ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-3422
U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on th

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

NVD description · AI analysis pending
9.3<1%
  • edetw u-office force
CVE-2025-12865
+1 in the same advisory: …12864
U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, mod

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete database contents.

NVD description · AI analysis pending
8.7<1%
  • edetw u-office force
CVE-2025-2395
+1 in the same advisory: …2396
The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter c

The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.

NVD description · AI analysis pending
9.8
group max
<1%
  • edetw u-office force
CVE-2023-32757
+2 in the same advisory: …32756 …32755
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type.

e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

NVD description · AI analysis pending
9.8
group max
<1%
  • edetw u-office force
CVE-2022-39023
U-Office Force Download function has a path traversal vulnerability.

U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.

NVD description · AI analysis pending
6.5
group max
<1%
  • edetw u-office force