ZeroHour

Vulnerabilities

109 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-59928
Mistune is a Python Markdown parser with renderers and plugins.

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing denial of service through CPU exhaustion. This issue is fixed in version 3.3.0.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • mistune project mistune
CVE-2026-44899
+4 in the same advisory: …44898 …44897 …44708 …44896
Mistune is a Python Markdown parser with renderers and plugins.

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^\d+(?:\.\d*)?"). When the validated value is not a plain integer, render_block_image() inserts it directly into a style="width:...;" or style="height:...;" attribute. Because the value was accepted by the prefix-only regex, any CSS after the leading digits reaches the style= attribute verbatim and without escaping. This vulnerability is fixed in 3.2.1.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • mistune project mistune
CVE-2026-45321
Supply chain compromise: credential-stealing code in 42 @tanstack/* npm packages

CVE-2026-45321 is a supply chain compromise in which 84 malicious versions across 42 @tanstack/* npm packages (including @tanstack/react-router, @tanstack/react-start, @tanstack/history, and related router/start packages) were published to the npm registry on 2026-05-11 between roughly 19:20 and 19:26 UTC, authenticated through TanStack's legitimate GitHub Actions OIDC trusted-publisher binding. The attacker chained three known weakness classes — a pull_request_target 'Pwn Request' misconfiguration, GitHub Actions cache poisoning across the fork-to-base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — allowing publication under a trusted identity without modifying the publish workflow. Each affected package received exactly two malicious versions carrying credential-stealing malware, so developers, CI pipelines, or downstream builds that installed them could have npm, GitHub, and cloud credentials extracted; related reporting (FBI, StepSecurity) links the campaign to stolen cloud credentials and a self-spreading 'Mini Shai-Hulud' worm that also hit packages in other ecosystems such as Mistral AI and Guardrails AI. Exposure is limited to consumers who installed the two malicious versions published per package during the exposure window; other users of these widely deployed libraries were not affected by the malicious publishes. Exploitation is confirmed in the wild: the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-27 with known ransomware use, and EPSS estimates a 2.3% probability of exploitation in the next 30 days (83rd percentile).

Do: Audit lockfiles and CI logs for the affected @tanstack/* packages' versions published during the 2026-05-11 ~19:20-19:26 UTC window; if found, reinstall from clean versions per the TanStack postmortem (tanstack.com/blog/npm-supply-chain-compromise-postmortem) and rotate exposed credentials (npm tokens, GitHub PATs/secrets, cloud keys), treating any cached CI artifacts as suspect. Apply mitigations per vendor instructions and CISA BOD 22-01 guidance for cloud services, or discontinue use if mitigations are unavailable, and remediate the underlying CI weaknesses (pull_request_target handling, Actions cache hygiene, and OIDC token handling) to prevent recurrence.

9.62% KEV ransomware PoC ×2
  • tanstack @tanstack/arktype-adapter
  • tanstack @tanstack/eslint-plugin-router
  • tanstack @tanstack/eslint-plugin-start
  • +9 more
large~100,000+ downstream installs/CI runs (estimate)
CVE-2026-36874
+2 in the same advisory: …36873 …36872
Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.

Sourcecodester Basic Library System v1.0 is vulnerable to SQL Injection in /librarysystem/load_student.php.

NVD description · AI analysis pending
2.7<1% PoC
  • razormist basic library system
CVE-2025-10617
A weakness has been identified in SourceCodester Online Polling System 1.0.

A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/positions.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.

NVD description · AI analysis pending
2.1<1%
  • razormist online polling system
CVE-2025-10082
+4 in the same advisory: …10078 …10077 …10076 …10075
A vulnerability has been found in SourceCodester Online Polling System 1.0.

A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument email leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.5
group max
<1% PoC
  • razormist online polling system
CVE-2025-9699
A vulnerability was detected in SourceCodester Online Polling System Code 1.0.

A vulnerability was detected in SourceCodester Online Polling System Code 1.0. This vulnerability affects unknown code of the file /admin/checklogin.php. The manipulation of the argument myusername results in sql injection. The attack may be performed from a remote location. The exploit is now public and may be used.

