ZeroHour

Vulnerabilities

399 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-5964
+1 in the same advisory: …5963
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

NVD description · AI analysis pending
9.3<1%
  • digiwin easyflow .net
CVE-2026-39397
@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder.

@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/puck/* CRUD endpoint handlers registered by createPuckPlugin() called Payload's local API with the default overrideAccess: true, bypassing all collection-level access control. The access option passed to createPuckPlugin() and any access rules defined on Puck-registered collections were silently ignored on these endpoints. This vulnerability is fixed in 0.6.23.

NVD description · AI analysis pending
9.8<1% PoC
  • delmaredigital payload-puck
CVE-2026-33896
+3 in the same advisory: …33891 …33895 …33894
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript.

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.

NVD description · AI analysis pending
9.1
group max
<1% PoC
  • digitalbazaar forge
CVE-2026-25061
tcpflow is a TCP/IP packet demultiplexer.

tcpflow is a TCP/IP packet demultiplexer. In versions up to and including 1.61, wifipcap parses 802.11 management frame elements and performs a length check on the wrong field when handling the TIM element. A crafted frame with a large TIM length can cause a 1-byte out-of-bounds write past `tim.bitmap[251]`. The overflow is small and DoS is the likely impact; code execution is potential, but still up in the air. The affected structure is stack-allocated in `handle_beacon()` and related handlers. As of time of publication, no known patches are available.

NVD description · AI analysis pending
5.5<1% PoC
  • digitalcorpora tcpflow
  • digitalcorpora debian linux
CVE-2025-13979
Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site:

Privilege Defined With Unsafe Actions vulnerability in Drupal Mini site allows Stored XSS.This issue affects Mini site: from 0.0.0 before 3.0.2.

NVD description · AI analysis pending
5.4<1%
  • salsa.digital mini site
CVE-2023-53975
Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters.

Atom CMS 2.0 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries through unvalidated parameters. Attackers can inject malicious SQL code in the 'id' parameter of the admin index page to execute time-based blind SQL injection attacks.

NVD description · AI analysis pending
9.3<1% PoC
  • thedigitalcraft atomcms
CVE-2025-55816
HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.

HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file.

NVD description · AI analysis pending
6.1<1% PoC
  • digitaldruid hoteldruid
CVE-2025-66031
+1 in the same advisory: …66030
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript.

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.

NVD description · AI analysis pending
8.7
group max
<1%
  • digitalbazaar forge
CVE-2025-12816
An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desyn

An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.

NVD description · AI analysis pending
8.6<1% PoC
  • digitalbazaar forge
CVE-2025-12082
+1 in the same advisory: …12083
Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System:

Incorrect Authorization vulnerability in Drupal CivicTheme Design System allows Forceful Browsing.This issue affects CivicTheme Design System: from 0.0.0 before 1.12.0.

NVD description · AI analysis pending
7.5
group max
<1%
  • salsa.digital civictheme design system
CVE-2025-59684
DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.

DigiSign DigiSigner ONE 1.0.4.60 allows DLL Hijacking.

NVD description · AI analysis pending
8.8<1% PoC
  • digisign digisigner one
CVE-2025-59717
In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedCla

In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .includes substring matching if allowedClasses or allowedEnvironments is a string (instead of an array).

NVD description · AI analysis pending
9.8<1% PoC
  • digitalocean do-markdownit
CVE-2021-4457
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

NVD description · AI analysis pending
9.1<1% PoC
  • digitalzoomstudio zoomsounds
CVE-2025-44203
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation wi

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a race condition during which verbose SQL error messages disclose the administrator username, password hash, and salt. The same race leaves the setup partially initialized, so the administrator can no longer log in with the credentials set during installation, resulting in a denial of service that requires reinstallation to recover. Remote exploitation additionally requires the installation to allow non-localhost access. The vulnerability was fixed in version 3.0.8.

NVD description · AI analysis pending
7.5<1%
  • digitaldruid hoteldruid
CVE-2025-47568
Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds:

Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue affects ZoomSounds: from n/a through <= 6.91.

NVD description · AI analysis pending
9.8<1%
  • digitalzoomstudio zoomsounds
CVE-2023-6786
The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an O

The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue

NVD description · AI analysis pending
6.1<1% PoC
  • hkdigit payment gateway for telcell
CVE-2025-4527
+2 in the same advisory: …4528 …4526
A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21.

A security flaw has been discovered in Dígitro NGC Explorer up to 3.48.21. The impacted element is an unknown function of the component Password Transmission Handler. Performing a manipulation results in client-side enforcement of server-side security. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. Upgrading to version 3.48.22 is sufficient to resolve this issue. Upgrading the affected component is recommended. The action taken by the vendor is: "Strengthening of security validation performed on the server side, together with improvements to administrative and authentication controls." The vulnerabilities are limited to NGC Explorer and do not affect other Dígitro products, including UNA and Guardião.

