ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-25539
+1 in the same advisory: …25538
202CMS v10 beta contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through

202CMS v10 beta contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the log_user parameter. Attackers can send POST requests to index.php with crafted SQL payloads using time-based blind injection techniques to extract sensitive database information.

NVD description · AI analysis pending
8.8<1% PoC
  • konradpl99 202cms
CVE-2023-40519
A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00

A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the disconnectMessage parameter.

NVD description · AI analysis pending
6.1<1%
  • broadpeak centralized accounts management auth agent
CVE-2021-34078
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.

lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.

NVD description · AI analysis pending
8.83% PoC
  • adp lifion-verifiy-dependencies
CVE-2020-11509
+1 in the same advisory: …11508
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript vi

An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).

NVD description · AI analysis pending
6.1
group max
2% PoC
  • wpleadplus wp lead plus x
CVE-2019-15151
AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.

NVD description · AI analysis pending
9.82% PoC
  • adplug project adplug
  • adplug project fedora
CVE-2019-14734
+2 in the same advisory: …14733 …14732
AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.

NVD description · AI analysis pending
8.82% PoC
  • adplug project adplug
  • adplug project fedora
CVE-2019-14692
+2 in the same advisory: …14690 …14691
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.

NVD description · AI analysis pending
8.82% PoC
  • adplug project adplug
  • adplug project fedora
CVE-2018-17825
An issue was discovered in AdPlug 2.3.1.

An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.

NVD description · AI analysis pending
9.82% PoC
  • adplug project adplug
  • adplug project fedora