ZeroHour

Vulnerabilities

16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-13256
Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact:

Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.

NVD description · AI analysis pending
7.5<1%
  • email contact project email contact
CVE-2023-29566
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process

huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.

NVD description · AI analysis pending
9.82% PoC
  • dawnsparks-node-tesseract project dawnsparks-node-tesseract
  • dawnsparks-node-tesseract project huedawn-tesseract
CVE-2023-22726
act is a project which allows for local running of github actions.

act is a project which allows for local running of github actions. The artifact server that stores artifacts from Github Action runs does not sanitize path inputs. This allows an attacker to download and overwrite arbitrary files on the host from a Github Action. This issue may lead to privilege escalation. The /upload endpoint is vulnerable to path traversal as filepath is user controlled, and ultimately flows into os.Mkdir and os.Open. The /artifact endpoint is vulnerable to path traversal as the path is variable is user controlled, and the specified file is ultimately returned by the server. This has been addressed in version 0.2.40. Users are advised to upgrade. Users unable to upgrade may, during implementation of Open and OpenAtEnd for FS, ensure to use ValidPath() to check against path traversal or clean the user-provided paths manually.

NVD description · AI analysis pending
8.81% PoC ×2
  • act project act
CVE-2020-28453
This affects all versions of package npos-tesseract.

This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.

NVD description · AI analysis pending
9.81% PoC
  • npos-tesseract project npos-tesseract
CVE-2020-28446
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.

The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.

NVD description · AI analysis pending
9.83% PoC
  • ntesseract project ntesseract
CVE-2022-1914
The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in adm

The Clean-Contact WordPress plugin through 1.6 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS due to the lack of sanitisation and escaping as well

NVD description · AI analysis pending
4.3<1% PoC
  • clean-contact project clean-contact
CVE-2021-24403
The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before insertin

The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors

NVD description · AI analysis pending
7.22% PoC ×2
  • wpagecontact project wpagecontact
CVE-2018-18584
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading

In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.

NVD description · AI analysis pending
6.53%
  • cabextract project cabextract
  • cabextract project libmspack
  • cabextract project debian linux
  • +1 more
CVE-2018-14682
+3 in the same advisory: …14681 …14680 …14679
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha.

An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.

NVD description · AI analysis pending
8.8
group max
4%
  • cabextract libmspack
  • cabextract cabextract
  • cabextract ubuntu linux
  • +1 more
CVE-2018-13771
The mintToken function of a smart contract implementation for ExacoreContract, an Ethereum token, has an integer overflow that allows the owner of the contract

The mintToken function of a smart contract implementation for ExacoreContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

NVD description · AI analysis pending
7.51% PoC
  • exacorecontract project exacorecontract
CVE-2018-13469
The mintToken function of a smart contract implementation for IcoContract, an Ethereum token, has an integer overflow that allows the owner of the contract to s

The mintToken function of a smart contract implementation for IcoContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

NVD description · AI analysis pending
7.51% PoC
  • icocontract project icocontract
CVE-2018-5983
SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.

SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.

NVD description · AI analysis pending
9.83% PoC
  • jquickcontact project jquickcontact
CVE-2016-10320
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function.

textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.

NVD description · AI analysis pending
7.82% PoC
  • textract project textract