ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-27416
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users accou

Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.

NVD description · AI analysis pending
9.82%
  • mahadiscom mahavitaran
CVE-2021-41716
+1 in the same advisory: …27413
Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

NVD description · AI analysis pending
9.8
group max
1% PoC
  • mahadiscom mahavitaran
CVE-2020-27414
Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters.

Mahavitaran android application 7.50 and prior transmit sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header, MITM or browser history.

NVD description · AI analysis pending
5.9<1% PoC
  • mahadiscom mahavitaran