ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-33035
XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

NVD description · AI analysis pending
7.8<1% PoC
  • netsarang xlpd
CVE-2022-27966
Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

NVD description · AI analysis pending
6.5<1% PoC
  • netsarang xshell
CVE-2022-27965
Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

NVD description · AI analysis pending
6.5<1% PoC
  • netsarang xlpd
CVE-2022-27964
Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

NVD description · AI analysis pending
6.5<1% PoC
  • netsarang xmanager
CVE-2022-27963
Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file.

NVD description · AI analysis pending
6.5<1% PoC
  • netsarang xftp
CVE-2021-42095
Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.

Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.

NVD description · AI analysis pending
7.5<1%
  • netsarang xshell
CVE-2021-37326
NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.

NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.

NVD description · AI analysis pending
5.3<1%
  • netsarang xshell
CVE-2019-17320
NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an atta

NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

NVD description · AI analysis pending
9.82%
  • netsarang xftp