ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-2177
A vulnerability has been found in SourceCodester Prison Management System 1.0.

A vulnerability has been found in SourceCodester Prison Management System 1.0. The impacted element is an unknown function of the component Login. The manipulation leads to session fixiation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.5<1% PoC
  • fast5 prison management system
CVE-2024-48594
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.

File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.

NVD description · AI analysis pending
8.83% PoC
  • fast5 prison management system
CVE-2024-4644
+1 in the same advisory: …4645
A vulnerability has been found in SourceCodester Prison Management System 1.0 and classified as problematic.

A vulnerability has been found in SourceCodester Prison Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /Employee/changepassword.php. The manipulation of the argument txtold_password/txtnew_password/txtconfirm_password leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263488.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • fast5 prison management system
CVE-2024-4512
+1 in the same advisory: …4528
A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0.

A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/edit-profile.php. The manipulation of the argument txtfullname/txtdob/txtaddress/txtqualification/cmddept/cmdemployeetype/txtappointment leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263116.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • fast5 prison management system
CVE-2024-4500
A vulnerability was found in SourceCodester Prison Management System 1.0.

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Employee/edit-photo.php. The manipulation of the argument userImage leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-263104.

NVD description · AI analysis pending
8.8<1% PoC
  • fast5 prison management system
CVE-2024-3439
A vulnerability was found in SourceCodester Prison Management System 1.0.

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259692.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • fast5 prison management system