ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-6689
+1 in the same advisory: …50707
A successful CSRF attack could force the user to perform state changing requests on the application.

A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CSRF attack could compromise the entire web application.

NVD description · AI analysis pending
8.8
group max
<1%
  • efacec bcu 500 firmware
CVE-2023-50704
+3 in the same advisory: …50703 …50705 …50706
An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing

An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.

NVD description · AI analysis pending
6.1
group max
<1%
  • efacec uc 500e firmware