ZeroHour

Vulnerabilities

26 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-10768
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing.

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

NVD description · AI analysis pending
9.82%
  • localgovdrupal localgov workflows
CVE-2026-29780
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information.

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to version 2.0.1, the official example script examples/recursively_extract_attachments.py contains a path traversal vulnerability that allows arbitrary file write outside the intended output directory. Attachment filenames extracted from parsed emails are directly used to construct output file paths without any sanitization, allowing an attacker-controlled filename to escape the target directory. This issue has been patched in version 2.0.1.

NVD description · AI analysis pending
5.5<1% PoC
  • govcert.lu eml parser
CVE-2025-28200
+3 in the same advisory: …28203 …28202 …28201
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.

Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac address.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • govicture rx1800 firmware
CVE-2023-41610
+2 in the same advisory: …41612 …41611
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.

Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • govicture pc420 firmware
CVE-2024-22048
govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability.

govuk_tech_docs versions from 2.0.2 to before 3.3.1 are vulnerable to a cross-site scripting vulnerability. Malicious JavaScript may be executed in the user's browser if a malicious search result is displayed on the search page.

NVD description · AI analysis pending
6.1<1%
  • gov.uk govuk tech docs
CVE-2023-6341
Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifier

Catalis (previously Icon Software) CMS360 allows a remote, unauthenticated attacker to view sensitive court documents by modifying document and other identifiers in URLs. The impact varies based on the intention and configuration of a specific CMS360 installation.

NVD description · AI analysis pending
5.3<1%
  • catalisgov cms360
CVE-2023-47655
Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi ANAC XML Bandi di Gara.This issue affects ANAC XML Bandi di Gara:

Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi ANAC XML Bandi di Gara.This issue affects ANAC XML Bandi di Gara: from n/a through 7.5.

NVD description · AI analysis pending
8.8<1%
  • wpgov anac xml bandi di gara
CVE-2023-45956
An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.

An issue discovered in Govee LED Strip v3.00.42 allows attackers to cause a denial of service via crafted Move and MoveWithOnoff commands.

NVD description · AI analysis pending
7.5<1%
  • govee led strip firmware
CVE-2023-44689
e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to im

e-Gov Client Application (Windows version) versions prior to 2.1.1.0 and e-Gov Client Application (macOS version) versions prior to 1.1.1.0 are vulnerable to improper authorization in handler for custom URL scheme. A crafted URL may direct the product to access an arbitrary website. As a result, the user may become a victim of a phishing attack.

NVD description · AI analysis pending
4.3<1%
  • e-gov e-gov
CVE-2023-42189
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42,

Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.

NVD description · AI analysis pending
7.5<1%
  • tapo mini smart wi-fi plug firmware
  • tapo lightstrip firmware
  • tapo led strip firmware
  • +1 more
CVE-2023-3612
Govee Home app has unprotected access to WebView component which can be opened by any app on the device.

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

NVD description · AI analysis pending
8.8<1%
  • govee home
CVE-2022-31215
In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation.

In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules for a time period of up to 30 seconds. This affects Goverlan Reach Console before 10.5.1, Reach Server before 3.70.1, and Reach Client Agents before 10.1.11.

NVD description · AI analysis pending
6.51% PoC
  • goverlan client agent
  • goverlan reach console
  • goverlan reach server
CVE-2021-43283
+2 in the same advisory: …43284 …43282
An issue was discovered on Victure WR1200 devices through 1.0.3.

An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges. This occurs in the ping and traceroute features. An attacker would thus be able to use this vulnerability to open a reverse shell on the device with root privileges.

NVD description · AI analysis pending
8.8
group max
5% PoC ×2
  • govicture wr1200 firmware
CVE-2020-15744
Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target de

Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target device. This issue affects: Victure PC420 firmware version 1.2.2 and prior versions.

NVD description · AI analysis pending
9.81%
  • govicture pc420 firmware
CVE-2021-34682
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.

Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.

NVD description · AI analysis pending
3.7<1% PoC
  • gov imposto de renda da pessoa fisica 2021
CVE-2020-12717
The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Blu

The COVIDSafe (Australia) app 1.0 and 1.1 for iOS allows a remote attacker to crash the app, and consequently interfere with COVID-19 contact tracing, via a Bluetooth advertisement containing manufacturer data that is too short. This occurs because of an erroneous OpenTrace manuData.subdata call. The ABTraceTogether (Alberta), ProteGO (Poland), and TraceTogether (Singapore) apps were also affected.

NVD description · AI analysis pending
6.51%
  • alberta abtracetogether
  • alberta protego safe
  • alberta covidsafe
  • +1 more
CVE-2019-20456
Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Comm

Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

NVD description · AI analysis pending
7.8<1%
  • goverlan client agent
  • goverlan reach console
  • goverlan reach server
CVE-2019-15940
Victure PC530 devices allow unauthenticated TELNET access as root.

Victure PC530 devices allow unauthenticated TELNET access as root.

NVD description · AI analysis pending
9.82% PoC
  • govicture pc530 firmware
CVE-2019-15569
HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.

HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.

NVD description · AI analysis pending
9.81%
  • gov ccd-data-store-api