ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-25589
RedisBloom is a probabilistic data structures module for Redis.

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This issue is fixed in version 2.8.20.

NVD description · AI analysis pending
7.71%
  • redisbloom redisbloom
CVE-2026-32722
Memray is a memory profiler for Python.

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue.

NVD description · AI analysis pending
6.1<1% PoC
  • bloomberg memray
CVE-2025-36520
+4 in the same advisory: …46354 …48498 …35966 …36512
A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg Comdb2 8.1.

A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg Comdb2 8.1. A specially crafted network packets can lead to a denial of service. An attacker can send packets to trigger this vulnerability.

NVD description · AI analysis pending
7.5<1% PoC
  • bloomberg comdb2
CVE-2024-1297
Loomio version 2.22.0 allows executing arbitrary commands on the server.

Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.

NVD description · AI analysis pending
7.23% PoC
  • loomio loomio
CVE-2024-23742
An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments sett

An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor disputes this because it requires local access to a victim's machine.

NVD description · AI analysis pending
9.82%
  • loom loom
CVE-2023-0247
Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1.

Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1.

NVD description · AI analysis pending
7.8<1% PoC
  • bloom project bloom
CVE-2020-14987
+2 in the same advisory: …14989 …14988
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2.

An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. An attacker must use an AST transforming annotation such as @Grab.

NVD description · AI analysis pending
7.2
group max
4% PoC
  • bloomreach experience manager
CVE-2019-14432
Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript

Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code execution from either malicious JavaScript in a browser or hosts on the same network, during periods in which a user is recording a video with the application. The same attack vector can be used to crash the application at any time.

NVD description · AI analysis pending
8.82%
  • loom loom
CVE-2017-11594
Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sa

Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.

NVD description · AI analysis pending
5.41% PoC
  • loomio loomio