ZeroHour

Vulnerabilities

150 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-25562
jetAudio 8.1.7 contains a buffer overflow vulnerability in the video converter component that allows local attackers to crash the application by supplying an ov

jetAudio 8.1.7 contains a buffer overflow vulnerability in the video converter component that allows local attackers to crash the application by supplying an oversized string in the File Naming field. Attackers can paste a malicious buffer of 512 bytes into the File Naming parameter and trigger the crash by clicking the Preview button, causing a denial of service.

NVD description · AI analysis pending
6.8<1% PoC
  • jetaudio jetaudio
CVE-2019-25561
Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the

Lyric Maker 2.0.1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Title field. Attackers can paste a 5000-byte buffer into the Title input field and save the file to trigger a denial of service condition.

NVD description · AI analysis pending
6.9<1% PoC
  • jetaudio lyric maker
CVE-2026-27974
Audiobookshelf is a self-hosted audiobook and podcast server.

Audiobookshelf is a self-hosted audiobook and podcast server. A cross-site scripting (XSS) vulnerability exists in versions prior to 0.12.0-beta of the Audiobookshelf mobile application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges (or control over a malicious podcast RSS feed) can execute code in victim users' WebViews, potentially leading to session hijacking, data exfiltration, and unauthorized access to native device APIs. audiobookshelf-app version 0.12.0-beta fixes the issue.

NVD description · AI analysis pending
4.8<1%
  • audiobookshelf audiobookshelf mobile app
CVE-2026-27963
+1 in the same advisory: …27973
Audiobookshelf is a self-hosted audiobook and podcast server.

Audiobookshelf is a self-hosted audiobook and podcast server. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 2.32.0 of the Audiobookshelf web application that allows arbitrary JavaScript execution through malicious library metadata. Attackers with library modification privileges can execute code in victim users' browsers, potentially leading to session hijacking and data exfiltration. Version 2.32.0 contains a patch for the issue.

NVD description · AI analysis pending
4.8<1% PoC
  • audiobookshelf audiobookshelf
CVE-2025-65843
+1 in the same advisory: …65841
Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature.

Aquarius Desktop 3.0.069 for macOS contains an insecure file handling vulnerability in its support data archive generation feature. The application follows symbolic links placed inside the ~/Library/Logs/Aquarius directory and treats them as regular files. When building the support ZIP, Aquarius recursively enumerates logs using a JUCE directory iterator configured to follow symlinks, and later writes file data without validating whether the target is a symbolic link. A local attacker can exploit this behavior by planting symlinks to arbitrary filesystem locations, resulting in unauthorized disclosure or modification of arbitrary files. When chained with the associated HelperTool privilege escalation issue, root-owned files may also be exposed.

NVD description · AI analysis pending
7.7
group max
<1% PoC
  • acustica-audio aquarius
CVE-2025-65842
The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation.

The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege escalation. The service accepts XPC connections from any local process without validating the client's identity, and its authorization logic incorrectly calls AuthorizationCopyRights with a NULL reference, causing all authorization checks to succeed. The executeCommand:authorization:withReply: method then interpolates attacker-controlled input into NSTask and executes it with root privileges. A local attacker can exploit these weaknesses to run arbitrary commands as root, create persistent backdoors, or obtain a fully interactive root shell.

NVD description · AI analysis pending
5.1<1% PoC
  • acustica-audio aquarius helpertool
CVE-2025-34329
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web interface. The script derives a backup folder path from application configuration, creates the directory if it does not exist, and then moves an uploaded file to that location using the attacker-controlled filename, without any authentication, authorization, or file-type validation. On default Windows deployments where the backup directory resolves to the system drive, a remote attacker can upload web server or interpreter configuration files that cause a log file or other server-controlled resource to be treated as executable code. This allows subsequent HTTP requests to trigger arbitrary command execution under the web server account, which runs as NT AUTHORITY\\SYSTEM.

NVD description · AI analysis pending
9.3
group max
1% PoC ×2
  • audiocodes fax server
  • audiocodes interactive voice response
CVE-2025-50950
Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.

Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.

NVD description · AI analysis pending
7.5<1% PoC
  • audiofile audiofile
CVE-2025-45583
+4 in the same advisory: …45584 …45586 …45587 …45585
Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combinat

Incorrect access control in the FTP protocol of Audi UTR 2.0 Universal Traffic Recorder 2.0 allows attackers to authenticate into the service using any combination of username and password.

NVD description · AI analysis pending
9.1
group max
<1% PoC
  • audi universal traffic recorder firmware
CVE-2025-57800
Audiobookshelf is an open-source self-hosted audiobook server.

Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshelf to store an arbitrary callback in a cookie, which is later used to redirect the user after authentication. The server then issues a 302 redirect to the attacker-controlled URL, appending sensitive OIDC tokens as query parameters. This allows an attacker to obtain the victim's tokens and perform full account takeover, including creating persistent admin users if the victim is an administrator. Tokens are further leaked via browser history, Referer headers, and server logs. This vulnerability impacts all Audiobookshelf deployments using OIDC; no IdP misconfiguration is required. The issue is fixed in version 2.28.0. No known workarounds exist.

NVD description · AI analysis pending
8.8<1% PoC
  • audiobookshelf audiobookshelf
CVE-2025-48448
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail:

Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.

NVD description · AI analysis pending
6.5<1%
  • admin audit trail project admin audit trail
CVE-2025-32106
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthori

In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.

