ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-35815
+3 in the same advisory: …35814 …35817 …35816
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

NVD description · AI analysis pending
9.8
group max
<1%
  • devexpress devexpress
CVE-2022-41479
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r=

The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code. NOTE: the vendor disputes this because the retrieved source code is only the DevExpress client-side application code that is, of course, intentionally readable by web browsers (a site's custom code and data is never accessible via an IDOR approach).

NVD description · AI analysis pending
7.51% PoC
  • devexpress asp.net web forms controls
CVE-2022-28684
This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit this vulnerability. The specific flaw exists within the SafeBinaryFormatter library. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-16710.

NVD description · AI analysis pending
8.83%
  • devexpress devexpress
CVE-2021-36483
DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

NVD description · AI analysis pending
8.83%
  • devexpress devexpress