ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-3776
The parameter used in the login page of Netvision airPASS is not properly filtered for user input.

The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.

NVD description · AI analysis pending
6.1<1%
  • netvision airpass
CVE-2023-48383
NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL.

NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

NVD description · AI analysis pending
7.5<1%
  • netvision airpass