ZeroHour

Vulnerabilities

45 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-46494
A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name

A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.

NVD description · AI analysis pending
5.4<1% PoC
  • typecho typecho
CVE-2024-57369
Clickjacking vulnerability in typecho v1.2.1.

Clickjacking vulnerability in typecho v1.2.1.

NVD description · AI analysis pending
6.4<1%
  • typecho typecho
CVE-2024-42495
+1 in the same advisory: …39278
Credentials to access device configuration were transmitted using an unencrypted protocol.

Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data.

NVD description · AI analysis pending
7.1
group max
<1%
  • echostar fusion
CVE-2024-35540
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

NVD description · AI analysis pending
9.03% PoC
  • typecho typecho
CVE-2024-35539
+1 in the same advisory: …35538
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function.

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.

NVD description · AI analysis pending
6.5
group max
1% PoC
  • typecho typecho
CVE-2023-6615
+2 in the same advisory: …6613 …6614
A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1.

A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected by this issue is some unknown functionality of the file /admin/manage-users.php. The manipulation of the argument page leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-247250 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3
group max
<1% PoC
  • typecho typecho
CVE-2023-49967
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.

Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.

NVD description · AI analysis pending
7.5<1% PoC
  • typecho typecho
CVE-2023-38817
An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component.

An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself."

NVD description · AI analysis pending
7.8<1% PoC
  • echo anti cheat tool
CVE-2023-36299
A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.

A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.

NVD description · AI analysis pending
8.82% PoC
  • typecho typecho
CVE-2020-21038
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.

Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.

NVD description · AI analysis pending
6.1<1% PoC
  • typecho typecho
CVE-2023-30184
A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected int

A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter at /index.php/archives/1/comment.

NVD description · AI analysis pending
5.4<1% PoC
  • typecho typecho
CVE-2023-27711
+2 in the same advisory: …27131 …27130
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.ph

Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component.

NVD description · AI analysis pending
4.8<1% PoC ×2
  • typecho typecho
CVE-2023-24114
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.

typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.

NVD description · AI analysis pending
9.81% PoC
  • typecho typecho
CVE-2021-4124
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NVD description · AI analysis pending
6.1<1% PoC
  • meetecho janus
CVE-2021-4020
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NVD description · AI analysis pending
5.4<1% PoC
  • meetecho janus
CVE-2021-33578
+4 in the same advisory: …36124 …36121 …36122 …36123
Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to

Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data.

NVD description · AI analysis pending
9.8
group max
1%
  • echobh sharecare
CVE-2021-29061
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attemp

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs.

NVD description · AI analysis pending
7.52% PoC ×3
  • vfsjfilechooser2 project vfsjfilechooser2
CVE-2020-14034
+1 in the same advisory: …14033
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0.

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

NVD description · AI analysis pending
9.82%
  • meetecho janus
CVE-2020-13901
+3 in the same advisory: …13898 …13900 …13899
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0.

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.

NVD description · AI analysis pending
9.8
group max
3% PoC
  • meetecho janus
CVE-2020-10574
+4 in the same advisory: …10573 …10576 …10577 …10575
An issue was discovered in Janus through 0.9.1.

An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.

NVD description · AI analysis pending
9.8
group max
1%
  • meetecho janus
CVE-2018-18753
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.

Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.

NVD description · AI analysis pending
9.83% PoC
  • typecho typecho
CVE-2018-13832
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attac

Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.

NVD description · AI analysis pending
4.82% PoC ×2
  • techotronic all in one favicon
CVE-2017-16230
In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in

In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit.

NVD description · AI analysis pending
5.4<1% PoC
  • typecho typecho
CVE-2017-2228
Untrusted search path vulnerability in Teikihoukokusho Sakuseishien Tool v4.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified dir

Untrusted search path vulnerability in Teikihoukokusho Sakuseishien Tool v4.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

NVD description · AI analysis pending
7.81%
  • enecho.meti teikihoukokusho sakuseishien tool
CVE-2017-10823
Untrusted search path vulnerability in Installer for Shin Kinkyuji Houkoku Data Nyuryoku Program (program released on 2011 March 10) Distributed on the website

Untrusted search path vulnerability in Installer for Shin Kinkyuji Houkoku Data Nyuryoku Program (program released on 2011 March 10) Distributed on the website till 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

NVD description · AI analysis pending
7.81%
  • enecho.meti shin kinkyuji houkoku data nyuryoku program
CVE-2017-10822
Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed

Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

NVD description · AI analysis pending
7.81%
  • enecho.meti shin sekiyu yunyu chousa houkoku data nyuryoku program
CVE-2017-10821
Untrusted search path vulnerability in Installer for Shin Kikan Toukei Houkoku Data Nyuryokuyou Program (program released on 2013 September 30) Distributed on t

Untrusted search path vulnerability in Installer for Shin Kikan Toukei Houkoku Data Nyuryokuyou Program (program released on 2013 September 30) Distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

NVD description · AI analysis pending
7.81%
  • enecho.meti shin kikan toukei houkoku data nyuryokuyou program