ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-4514
+1 in the same advisory: …4297
The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post w

The Mmm Simple File List WordPress plugin through 2.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • mediamanifesto mmm simple file list
CVE-2020-12069
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords u

In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.

NVD description · AI analysis pending
7.8<1%
  • pilz pmc
  • pilz control for beaglebone
  • pilz control for empc-a\/imx6
  • +1 more
CVE-2022-3270
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confident

In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.

NVD description · AI analysis pending
9.81%
  • festo bus module cpx-e-ep firmware
  • festo bus node cpx-fb32 firmware
  • festo bus node cpx-fb33 firmware
  • +1 more
CVE-2022-3079
Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of

Festo control block CPX-CEC-C1 and CPX-CMXX in multiple versions allow unauthenticated, remote access to critical webpage functions which may cause a denial of service.

NVD description · AI analysis pending
7.5<1%
  • festo cpx-cmxx firmware
  • festo cpx-cec-c1 firmware
CVE-2022-30309
+3 in the same advisory: …30308 …30310 …30311
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax.

In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.

NVD description · AI analysis pending
9.83%
  • festo controller cecc-x-m1 firmware
  • festo controller cecc-x-m1-mv firmware
  • festo controller cecc-x-m1-mv-s1 firmware
  • +1 more