ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-5422
XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the ser

XSS in buttle npm package version 0.2.0 causes execution of attacker-provided code in the victim's browser when an attacker creates an arbitrary file on the server.

NVD description · AI analysis pending
6.11%
  • buttle project buttle
CVE-2018-3766
Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.

Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.

NVD description · AI analysis pending
7.52% PoC
  • buttle project buttle