ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-1789
+1 in the same advisory: …1787
Local privilege escalation in Genetec Update Service.

Local privilege escalation in Genetec Update Service. An authenticated, low-privileged, Windows user could exploit this vulnerability to gain elevated privileges on the affected system.

NVD description · AI analysis pending
5.8<1%
  • genetec genetec update service
CVE-2024-13818
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information about users contained in the exposed log files.

NVD description · AI analysis pending
7.5<1%
  • genetechsolutions pie register
CVE-2024-27957
Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register:

Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.

NVD description · AI analysis pending
9.8<1%
  • genetechsolutions pie register
CVE-2023-1522
SQL Injection in the Hardware Inventory report of Security Center 5.11.2.

SQL Injection in the Hardware Inventory report of Security Center 5.11.2.

NVD description · AI analysis pending
8.8<1%
  • genetec security center
CVE-2023-0552
The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

NVD description · AI analysis pending
5.424% PoC
  • genetechsolutions pie register
CVE-2022-4024
The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthentic

The Registration Forms WordPress plugin before 3.8.1.3 does not have authorisation and CSRF when deleting users via an init action handler, allowing unauthenticated attackers to delete arbitrary users (along with their posts)

NVD description · AI analysis pending
6.5<1% PoC
  • genetechsolutions pie register
CVE-2021-24731
+1 in the same advisory: …24647
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properl

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

NVD description · AI analysis pending
9.8
group max
6% PoC
  • genetechsolutions pie register
CVE-2021-24239
The Pie Register – User Registration Forms.

The Pie Register – User Registration Forms. Invitation based registrations, Custom Login, Payments WordPress plugin before 3.7.0.1 does not sanitise the invitaion_code GET parameter when outputting it in the Activation Code page, leading to a reflected Cross-Site Scripting issue.

NVD description · AI analysis pending
6.12% PoC
  • genetechsolutions pie register
CVE-2019-15659
The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.

The pie-register plugin before 3.1.2 for WordPress has SQL injection, a different issue than CVE-2018-10969.

NVD description · AI analysis pending
9.82%
  • genetechsolutions pie register
CVE-2019-1010207
Genetechsolutions Pie Register 3.0.15 is affected by:

Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session cookies. The component is: File: Login. Parameters: interim-login, wp-lang, and supplied URL. The attack vector is: If a victim clicks a malicious link, the attacker can steal his/her account. The fixed version is: 3.0.16.

NVD description · AI analysis pending
6.12%
  • genetechsolutions pie register
CVE-2018-10969
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation

SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.

NVD description · AI analysis pending
9.85% PoC
  • genetechsolutions pie register