ZeroHour

Vulnerabilities

201 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-41432
in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

NVD description · AI analysis pending
7.8
group max
<1%
  • openatom openharmony
CVE-2025-69822
An issue in Atomberg Atomberg Erica Smart Fan Firmware Version:

An issue in Atomberg Atomberg Erica Smart Fan Firmware Version: V1.0.36 allows an attacker to obtain sensitive information and escalate privileges via a crafted deauth frame

NVD description · AI analysis pending
7.4<1% PoC
  • atomberg erica smart fan firmware
CVE-2025-27128
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in tcb through use after free.

NVD description · AI analysis pending
7.8
group max
<1%
  • openatom openharmony
CVE-2025-27131
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

NVD description · AI analysis pending
5.5
group max
<1%
  • openatom openharmony
CVE-2025-4415
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO allows Cross-Site Scripting (XSS).This is

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO allows Cross-Site Scripting (XSS).This issue affects Piwik PRO: from 0.0.0 before 1.3.2.

NVD description · AI analysis pending
4.8<1%
  • matomo piwik pro
CVE-2025-27132
in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

in OpenHarmony v5.0.3 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

NVD description · AI analysis pending
7.8
group max
<1%
  • openatom openharmony
CVE-2025-22851
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through integer overflow.

NVD description · AI analysis pending
8.8
group max
<1%
  • openatom openharmony
CVE-2025-31680
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics:

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Matomo Analytics allows Cross Site Request Forgery.This issue affects Matomo Analytics: from 0.0.0 before 1.24.0.

NVD description · AI analysis pending
6.8<1%
  • matomo analytics project matomo analytics
CVE-2025-24309
in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

in OpenHarmony v5.0.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write. This vulnerability can be exploited only in restricted scenarios.

NVD description · AI analysis pending
7.8
group max
<1%
  • openatom openharmony