NVD description · AI analysis pending
9.8<1% PoC
  • audiocodes mp-112 firmware
  • audiocodes mp-114 firmware
  • audiocodes mp-118 firmware
CVE-2025-46338
Audiobookshelf is a self-hosted audiobook and podcast server.

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.21.0, an improper input handling vulnerability in the `/api/upload` endpoint allows an attacker to perform a reflected cross-site scripting (XSS) attack by submitting malicious payloads in the `libraryId` field. The unsanitized input is reflected in the server’s error message, enabling arbitrary JavaScript execution in a victim's browser. This issue has been patched in version 2.21.0.

NVD description · AI analysis pending
6.9<1% PoC
  • audiobookshelf audiobookshelf
CVE-2025-25205
Audiobookshelf is a self-hosted audiobook and podcast server.

Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a flaw in the authentication bypass logic allows unauthenticated requests to match certain unanchored regex patterns in the URL. Attackers can craft URLs containing substrings like "/api/items/1/cover" in a query parameter (?r=/api/items/1/cover) to partially bypass authentication or trigger server crashes under certain routes. This could lead to information disclosure of otherwise protected data and, in some cases, a complete denial of service (server crash) if downstream code expects an authenticated user object. Version 2.19.1 contains a patch for the issue.

NVD description · AI analysis pending
8.25% PoC
  • audiobookshelf audiobookshelf
CVE-2024-52884
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841.

An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.

NVD description · AI analysis pending
7.5<1%
  • audiocodes mediant session border controller
CVE-2024-52883
+2 in the same advisory: …52881 …52882
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582.

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • audiocodes one voice operations center
CVE-2024-11586
Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.

Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.

NVD description · AI analysis pending
4.0<1%
  • pulseaudio pulseaudio
CVE-2024-49620
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mrcheck116 FERMA.ru.net ferma-ru-net-checkout allows Blind

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mrcheck116 FERMA.ru.net ferma-ru-net-checkout allows Blind SQL Injection.This issue affects FERMA.ru.net: from n/a through <= 1.3.3.

NVD description · AI analysis pending
8.8<1%
  • naudinvladimir ferma.ru.net
CVE-2024-49614
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SermonAudio SermonAudio Widgets sermonaudio-widgets allows

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SermonAudio SermonAudio Widgets sermonaudio-widgets allows SQL Injection.This issue affects SermonAudio Widgets: from n/a through <= 1.9.3.

NVD description · AI analysis pending
8.8<1%
  • sermonaudio sermonaudio widgets
CVE-2024-43797
audiobookshelf is a self-hosted audiobook and podcast server.

audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission to). However, the `LibraryController` is missing the check for admin user and thus allows a path traversal issue. Allowing non-admin users to write to any directory in the system can be seen as a form of path traversal. However, since it can be restricted to only admin permissions, fixing this is relatively simple and falls more into the realm of Role-Based Access Control (RBAC). This issue has been addressed in release version 2.13.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
4.3<1% PoC
  • audiobookshelf audiobookshelf
CVE-2024-39685
+1 in the same advisory: …39688
Bert-VITS2 is the VITS2 Backbone with multilingual bert.

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the resample function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • fish.audio bert-vits2
CVE-2024-39686
Bert-VITS2 is the VITS2 Backbone with multilingual bert.

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the bert_gen function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.

NVD description · AI analysis pending
9.81% PoC
  • fishaudio bert-vits2
CVE-2024-30889
Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, metho

Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, method, widget_type, request_id, payload parameters.

NVD description · AI analysis pending
5.4<1% PoC
  • web-audimex audimexee
CVE-2024-4419
The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to insufficie

The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

NVD description · AI analysis pending
4.0<1%
  • pjaudiomv fetch jft
CVE-2024-35236
Audiobookshelf is a self-hosted audiobook and podcast server.

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Attacking a user with high privileges (upload, creation of libraries) can lead to remote code execution (RCE) in the worst case. This was tested on version 2.9.0 on Windows, but an arbitrary file write is powerful enough as is and should easily lead to RCE on Linux, too. Version 2.10.0 contains a patch for the vulnerability.

NVD description · AI analysis pending
4.8<1% PoC ×2
  • audiobookshelf audiobookshelf
CVE-2023-51697
+1 in the same advisory: …51665
Audiobookshelf is a self-hosted audiobook and podcast server.

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.7.0, Audiobookshelf is vulnerable to unauthenticated blind server-side request (SSRF) vulnerability in `podcastUtils.js`. This vulnerability has been addressed in version 2.7.0. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
7.5<1%
  • audiobookshelf audiobookshelf
CVE-2023-47624
+1 in the same advisory: …47619
Audiobookshelf is a self-hosted audiobook and podcast server.

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the `/hls` endpoint. This issue may lead to Information Disclosure. As of time of publication, no patches are available.

NVD description · AI analysis pending
6.5<1% PoC
  • audiobookshelf audiobookshelf
CVE-2023-6196
+1 in the same advisory: …6197
The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4.

The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missing or incorrect nonce validation on the function audio_merchant_add_audio_file function. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

NVD description · AI analysis pending
8.8
group max
<1%
  • myaudiomerchant audio merchant
CVE-2023-46396
Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters.

Audimex 15.0.0 is vulnerable to Cross Site Scripting (XSS) in /audimex/cgi-bin/wal.fcgi via company parameter search filters.

NVD description · AI analysis pending
5.4<1% PoC
  • web-audimex audimex
CVE-2023-36361
Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

NVD description · AI analysis pending
9.8<1%
  • web-audimex audimexee
CVE-2023-39559
AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.

AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.

NVD description · AI analysis pending
5.3<1% PoC
  • web-audimex audimexee