NVD description · AI analysis pending
2.9
group max
<1%
  • digitro ngc explorer
CVE-2025-3927
Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and comp

Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.

NVD description · AI analysis pending
9.8<1%
  • digigram pyko-out
CVE-2023-43378
A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into th

A cross-site scripting (XSS) vulnerability in Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the commento1_1 parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • digitaldruid hoteldruid
CVE-2025-3431
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.91 via the 'dzsap_download' action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

NVD description · AI analysis pending
7.5<1%
  • digitalzoomstudio zoomsounds
CVE-2024-13776
+1 in the same advisory: …0839
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'dzsap_delete_notice' AJAX action in all versions up to, and including, 6.91. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update option values to 'seen' on the WordPress site. This can be leveraged to update an option that would create an error on the site and deny service to legitimate users or be used to set some values to true such as registration. There are several other functions also vulnerable to missing authorization.

NVD description · AI analysis pending
8.1
group max
<1%
  • digitalzoomstudio zoomsounds
CVE-2025-25748
+2 in the same advisory: …25749 …25747
A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) o

A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token.

NVD description · AI analysis pending
7.3
group max
<1%
  • digitaldruid hoteldruid
CVE-2024-13777
The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91

The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.91 via deserialization of untrusted input from the 'margs' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

NVD description · AI analysis pending
9.8<1%
  • digitalzoomstudio zoomsounds
CVE-2025-1387
+2 in the same advisory: …1388 …1389
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.

Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.

NVD description · AI analysis pending
9.8
group max
<1%
  • learningdigital orca hcm
CVE-2025-25167
+1 in the same advisory: …25168
Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security

Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7.

NVD description · AI analysis pending
9.8
group max
<1%
  • blackandwhitedigital bookpress
CVE-2023-52163
Missing Authorization Enables Command Injection in Digiever DS-2105 Pro NVRs

Digiever DS-2105 Pro network video recorders (firmware version 3.1.0.71-11 is cited in the advisory) expose a time_tzsetup.cgi endpoint that fails to properly enforce authorization (CWE-862), and crafted requests to it trigger operating-system command injection; the CVSS 8.8 score reflects network reachability, low privilege requirements, and no user interaction. Successful exploitation yields command execution on the device with high impact on confidentiality, integrity, and availability — effectively remote code execution, which makes these NVRs attractive targets for IoT botnets such as the RondoDox campaign and the Mirai-variant ShadowV2. Only organizations still running the DS-2105 Pro (or DS-2105 Pro+) are affected, and because the vendor no longer supports the product, unpatched internet-facing units are the primary risk. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-12-22, EPSS puts the 30-day exploitation probability at 96.9%, and ransomware use is currently unknown.

Do: Because the product is end-of-life, check with Digiever for any final firmware update and apply it per vendor instructions; if no patch or mitigation is available, the CISA KEV required action is to discontinue use of the device, and federal agencies must follow BOD 22-01 timelines. In the interim, remove direct internet exposure of the NVR's web interface (restrict via firewall or place behind VPN) and hunt for compromise by looking for suspicious requests to time_tzsetup.cgi and unexpected outbound connections consistent with botnet infection.

8.897% KEV PoC ×3
  • Digiever DS-2105 Pro NVR firmware 3.1.0.71-11 (the version named in the advisory; the product is end-of-life and no longer supported)
  • Digiever DS-2105 Pro+ NVR firmware
moderatelikely on the order of thousands of internet-exposed NVRs (estimated; exact install base unknown)
CVE-2024-11842
The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

NVD description · AI analysis pending
4.3<1% PoC
  • digireturn shipping by weight for woocommerce
CVE-2024-50626
+3 in the same advisory: …50628 …50627 …50625
An issue was discovered in Digi ConnectPort LTS before 1.4.12.

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area network to manipulate URLs to include traversal sequences, potentially leading to unauthorized access to data.

NVD description · AI analysis pending
8.8
group max
<1%
  • digi connectport lts firmware
CVE-2021-4449
The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and

The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'savepng.php' file in versions up to, and including, 5.96. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. CVE-2021-4457 is a duplicate of this.

NVD description · AI analysis pending
9.85% PoC ×2
  • digitalzoomstudio zoomsounds
CVE-2024-8803
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate

The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

NVD description · AI analysis pending
6.1<1%
  • madfishdigital bulk noindex \& nofollow toolkit
CVE-2024-6845
The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retriev

The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key

NVD description · AI analysis pending
5.31% PoC
  • webdigit chatbot with chatgpt
CVE-2024-43988
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in digitalnature Mystique allows Stored XSS.This issue

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in digitalnature Mystique allows Stored XSS.This issue affects Mystique: from n/a through 2.5.7.

NVD description · AI analysis pending
5.4<1%
  • digitalnature mystique
CVE-2024-8585
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privil

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remote attacker with regular privileges to download arbitrary system files.

NVD description · AI analysis pending
6.5<1%
  • learningdigital orca hcm