ZeroHour

Vulnerabilities

29 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-26010
OpenMetadata is a unified metadata platform.

OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies). This vulnerability is fixed in 1.11.8.

NVD description · AI analysis pending
7.6<1% PoC
  • open-metadata openmetadata
CVE-2026-22798
hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata.

hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options under the -O argument. These have been logged in raw form. If users provide sensitive data such as API tokens (e.g., via hermes deposit -O invenio_rdm.auth_token SECRET), these are written to the log file in plain text, making them available to whoever can access the log file. This vulnerability is fixed in 0.9.1.

NVD description · AI analysis pending
5.0<1%
  • software-metadata.pub hermes
CVE-2026-22244
OpenMetadata is a unified metadata platform.

OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch.

NVD description · AI analysis pending
8.51% PoC
  • open-metadata openmetadata
CVE-2025-61075
+1 in the same advisory: …61074
Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry ou

Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry out administrative functions and manipulate data of other users via unauthorized API calls.

NVD description · AI analysis pending
8.1
group max
<1% PoC
  • adata mitarbeiter portal
CVE-2025-50465
+3 in the same advisory: …50466 …50468 …50467
OpenMetadata <=1.4.4 is vulnerable to SQL Injection.

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL query.

NVD description · AI analysis pending
8.8
group max
<1%
  • open-metadata openmetadata
CVE-2024-55238
OpenMetadata <=1.4.1 is vulnerable to SQL Injection.

OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.

NVD description · AI analysis pending
8.8<1% PoC
  • open-metadata openmetadata
CVE-2024-28255
+4 in the same advisory: …28254 …28253 …28848 …28847
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team co

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication by requiring and verifying JWT tokens. When a new request comes in, the request's path is checked against this list. When the request's path contains any of the excluded endpoints the filter returns without validating the JWT. Unfortunately, an attacker may use Path Parameters to make any path contain any arbitrary strings. For example, a request to `GET /api/v1;v1%2fusers%2flogin/events/subscriptions/validation/condition/111` will match the excluded endpoint condition and therefore will be processed with no JWT validation allowing an attacker to bypass the authentication mechanism and reach any arbitrary endpoint, including the ones listed above that lead to arbitrary SpEL expression injection. This bypass will not work when the endpoint uses the `SecurityContext.getUserPrincipal()` since it will return `null` and will throw an NPE. This issue may lead to authentication bypass and has been addressed in version 1.2.4. Users are advised to upgrade. There are no known workarounds for this vulnerability. This issue is also tracked as `GHSL-2023-237`.

NVD description · AI analysis pending
9.8
group max
73% PoC ×2
  • open-metadata openmetadata
CVE-2022-31509
The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

NVD description · AI analysis pending
9.31% PoC
  • iedadata usap-dc web submission and dataset search
CVE-2022-0836
The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading

The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading to SQL Injections exploitable by unauthenticated users

NVD description · AI analysis pending
9.82% PoC
  • semadatacoop sema api
CVE-2022-24613
+1 in the same advisory: …24614
metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash.

metadata-extractor up to 2.16.0 can throw various uncaught exceptions while parsing a specially crafted JPEG file, which could result in an application crash. This could be used to mount a denial of service attack against services that use metadata-extractor library.

NVD description · AI analysis pending
5.5<1% PoC
  • metadata-extractor project metadata-extractor
CVE-2021-24855
The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which cou

The Display Post Metadata WordPress plugin before 1.5.0 adds a shortcode to print out custom fields, however their content is not sanitised or escaped which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

NVD description · AI analysis pending
5.4<1% PoC
  • display post metadata project display post metadata
CVE-2019-15638
COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.

COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.

NVD description · AI analysis pending
7.8<1%
  • copadata zenon
CVE-2019-14262
MetadataExtractor 2.1.0 allows stack consumption.

MetadataExtractor 2.1.0 allows stack consumption.

NVD description · AI analysis pending
7.52%
  • metadataextractor project metadataextractor
CVE-2019-6499
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\serv

Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise the affected system.

NVD description · AI analysis pending
8.12%
  • teradata viewpoint
CVE-2017-9149
Metadata Anonymisation Toolkit (MAT) 0.6 and 0.6.1 silently fails to perform "Clean metadata" actions upon invocation from the Nautilus contextual menu, which a

Metadata Anonymisation Toolkit (MAT) 0.6 and 0.6.1 silently fails to perform "Clean metadata" actions upon invocation from the Nautilus contextual menu, which allows context-dependent attackers to obtain sensitive information by reading a file for which cleaning had been attempted.

NVD description · AI analysis pending
7.52%
  • metadata anonymisation toolkit project metadata anonymisation toolkit
CVE-2017-6518
Cross-site scripting (XSS) vulnerability in /sanadata/seo/index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via t

Cross-site scripting (XSS) vulnerability in /sanadata/seo/index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the txtFrom parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • sanadata sanacms
CVE-2017-5882
Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the search para

Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • sanadata sanacms
CVE-2016-7490
The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely.

The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges.

NVD description · AI analysis pending
7.8<1% PoC
  • teradata studio express
CVE-2016-7489
+1 in the same advisory: …7488
Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp in an insecure manner, this may lead to

Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp in an insecure manner, this may lead to elevated code execution.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • teradata virtual machine