ZeroHour

Vulnerabilities

523 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-46690
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue.

unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At time of publication, there are no publicly available patches.

NVD description · AI analysis pending
5.8<1% PoC
  • spearman unbounded-spsc
CVE-2025-27851
+3 in the same advisory: …27850 …27853 …27852
The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack.

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including administrative settings. This allows a network attacker to take full control of a WDU. To initiate an exploit of this vulnerability, the victim must (1) be utilizing a web browser on a multihomed host that has local interfaces on the Garmin Marine Network as well as another network, and (2) access a malicious third party website created by the attacker.

NVD description · AI analysis pending
9.3
group max
<1%
  • garmin empirbus wireless display unit firmware
CVE-2026-41589
Wish is an SSH server with defaults and a collection of middlewares.

Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path traversal attacks. A malicious SCP client can read arbitrary files from the server, write arbitrary files to the server, and create directories outside the configured root directory by sending crafted filenames containing ../ sequences over the SCP protocol. This issue has been patched in version 2.0.1.

NVD description · AI analysis pending
9.6<1% PoC
  • charm wish
CVE-2019-25694
Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through th

Kados R10 GreenBee contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user2reset parameter. Attackers can send crafted requests with malicious SQL payloads to extract sensitive database information or modify data.

NVD description · AI analysis pending
8.8<1% PoC
  • marmotech kados
CVE-2026-34877
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.

An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures to induce memory corruption, leading to arbitrary code execution. This is caused by Incorrect Use of Privileged APIs.

NVD description · AI analysis pending
9.8<1%
  • arm mbed tls
CVE-2026-34872
+3 in the same advisory: …25835 …34871 …66442
An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0.

An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other party can force the shared secret into a small set of values (lack of contributory behavior). This is a problem for protocols that depend on contributory behavior (which is not the case for TLS). The attack can be carried by the peer, or depending on the protocol by an active network attacker (person in the middle).

NVD description · AI analysis pending
9.1
group max
<1%
  • arm mbed tls
  • arm tf-psa-crypto
CVE-2026-5019
A security vulnerability has been detected in code-projects Simple Food Order System 1.0.

A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parameter Handler. The manipulation of the argument Status leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

NVD description · AI analysis pending
5.5<1% PoC
  • carmelo simple food order system
CVE-2026-5018
+1 in the same advisory: …5017
A weakness has been identified in code-projects Simple Food Order System 1.0.

A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

NVD description · AI analysis pending
5.5<1% PoC
  • carmelo simple food order system
CVE-2026-33353
Soft Serve is a self-hostable Git server for the command line.

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository, including another user's private repo, into a new repository they control. This issue has been patched in version 0.11.6.

NVD description · AI analysis pending
7.1<1% PoC
  • charm soft serve
CVE-2026-4532
+1 in the same advisory: …4533
A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0.

A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. It is recommended to change the configuration settings.

NVD description · AI analysis pending
5.5
group max
<1% PoC
  • carmelo simple food order system
CVE-2026-4319
A vulnerability was identified in code-projects Simple Food Order System 1.0.

A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/add-item.php. Such manipulation of the argument price leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.

NVD description · AI analysis pending
5.5<1% PoC
  • carmelo simple food order system
CVE-2026-3723
A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0.

A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

NVD description · AI analysis pending
5.5
group max
<1% PoC
  • carmelo simple flight ticket booking system
CVE-2026-3744
+1 in the same advisory: …3745
A vulnerability has been found in code-projects Student Web Portal 1.0.

A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.5
group max
<1% PoC
  • carmelo student web portal
CVE-2026-30832
Soft Serve is a self-hostable Git server for the command line.

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by running repo import with a crafted --lfs-endpoint URL. The initial batch request is blind (the response from a metadata endpoint won't parse as valid LFS JSON), but an attacker hosting a fake LFS server can chain this into full read access to internal services by returning download URLs that point at internal targets. This issue has been patched in version 0.11.4.

NVD description · AI analysis pending
9.1<1% PoC
  • charm soft serve
CVE-2026-26710
+3 in the same advisory: …26713 …26711 …26712
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.

code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.

NVD description · AI analysis pending
9.8<1% PoC
  • carmelo simple food order system
CVE-2026-26709
code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

NVD description · AI analysis pending
9.8<1% PoC
  • carmelo simple gym management system
CVE-2026-26694
+4 in the same advisory: …26695 …26696 …26698 …26697
code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.

code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • carmelo simple student alumni system
CVE-2026-0995
An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesse

An issue has been identified in Arm C1-Pro before r1p2-50eac0, where, under certain conditions, a TLBI+DSB might fail to ensure the completion of memory accesses related to SME.

NVD description · AI analysis pending
3.6<1%
  • arm c1-pro firmware