ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-52323
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.

NVD description · AI analysis pending
5.9<1%
  • pycryptodome pycryptodome
  • pycryptodome pycryptodomex
CVE-2022-36787
+1 in the same advisory: …39178
webvendome - webvendome SQL Injection.

webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.

NVD description · AI analysis pending
9.8
group max
<1%
  • webvendome project webvendome
CVE-2021-34577
In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded shared key while being adjacent to the dev

In the Kaden PICOFLUX AiR water meter an adversary can read the values through wireless M-Bus mode 5 with a hardcoded shared key while being adjacent to the device.

NVD description · AI analysis pending
6.5<1%
  • kadenvodomery picoflux air firmware
CVE-2020-9058
Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM

Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection.

NVD description · AI analysis pending
8.1<1%
  • silabs 500 series firmware
  • silabs dm501
  • silabs zw4201
  • +1 more
CVE-2021-41232
Thunderdome is an open source agile planning poker tool in the theme of Battling for points.

Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is not properly escaped. This issue has been patched in version 1.16.3. If users are unable to update they should disable the LDAP feature if in use.

NVD description · AI analysis pending
9.82%
  • thunderdome planning poker
CVE-2021-34576
In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists.

In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give sensitive information (water consumption without distinct values) to third parties.

NVD description · AI analysis pending
4.3<1%
  • kadenvodomery picoflux air firmware
CVE-2018-15560
PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the

PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes.

NVD description · AI analysis pending
7.52% PoC ×2
  • pycryptodome pycryptodome