ZeroHour

Vulnerabilities

36 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-35002
Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Pyth

Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_type value in a FunctionCall to achieve remote code execution.

NVD description · AI analysis pending
9.3<1%
  • agno agno
CVE-2022-43163
+1 in the same advisory: …43162
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php.

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php.

NVD description · AI analysis pending
7.2<1% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-43135
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.

NVD description · AI analysis pending
9.8<1% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-43058
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.

NVD description · AI analysis pending
9.8<1%
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-43052
+1 in the same advisory: …43051
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete.

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/classes/Users.php?f=delete.

NVD description · AI analysis pending
7.2<1% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-43063
+1 in the same advisory: …43062
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Users.php?f=delete_client.

NVD description · AI analysis pending
7.2<1% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-43226
+3 in the same advisory: …43066 …43068 …43227
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appo

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-43127
+3 in the same advisory: …43126 …43125 …43124
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.

Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /appointments/update_status.php.

NVD description · AI analysis pending
7.2<1% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-42064
Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

NVD description · AI analysis pending
9.81% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-41534
+1 in the same advisory: …41533
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php.

Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

NVD description · AI analysis pending
7.21% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-41512
+3 in the same advisory: …42073 …41513 …42074
An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to execute arb

An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

NVD description · AI analysis pending
7.21% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-37152
+2 in the same advisory: …37151 …37150
An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save

An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"

NVD description · AI analysis pending
9.8
group max
1% PoC
  • online diagnostic lab management system project online diagnostic lab management system
CVE-2022-33098
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.

Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.

NVD description · AI analysis pending
6.153%
  • magnolia-cms magnolia cms
CVE-2021-46362
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute

A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.

NVD description · AI analysis pending
9.8
group max
5% PoC
  • magnolia-cms magnolia cms
CVE-2021-25894
+1 in the same advisory: …25893
Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId paramete

Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.

NVD description · AI analysis pending
6.1
group max
1% PoC
  • magnolia-cms magnolia cms