ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-41254
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

NVD description · AI analysis pending
7.5<1% PoC
  • littlecms little cms
CVE-2025-3978
+1 in the same advisory: …3979
A vulnerability was found in dazhouda lecms 3.0.3.

A vulnerability was found in dazhouda lecms 3.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/view/default/user_set.htm. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • lecms lecms
CVE-2023-2420
A vulnerability was found in MLECMS 3.0.

A vulnerability was found in MLECMS 3.0. It has been rated as critical. This issue affects the function get_url in the library /upload/inc/lib/admin of the file upload\inc\include\common.func.php. The manipulation of the argument $_SERVER['REQUEST_URI'] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227717 was assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1% PoC
  • mlecms mlecms
CVE-2020-28063
+1 in the same advisory: …20092
A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.

A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.

NVD description · AI analysis pending
9.81% PoC
  • articlecms project articlecms
CVE-2019-8408
OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.

OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice.

NVD description · AI analysis pending
4.91% PoC
  • onefilecms onefilecms
CVE-2018-19469
ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.

ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • articlecms project articlecms
CVE-2018-16435
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overfl

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

NVD description · AI analysis pending
5.52% PoC
  • littlecms little cms color engine
  • littlecms ubuntu linux
  • littlecms enterprise linux desktop
  • +1 more
CVE-2018-13123
+1 in the same advisory: …13122
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=

onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file.

NVD description · AI analysis pending
9.8
group max
1%
  • onefilecms onefilecms
CVE-2018-12993
+2 in the same advisory: …12994 …12995
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.

onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • onefilecms onefilecms
CVE-2018-12339
ArticleCMS through 2017-02-19 has XSS via an "add an article" action.

ArticleCMS through 2017-02-19 has XSS via an "add an article" action.

NVD description · AI analysis pending
5.4<1% PoC
  • articlecms project articlecms
CVE-2018-11556
+1 in the same advisory: …11555
tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file.

tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”

NVD description · AI analysis pending
7.81%
  • littlecms little cms
CVE-2016-10165
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an i

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

NVD description · AI analysis pending
7.13%
  • littlecms little cms color engine
  • littlecms ubuntu linux
  • littlecms debian linux
  • +1 more