ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-67298
An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile

An issue in ClasroomIO before v.0.2.6 allows a remote attacker to escalate privileges via the endpoints /api/verify and /rest/v1/profile

NVD description · AI analysis pending
8.1<1% PoC
  • classroomio classroomio
CVE-2025-65669
+4 in the same advisory: …65672 …65675 …65676 …65670
An issue was discovered in classroomio 0.1.13.

An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction.

NVD description · AI analysis pending
9.1
group max
<1% PoC
  • classroomio classroomio