ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-37243
The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots.

The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Package.Availability.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.

NVD description · AI analysis pending
7.8<1%
  • atera agent package availability
CVE-2023-46865
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an imag

/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

NVD description · AI analysis pending
7.220% PoC
  • craterapp crater
CVE-2023-26078
+1 in the same advisory: …26077
Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs.

Privilege escalation vulnerability was discovered in Atera Agent 1.8.4.4 and prior on Windows due to mishandling of privileged APIs.

NVD description · AI analysis pending
7.8<1% PoC
  • atera atera
CVE-2022-1032
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

NVD description · AI analysis pending
7.22% PoC
  • craterapp crater
CVE-2022-1033
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

NVD description · AI analysis pending
7.8<1% PoC
  • craterapp crater
CVE-2022-0514
+1 in the same advisory: …0515
Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

Business Logic Errors in GitHub repository crater-invoice/crater prior to 6.0.5.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • craterapp crater
CVE-2022-0372
Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.

Cross-site Scripting (XSS) - Stored in Packagist bytefury/crater prior to 6.0.2.

NVD description · AI analysis pending
5.4<1% PoC
  • craterapp crater
CVE-2022-0203
Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

NVD description · AI analysis pending
5.31% PoC
  • craterapp crater
CVE-2022-0242
Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.

NVD description · AI analysis pending
7.21% PoC
  • craterapp crater
CVE-2021-4080
crater is vulnerable to Unrestricted Upload of File with Dangerous Type

crater is vulnerable to Unrestricted Upload of File with Dangerous Type

NVD description · AI analysis pending
8.81% PoC
  • craterapp crater
CVE-2018-14925
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.

Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.

NVD description · AI analysis pending
9.8
group max
2%
  • matera banco