ZeroHour

Vulnerabilities

23 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34965
SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.

SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.

NVD description · AI analysis pending
5.3<1% PoC
  • sspanel-uim project sspanel-uim
CVE-2023-27781
jpegoptim v1.5.2 was discovered to contain a heap overflow in the optimize function at jpegoptim.c.

jpegoptim v1.5.2 was discovered to contain a heap overflow in the optimize function at jpegoptim.c.

NVD description · AI analysis pending
7.8<1% PoC
  • jpegoptim project jpegoptim
CVE-2022-4523
A vulnerability, which was classified as problematic, has been found in vexim2.

A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processing. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is 21c0a60d12e9d587f905cd084b2c70f9b1592065. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215903.

NVD description · AI analysis pending
6.1<1%
  • virtual exim project virtual exim 2
CVE-2022-37623
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.

Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.

NVD description · AI analysis pending
9.81% PoC ×2
  • browserify-shim project browserify-shim
CVE-2022-37621
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.

Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.

NVD description · AI analysis pending
9.81%
  • browserify-shim project browserify-shim
CVE-2022-37617
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.

Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.

NVD description · AI analysis pending
9.81% PoC ×2
  • browserify-shim project browserify-shim
CVE-2022-32325
JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c.

JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c.

NVD description · AI analysis pending
6.5<1% PoC
  • jpegoptim project jpegoptim
  • jpegoptim project fedora
CVE-2021-37778
There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution.

There is a buffer overflow in gps-sdr-sim v1.0 when parsing long command line parameters, which can lead to DoS or code execution.

NVD description · AI analysis pending
9.82% PoC
  • gps-sdr-sim project gps-sdr-sim
CVE-2021-28832
VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.

VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.

NVD description · AI analysis pending
7.81%
  • vim project vim
CVE-2020-36204
An issue was discovered in the im crate through 2020-11-09 for Rust.

An issue was discovered in the im crate through 2020-11-09 for Rust. Because TreeFocus does not have bounds on its Send trait or Sync trait, a data race can occur.

NVD description · AI analysis pending
4.7<1% PoC
  • im project im
CVE-2020-35284
Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5

Flamingo (aka FlamingoIM) through 2020-09-29 allows ../ directory traversal because the only ostensibly unpredictable part of a file-transfer request is an MD5 computation; however, this computation occurs on the client side, and the computation details can be easily determined because the product's source code is available.

NVD description · AI analysis pending
7.52% PoC
  • flamingoim project flamingoim
CVE-2020-7753
All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().

NVD description · AI analysis pending
7.54% PoC ×2
  • trim project trim
CVE-2019-19920
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule.

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

NVD description · AI analysis pending
8.83%
  • sa-exim project sa-exim
  • sa-exim project ubuntu linux
  • sa-exim project debian linux
CVE-2019-12240
The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.

The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php.

NVD description · AI analysis pending
9.82% PoC
  • virim project virim
CVE-2019-7692
install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in t

install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs function that creates a .php file in the public folder.

NVD description · AI analysis pending
9.82% PoC
  • cim project cim
CVE-2018-20614
public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.

public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.

NVD description · AI analysis pending
7.51% PoC
  • cim project cim
CVE-2016-10692
haxeshim haxe shim to deal with coexisting versions.

haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

NVD description · AI analysis pending
8.13%
  • haxeshim project haxeshim
CVE-2016-10675
libsbmlsim is a module that installs linux binaries for libsbmlsim libsbmlsim downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.

libsbmlsim is a module that installs linux binaries for libsbmlsim libsbmlsim downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

NVD description · AI analysis pending
8.12%
  • libsbmlsim project libsbmlsim
CVE-2016-10596
imageoptim is a Node.js wrapper for some images compression algorithms.

imageoptim is a Node.js wrapper for some images compression algorithms. imageoptim downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested tarball with an attacker controlled tarball if the attacker is on the network or positioned in between the user and the remote server.

NVD description · AI analysis pending
8.11%
  • imageoptim project imageoptim
CVE-2018-11416
jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (applicat

jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

NVD description · AI analysis pending
8.82%
  • jpegoptim project jpegoptim
CVE-2018-6644
SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI.

SBLIM Small Footprint CIM Broker (SFCB) 1.4.9 has a null pointer (DoS) vulnerability via a crafted POST request to the /cimom URI.

NVD description · AI analysis pending
7.52% PoC
  • sblim project small footprint cim broker
CVE-2017-10975
Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is

Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in an upload notification and in the myfiles component, if the attacker can convince the victim to proceed with an upload despite the appearance of an XSS payload in the filename.

NVD description · AI analysis pending
6.1<1% PoC
  • lutim project lutim
CVE-2017-6877
Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script.

Cross-site scripting (XSS) vulnerability in SVG file handling in Lutim 0.7.1 and earlier allows remote attackers to inject arbitrary web script.

NVD description · AI analysis pending
6.1<1%
  • lutim project lutim