ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-37762
+3 in the same advisory: …37765 …37763 …37764
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

NVD description · AI analysis pending
9.9
group max
1% PoC
  • machform machform
CVE-2021-20102
+4 in the same advisory: …20104 …20105 …20101 …20103
Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.

Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.

NVD description · AI analysis pending
8.8
group max
<1%
  • machform machform
CVE-2018-6411
+2 in the same advisory: …6410 …6409
An issue was discovered in Appnitro MachForm before 4.2.3.

An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.

NVD description · AI analysis pending
9.8
group max
6% PoC ×2
  • machform machform