ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-9582
The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, an

The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an accordion slider in all versions up to, and including, 1.9.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: Successful exploitation by Contributor-level users requires an Administrator-level user to provide access to the plugin's admin area via the `Access` plugin setting, which is restricted to administrators by default.

NVD description · AI analysis pending
5.4<1%
  • bqworks accordion slider
CVE-2021-42258
Unauthenticated SQL Injection RCE in BQE BillQuick Web Suite

CVE-2021-42258 is an unauthenticated SQL injection flaw (CWE-89) in BQE BillQuick Web Suite 2018 through 2021, fixed in version 22.0.9.1, that can be triggered through user-supplied input such as the txtID (username) parameter of the web interface. Because attacker-controlled input reaches the backend Microsoft SQL Server, an unauthenticated attacker with network access to the web suite can inject SQL and abuse xp_cmdshell to execute arbitrary code on the database server under the MSSQLSERVER$ account. This yields full unauthenticated remote code execution, and in observed intrusions it was used to deploy ransomware. Any organization running an affected BillQuick Web Suite release is affected, particularly those exposing the billing portal directly to the internet. The flaw is actively exploited in the wild (added to CISA KEV on 2021-11-03 with known ransomware use) and carries a high EPSS score of 74.4%, making urgent patching advisable.

Do: Upgrade BillQuick Web Suite to version 22.0.9.1 or later per BQE's instructions, as required by the CISA KEV entry. Until patched, restrict internet-facing access to the Web Suite server and review logs for SQL injection attempts against the username (txtID) parameter, unexpected xp_cmdshell usage, or commands running as MSSQLSERVER$; the referenced Huntress advisory includes indicators of compromise for the October 2021 ransomware campaign.

9.874% KEV ransomware PoC
  • BQE BillQuick Web Suite 2018 through 2021, before 22.0.9.1
nichelikely low thousands of installations worldwide, with only hundreds of internet-exposed instances
CVE-2021-20086
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a malicious user to inject properties into Object.prototype.

NVD description · AI analysis pending
8.86% PoC
  • jquery-bbq project jquery-bbq
CVE-2019-15381
The BQ 5515L Android device with a build fingerprint of BQru/BQru-5515L/BQru-5515L:8.1.0/O11019/20180409.195525:user/release-keys contains a pre-installed app w

The BQ 5515L Android device with a build fingerprint of BQru/BQru-5515L/BQru-5515L:8.1.0/O11019/20180409.195525:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.

NVD description · AI analysis pending
5.5<1%
  • bq 5515l firmware
CVE-2017-12145
+1 in the same advisory: …12143
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.

NVD description · AI analysis pending
6.51%
  • libquicktime libquicktime
CVE-2017-9122
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a

The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.

NVD description · AI analysis pending
6.56%
  • libquicktime libquicktime
CVE-2016-2399
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have o

Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom.

NVD description · AI analysis pending
7.87% PoC ×2
  • libquicktime libquicktime