NVD description · AI analysis pending
5.5<1% PoC
  • razormist online polling system
CVE-2025-6477
+1 in the same advisory: …6475
A vulnerability was found in SourceCodester Student Result Management System 1.0.

A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/admin/system of the component System Settings Page. The manipulation of the argument School Name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
1.9<1% PoC
  • razormist student result management system
CVE-2025-5721
+2 in the same advisory: …5726 …5727
A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0.

A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/core/update_profile of the component Profile Setting Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
1.9<1% PoC ×2
  • razormist student result management system
CVE-2025-5649
A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0.

A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of the component Register Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9<1% PoC
  • razormist student result management system
CVE-2025-5412
A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1.

A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1. Affected is the function Login of the file src/mist/api/views.py of the component Authentication Endpoint. The manipulation of the argument return_to leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.7.2 is able to address this issue. The name of the patch is db10ecb62ac832c1ed4924556d167efb9bc07fad. It is recommended to upgrade the affected component.

NVD description · AI analysis pending
5.1<1% PoC
  • mist mist
CVE-2025-5409
+2 in the same advisory: …5410 …5411
A vulnerability was found in Mist Community Edition up to 4.7.1.

A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the function create_token of the file src/mist/api/auth/views.py of the component API Token Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.7.2 is able to address this issue. The identifier of the patch is db10ecb62ac832c1ed4924556d167efb9bc07fad. It is recommended to upgrade the affected component.

NVD description · AI analysis pending
6.9
group max
<1% PoC
  • mist mist
CVE-2025-5371
+1 in the same advisory: …5376
A vulnerability, which was classified as critical, has been found in SourceCodester Health Center Patient Record Management System 1.0.

A vulnerability, which was classified as critical, has been found in SourceCodester Health Center Patient Record Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9<1% PoC
  • razormist health center patient record management system
CVE-2025-5369
A vulnerability classified as critical has been found in SourceCodester PHP Display Username After Login 1.0.

A vulnerability classified as critical has been found in SourceCodester PHP Display Username After Login 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9<1% PoC
  • razormist display username after login
CVE-2025-5297
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0.

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file main.c. The manipulation of the argument laptopcompany/RAM/Processor leads to stack-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
4.8<1% PoC
  • razormist simple computer store system
CVE-2025-3763
A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0.

A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the function main of the component Password Handler. The manipulation of the argument s leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
4.8<1% PoC
  • razormist phone management system
CVE-2025-3728
A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0.

A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability affects the function Login. The manipulation of the argument uname leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
4.8<1% PoC
  • razormist simple hotel booking system
CVE-2025-1591
A vulnerability was found in SourceCodester Employee Management System 1.0.

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /department.php of the component Department Page. The manipulation of the argument Department Name leads to cross site scripting. The attack can be launched remotely.

NVD description · AI analysis pending
4.8<1%
  • razormist employee management system
CVE-2025-1587
A vulnerability was found in SourceCodester Telecom Billing Management System 1.0.

A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This issue affects the function addrecords of the file main.cpp of the component Add New Record. The manipulation of the argument name/phonenumber leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

NVD description · AI analysis pending
4.8<1% PoC
  • razormist telecom billing management system
CVE-2024-13899
The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input v

The Mambo Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input via the $data parameter in the fImportMenu function. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

NVD description · AI analysis pending
7.2<1%
  • misterpah mambo joomla importer
CVE-2024-12354
+2 in the same advisory: …12355 …12353
A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0.

A vulnerability, which was classified as critical, was found in SourceCodester Phone Contact Manager System 1.0. Affected is the function UserInterface::MenuDisplayStart of the component User Menu. The manipulation leads to buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
4.8<1% PoC
  • razormist phone contact manager system
CVE-2024-11262
+1 in the same advisory: …11261
A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical.

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as critical. Affected by this vulnerability is the function main of the component View All Student Marks. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
4.8<1% PoC
  • razormist student record management system
CVE-2024-11097
A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic.

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Main Menu. The manipulation leads to infinite loop. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
4.8<1% PoC
  • razormist student record management system