ZeroHour

Vulnerabilities

28 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-55055
+4 in the same advisory: …55058 …55057 …55059 …55056
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

NVD description · AI analysis pending
9.8
group max
<1%
  • maxum rumpus
CVE-2022-46368
+4 in the same advisory: …46367 …46370 …39187 …46369
Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.

Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.

NVD description · AI analysis pending
8.8
group max
<1%
  • maxum rumpus
CVE-2020-27575
+2 in the same advisory: …27574 …27576
Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability.

Maxum Rumpus 8.2.13 and 8.2.14 is affected by a command injection vulnerability. The web administration contains functionality in which administrators are able to manage users. The edit users form contains a parameter vulnerable to command injection due to insufficient validation.

NVD description · AI analysis pending
8.8
group max
3% PoC
  • maxum rumpus
CVE-2020-12737
An issue was discovered in Maxum Rumpus before 8.2.12 on macOS.

An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using double escaped characters, enabling read access to arbitrary files on the server.

NVD description · AI analysis pending
6.51% PoC
  • maxum rumpus
CVE-2019-19664
A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1.

A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server Web settings at RAPR/WebSettingsGeneralSet.html.

NVD description · AI analysis pending
7.1
group max
<1%
  • maxum rumpus ftp
CVE-2019-19659
+3 in the same advisory: …19663 …19660 …19665
A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1.

A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details, and escalate privileges via RAPR/DefineUsersSet.html.

NVD description · AI analysis pending
8.8
group max
<1%
  • maxum rumpus
CVE-2020-8514
An issue was discovered in Rumpus 8.2.10 on macOS.

An issue was discovered in Rumpus 8.2.10 on macOS. By crafting a directory name, it is possible to activate JavaScript in the context of the web application after invoking the rename folder functionality.

NVD description · AI analysis pending
6.1<1% PoC
  • maxum rumpus
CVE-2019-19368
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1.

A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker can exploit it by sending a crafted link to end users and can execute arbitrary Javascripts

NVD description · AI analysis pending
6.126% PoC ×2
  • maxum rumpus