ZeroHour

Vulnerabilities

23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-59106
The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges.

The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest privileges.

NVD description · AI analysis pending
8.8<1%
  • dormakabagroup dormakaba access manager 9200-k7 firmware
  • dormakabagroup dormakaba access manager 9230-k7 firmware
  • dormakabagroup dormakaba access manager 9290-k7 firmware
  • +1 more
CVE-2025-3733
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).Th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal baguetteBox.Js allows Cross-Site Scripting (XSS).This issue affects baguetteBox.Js: from 0.0.0 before 2.0.4, from 3.0.0 before 3.0.1.

NVD description · AI analysis pending
6.5<1%
  • baguettebox.js project baguettebox.js
CVE-2023-0737
wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/del

wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4.

NVD description · AI analysis pending
6.5<1% PoC
  • wallabag wallabag
CVE-2024-49327
Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows Upload a Web Shell to a Web Server.This

Unrestricted Upload of File with Dangerous Type vulnerability in bepitulaz Woostagram Connect woostagram-connect allows Upload a Web Shell to a Web Server.This issue affects Woostagram Connect: from n/a through <= 1.0.2.

NVD description · AI analysis pending
9.8<1%
  • asepbagjapriandana woostagram connect
CVE-2023-4455
+1 in the same advisory: …4454
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • wallabag wallabag
CVE-2023-3566
A vulnerability was found in wallabag 2.5.4.

A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-233359. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.51% PoC ×2
  • wallabag wallabag
CVE-2023-37122
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected int

A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.

NVD description · AI analysis pending
5.4<1% PoC
  • bagesoft bagecms
CVE-2023-0734
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.

NVD description · AI analysis pending
5.3<1% PoC
  • wallabag wallabag
CVE-2023-0735
+1 in the same advisory: …0736
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.

Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • wallabag wallabag
CVE-2023-0609
+1 in the same advisory: …0610
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

NVD description · AI analysis pending
4.3<1% PoC
  • wallabag wallabag
CVE-2023-22333
Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

NVD description · AI analysis pending
6.1<1%
  • mubag easymail
CVE-2022-25842
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially cr

All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.

NVD description · AI analysis pending
9.84% PoC
  • alibabagroup one-java-agent
CVE-2021-37786
Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions.

Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions. This affects COVID Certificate App IOS 2.2.0 and below affected, patch in progress and COVID Certificate Check App IOS 2.2.0 and below affected, patch in progress. A denial of service (physically proximate) could be caused by scanning a crafted QR code.

NVD description · AI analysis pending
4.6<1% PoC
  • bag covid certificate
CVE-2019-8421
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.

upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.

NVD description · AI analysis pending
7.21% PoC
  • bagesoft bagecms
CVE-2018-19560
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

NVD description · AI analysis pending
8.8<1% PoC
  • bagesoft bagecms
CVE-2018-19104
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.

In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.

NVD description · AI analysis pending
8.8<1% PoC
  • bagesoft bagecms
CVE-2018-18258
+1 in the same advisory: …18257
An issue was discovered in BageCMS 3.1.3.

An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • bagesoft bagecms
CVE-2018-11352
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page.

The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.

NVD description · AI analysis pending
4.0<1% PoC
  • wallabag wallabag
CVE-2018-14582
index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.

index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.

NVD description · AI analysis pending
8.8<1% PoC
  • bagesoft bagecms