... Great for enterprise, but the HIBP API is awesome too for sure!
if you made #30Under30, don’t give your personal info to Forbes. I found a bug that lets any 30under30 member (like me) see other members’ DoBs, addresses, phones, etc. Forbes ignored my emails asking them to fix.