ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-8888
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new Re

Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific patterns to cause catastrophic backtracking, resulting in denial of service on all browsing.

NVD description · AI analysis pending
7.5
group max
<1%
  • securly securly
CVE-2025-11563
URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly as

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

NVD description · AI analysis pending
4.6<1%
  • curl wcurl
CVE-2021-30134
php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimens

php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the post_file_path_upload.php key parameter and the POST data to post_multidimensional.php.

NVD description · AI analysis pending
6.11% PoC
  • php curl class project php curl class
  • php curl class project ht slider range for amazon affiliates
  • php curl class project woo-qiwi-payment-gateway
  • +1 more
CVE-2020-28425
This affects all versions of package curljs.

This affects all versions of package curljs.

NVD description · AI analysis pending
9.8<1% PoC
  • curljs project curljs
CVE-2020-36474
SafeCurl before 0.9.2 has a DNS rebinding vulnerability.

SafeCurl before 0.9.2 has a DNS rebinding vulnerability.

NVD description · AI analysis pending
9.82%
  • safecurl project safecurl
CVE-2021-23416
This affects all versions of package curly-bracket-parser.

This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitize the user input.

NVD description · AI analysis pending
6.1<1% PoC
  • curly-bracket-parser project curly-bracket-parser
CVE-2020-7646
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

NVD description · AI analysis pending
9.82% PoC
  • curlrequest project curlrequest
CVE-2019-10789
All versions of curling.js are vulnerable to Command Injection via the run function.

All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

NVD description · AI analysis pending
9.85% PoC ×2
  • curling project curling
CVE-2018-6651
In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrar

In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer.

NVD description · AI analysis pending
8.82%
  • uncurl project uncurl
  • uncurl project parsec
CVE-2017-0907
The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerabil

The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.

NVD description · AI analysis pending
9.83%
  • recurly recurly client .net
CVE-2017-0906
The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "

The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.

NVD description · AI analysis pending
9.83%
  • recurly recurly client python
CVE-2017-0905
The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side R

The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in compromise of API keys or other critical resources.

NVD description · AI analysis pending
9.83%
  • recurly recurly client ruby