ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-36385
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (

A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the default.aspx User ID field. Arbitrary system commands can be executed through the use of xp_cmdshell.

NVD description · AI analysis pending
9.83%
  • cerner mobile care
CVE-2020-11674
+3 in the same advisory: …11676 …11675 …11677
Cerner medico 26.00 allows variable reuse, possibly causing data corruption.

Cerner medico 26.00 allows variable reuse, possibly causing data corruption.

NVD description · AI analysis pending
8.8<1% PoC
  • cerner medico
CVE-2018-20053
+1 in the same advisory: …20052
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices.

An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The hostname, timezone, and NTP server configurations on the CCE device are vulnerable to command injection by sending a crafted configuration file over the network.

NVD description · AI analysis pending
9.8
group max
2%
  • cerner connectivity engine 4 firmware