ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-8868
+1 in the same advisory: …6724
SQL Injection in Progress Chef Automate Compliance Service

CVE-2025-8868 is a SQL injection flaw (CWE-89) in the compliance service of Progress Chef Automate that also results in exposure of sensitive information (CWE-200). An authenticated attacker with low privileges can trigger it remotely without user interaction by sending improperly neutralized input that is used in a SQL command, reportedly via a well-known token. Successful exploitation grants access to restricted compliance-service functionality and can disclose sensitive data, which the high CVSS 3.1 score of 8.8 (C:H/I:H/A:H) reflects. Only Chef Automate versions earlier than 4.13.295 running on the Linux x86 platform are affected. No public proof-of-concept or confirmed in-the-wild exploitation is currently known, but the 24.3% EPSS score (98th percentile) indicates a high probability of exploitation within the next 30 days.

Do: Upgrade Chef Automate to version 4.13.295 or later on affected Linux x86 installations. Until patched, restrict access to the compliance service to trusted, low-privileged accounts and check whether the well-known token referenced in the advisory is in use, rotating it where feasible. Prioritize patching internet-exposed or multi-tenant Automate instances, given the 98th-percentile EPSS score and the fact that any authenticated user can exploit the flaw.

8.824%
  • Progress (Chef) Chef Automate all versions earlier than 4.13.295 on the Linux x86 platform
moderate≈ low thousands of Chef Automate deployments, of which only a minority are internet-exposed (estimate)
CVE-2024-0338
A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier.

A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH).

NVD description · AI analysis pending
9.8<1%
  • apachefriends xampp
CVE-2023-42658
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

NVD description · AI analysis pending
7.8<1%
  • chef inspec
CVE-2023-40050
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

NVD description · AI analysis pending
8.81%
  • chef automate
CVE-2022-47637
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory.

The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.

NVD description · AI analysis pending
6.7<1% PoC
  • apachefriends xampp
CVE-2017-20018
A vulnerability was found in XAMPP 7.1.1-0-VC14.

A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely.

NVD description · AI analysis pending
7.8<1% PoC
  • apachefriends xampp
CVE-2022-29376
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via ov

Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.

NVD description · AI analysis pending
8.81% PoC
  • apachefriends xampp
CVE-2020-11107
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.

An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.

NVD description · AI analysis pending
8.822% PoC
  • apachefriends xampp
CVE-2019-8920
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.

iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.

NVD description · AI analysis pending
6.1<1% PoC
  • apachefriends xampp
CVE-2019-12826
A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to

A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 for WordPress allows remote attackers to execute PHP code via snippets (that are attached to widgets and then eval'd to dynamically determine their visibility) by crafting a malicious POST request that tricks administrators into adding the code.

NVD description · AI analysis pending
8.81% PoC
  • wpchef widget logic
CVE-2019-8924
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter.

XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.

NVD description · AI analysis pending
6.16% PoC ×3
  • apachefriends xampp
CVE-2019-8923
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter.

XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.

NVD description · AI analysis pending
9.84% PoC ×2
  • apachefriends xampp
CVE-2017-7174
The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code.

The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.

NVD description · AI analysis pending
9.82%
  • chef manage project chef manage
CVE-2016-4326
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cooki

The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.

NVD description · AI analysis pending
9.84%
  • chef chef manage