ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-2267
+1 in the same advisory: …2556
The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on

The Mailchimp for WooCommerce WordPress plugin before 2.7.1 has an AJAX action that allows any logged in users (such as subscriber) to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it can be used to scan private network for example

NVD description · AI analysis pending
4.3
group max
<1% PoC
  • mailchimp mailchimp for woocommerce
CVE-2021-27352
An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.

An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.

NVD description · AI analysis pending
5.4<1% PoC ×2
  • ilch ilch cms
CVE-2019-20524
+2 in the same advisory: …20523 …20522
ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.

ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • ilch ilch cms
CVE-2019-17046
+1 in the same advisory: …17045
Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.

Ilch 2.1.22 allows remote code execution because php is listed under "Allowed files" on the index.php/admin/media/settings/index page.

NVD description · AI analysis pending
7.2
group max
4% PoC
  • ilch ilch cms