ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-27925
+2 in the same advisory: …27924 …27926
Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

NVD description · AI analysis pending
9.8
group max
<1%
  • nintex automation
CVE-2024-13632
The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-

The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

NVD description · AI analysis pending
7.1<1% PoC
  • sprintexperts wp extra fields
CVE-2022-38167
The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS.

The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS.

NVD description · AI analysis pending
6.1<1%
  • nintex workflow
CVE-2018-12529
+1 in the same advisory: …12528
An issue was discovered on Intex N150 devices.

An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings.

NVD description · AI analysis pending
8.8
group max
<1% PoC ×3
  • intex n150 firmware