ZeroHour

Vulnerabilities

17 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-35355
A vulnerability has been discovered in Diño Physics School Assistant version 2.3.

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=delete_category. Manipulating the argument id can result in SQL injection.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • dino physics school assistant project dino physics school assistant
CVE-2023-28686
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message.

Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.

NVD description · AI analysis pending
7.1<1%
  • dino dino
  • dino fedora
  • dino debian linux
CVE-2021-33896
Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.

Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.

NVD description · AI analysis pending
5.32%
  • dino dino
  • dino fedora
CVE-2019-16236
+2 in the same advisory: …16235 …16237
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.

Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.

NVD description · AI analysis pending
7.52% PoC
  • dino dino
  • dino ubuntu linux
  • dino fedora
  • +1 more