ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-13609
+1 in the same advisory: …13555
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to

The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 via the class-ocm-backup.php. This makes it possible for unauthenticated attackers to extract sensitive data including usernames and their respective password hashes during a short window of time in which the backup is in process.

NVD description · AI analysis pending
5.9
group max
2%
  • 1clickmigration 1 click migration
CVE-2020-23911
+1 in the same advisory: …23910
An issue was discovered in asn1c through v0.9.28.

An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logger() located in asn1fix.c. It allows an attacker to cause Denial of Service.

NVD description · AI analysis pending
5.5<1% PoC
  • asn1c project asn1c
CVE-2020-18460
Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content.

Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content.

NVD description · AI analysis pending
8.8<1% PoC
  • 711cms 711cms
CVE-2021-32616
1CDN is open-source file sharing software.

1CDN is open-source file sharing software. In 1CDN before commit f88a2730fa50fc2c2aeab09011f6f142fd90ec25, there is a basic cross-site scripting vulnerability that allows an attacker to inject / and execute JavaScript code on the client side.

NVD description · AI analysis pending
6.1<1%
  • 1cdn project 1cdn
CVE-2021-3131
The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter.

The Web server in 1C:Enterprise 8 before 8.3.17.1851 sends base64 encoded credentials in the creds URL parameter.

NVD description · AI analysis pending
7.5<1%
  • 1c 1c\
CVE-2020-15958
An issue was discovered in 1CRM System through 8.6.7.

An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.

NVD description · AI analysis pending
8.63% PoC ×2
  • 1crm 1crm
CVE-2019-14221
1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.

1CRM On-Premise Software 8.5.7 allows XSS via a payload that is mishandled during a Run Report operation.

NVD description · AI analysis pending
5.42% PoC ×2
  • 1crm 1crm on-premise
CVE-2017-12966
The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation f

The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation fault) via a crafted .asn1 file.

NVD description · AI analysis pending
6.51% PoC
  • asn1c project asn1c