ZeroHour

Vulnerabilities

59 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-23758
+4 in the same advisory: …23757 …23756 …23753 …23752
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject ma

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Controller_Ticket.EditSubmit() that bypass the incomplete SanitizeForXSS() method to execute arbitrary JavaScript when other staff members or administrators view the affected ticket.

NVD description · AI analysis pending
6.4
group max
<1%
  • gfi helpdesk
CVE-2026-2039
+3 in the same advisory: …2038 …2037 …2036
GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability.

GFI Archiver MArc.Store Missing Authorization Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MArc.Store.Remoting.exe process, which listens on port 8018. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of SYSTEM. Was ZDI-CAN-28597.

NVD description · AI analysis pending
9.8
group max
<1%
  • gfi archiver
CVE-2026-23621
GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web method expos

GFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web method exposed at /MailEssentials/pages/MailSecurity/ListServer.aspx/IsPathExist. An authenticated user can supply an unrestricted filesystem path via the JSON key \"path\", which is URL-decoded and passed to Directory.Exists(), allowing the attacker to determine whether arbitrary directories exist on the server.

NVD description · AI analysis pending
5.3
group max
<1%
  • gfi mailessentials
CVE-2025-34070
+2 in the same advisory: …34069 …34071
A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operat

A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The /proxy handler on port 7996 allows arbitrary forwarding to administrative endpoints when provided with an Appliance UUID, which itself can be retrieved from port 7995. This results in a complete authentication bypass, permitting access to sensitive administrative APIs.

NVD description · AI analysis pending
10.0
group max
<1% PoC
  • gfi kerio control
CVE-2025-34491
+2 in the same advisory: …34489 …34490
GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue.

GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary code by sending crafted serialized .NET when joining to a Multi-Server setup.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • gfi mailessentials
CVE-2025-2977
+2 in the same advisory: …2975 …2976
A vulnerability was found in GFI KerioConnect 10.0.6.

A vulnerability was found in GFI KerioConnect 10.0.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component PDF File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.1<1%
  • gfi kerio connect
CVE-2024-52875
CRLF Injection/Open Redirect in GFI Kerio Control Enables Reflected XSS and RCE

CVE-2024-52875 is an HTTP response splitting flaw (CWE-113) in GFI Kerio Control 9.2.5 through 9.4.5, where the unauthenticated 'dest' GET parameter on the /nonauth/addCertException.cs, /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is placed into the Location header of a 302 redirect without sanitization. An attacker triggers it by convincing a user to open a crafted link containing CRLF sequences in the 'dest' parameter, which yields open redirects, HTTP response splitting, and reflected cross-site scripting. Beyond XSS, the flaw can be escalated to remote command execution by abusing the upgrade feature in the Kerio Control admin interface, as demonstrated in published research. Any organization running Kerio Control 9.2.5 through 9.4.5 — typically SMB firewall/VPN gateway appliances or virtual appliances — is affected. No confirmed in-the-wild exploitation is documented and the issue is not in CISA KEV, but two public proofs of concept exist and a 29.6% EPSS score (98th percentile) indicates a high likelihood of exploitation attempts within 30 days.

Do: Upgrade Kerio Control to a release later than 9.4.5, which resolves this issue. Until patched, minimize internet exposure of the Kerio Control admin and /nonauth/ pages (restrict management access to trusted networks) and treat any emailed or linked URLs pointing to the appliance's addCertException.cs, guestConfirm.cs or expiration.cs pages as untrusted. Monitor the appliance for unexpected upgrade activity or admin-interface sessions, since the known escalation path runs through the admin upgrade feature.

8.830% PoC ×2
  • GFI Kerio Control 9.2.5 through 9.4.5
large≈ tens of thousands of internet-exposed Kerio Control instances (estimated, no official install base in source data)
CVE-2024-11948
+2 in the same advisory: …11949 …11947
GFI Archiver Telerik Web UI Remote Code Execution Vulnerability.

GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from the use of a vulnerable version of Telerik Web UI. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-24041.

NVD description · AI analysis pending
9.8
group max
1%
  • gfi archiver
CVE-2023-3835
A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0.

A vulnerability classified as problematic has been found in Bug Finder MineStack 1.0. This affects an unknown part of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235161 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.1<1%
  • bugfinder minestack
CVE-2023-3834
A vulnerability was found in Bug Finder EX-RATE 1.0.

A vulnerability was found in Bug Finder EX-RATE 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-235160. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.1<1%
  • bugfinder ex-rate
CVE-2023-3833
A vulnerability was found in Bug Finder Montage 1.0.

A vulnerability was found in Bug Finder Montage 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-235159. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.1<1%
  • bugfinder montage
CVE-2023-3832
A vulnerability was found in Bug Finder Wedding Wonders 1.0.

A vulnerability was found in Bug Finder Wedding Wonders 1.0. It has been classified as problematic. Affected is an unknown function of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. It is possible to launch the attack remotely. VDB-235158 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.1<1%
  • bugfinder wedding wonders
CVE-2023-3831
A vulnerability was found in Bug Finder Finounce 1.0 and classified as problematic.

A vulnerability was found in Bug Finder Finounce 1.0 and classified as problematic. This issue affects some unknown processing of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235157 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.4<1%
  • bugfinder finounce
CVE-2023-3830
A vulnerability was found in Bug Finder SASS BILLER 1.0.

A vulnerability was found in Bug Finder SASS BILLER 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /company/store. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The associated identifier of this vulnerability is VDB-235151. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.1<1%
  • bugfinder sass biller
CVE-2023-3829
A vulnerability was found in Bug Finder ICOGenie 1.0.

A vulnerability was found in Bug Finder ICOGenie 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/ticket/create of the component Support Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack can be initiated remotely. VDB-235150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.1<1%
  • bugfinder icogenie
CVE-2023-3828
+1 in the same advisory: …3827
A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0.

A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0. It has been classified as problematic. This affects an unknown part of the file /listplace/user/coverPhotoUpdate of the component Photo Handler. The manipulation of the argument user_cover_photo leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-235149 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.1<1%
  • bugfinder listplace directory listing platform
CVE-2023-3796
A vulnerability, which was classified as problematic, has been found in Bug Finder Foody Friend 1.0.

A vulnerability, which was classified as problematic, has been found in Bug Finder Foody Friend 1.0. Affected by this issue is some unknown functionality of the file /user/profile of the component Profile Picture Handler. The manipulation of the argument profile_picture leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-235064. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
8.8<1%
  • bugfinder foody friend