ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-9003
A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0.

A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do of the component Attachment Handler. The manipulation of the argument oid leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3<1%
  • jflow project jflow
CVE-2023-25230
A Server-Side Request Forgery (SSRF) in loonflow r2.0.14 allows attackers to force the application to make arbitrary requests via manipulation of the hook_url p

A Server-Side Request Forgery (SSRF) in loonflow r2.0.14 allows attackers to force the application to make arbitrary requests via manipulation of the hook_url parameter.

NVD description · AI analysis pending
4.9<1% PoC
  • loonflow project loonflow
CVE-2021-28173
+2 in the same advisory: …28171 …28172
The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly.

The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers can upload and execute arbitrary files without login.

NVD description · AI analysis pending
9.8
group max
2%
  • deltaflow project deltaflow
CVE-2016-10970
+1 in the same advisory: …10969
The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt.

The supportflow plugin before 0.7 for WordPress has XSS via a ticket excerpt.

NVD description · AI analysis pending
6.11%
  • supportflow project supportflow
CVE-2018-13525
The mintToken function of a smart contract implementation for Flow, an Ethereum token, has an integer overflow that allows the owner of the contract to set the

The mintToken function of a smart contract implementation for Flow, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

NVD description · AI analysis pending
7.51% PoC
  • flow project flow