ZeroHour

Vulnerabilities

20 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-7937
+1 in the same advisory: …7936
A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0.

A vulnerability classified as critical was found in itsourcecode Project Expense Monitoring System 1.0. This vulnerability affects unknown code of the file printtransfer.php. The manipulation of the argument transfer_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.3<1% PoC
  • project expense monitoring system project project expense monitoring system
CVE-2024-7933
+2 in the same advisory: …7934 …7935
A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0.

A vulnerability was found in itsourcecode Project Expense Monitoring System 1.0. It has been classified as critical. Affected is an unknown function of the file login1.php of the component Backend Login. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9
group max
<1% PoC
  • project expense monitoring system project project expense monitoring system
CVE-2023-5827
A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2.

A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-243717 was assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1% PoC
  • cti monitoring and early warning system project cti monitoring and early warning system
CVE-2023-1480
+1 in the same advisory: …1481
A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0.

A vulnerability classified as critical was found in SourceCodester Monitoring of Students Cyber Accounts System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument un leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223363.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • monitoring of students cyber accounts system project monitoring of students cyber accounts system
CVE-2022-37298
Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control.

Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server.

NVD description · AI analysis pending
9.82%
  • shinken-monitoring shinken monitoring
CVE-2022-31202
+1 in the same advisory: …31201
The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.

The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via export or man.tcl.

NVD description · AI analysis pending
6.5
group max
1% PoC
  • monitoringsoft softguard web
CVE-2021-4035
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor.

A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of tinymce editor. In order to exploit this vulnerability, the attackers needs an account with enough privileges to view and edit reports.

NVD description · AI analysis pending
4.8<1%
  • wocu-monitoring wocu monitoring
CVE-2021-45043
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.

HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.

NVD description · AI analysis pending
7.533% PoC ×2
  • hd-network real-time monitoring system project hd-network real-time monitoring system
CVE-2020-5623
NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary

NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

NVD description · AI analysis pending
6.1<1%
  • nitori nitori
CVE-2020-13118
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22.

An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.

NVD description · AI analysis pending
9.84% PoC ×2
  • mikrotik-router-monitoring-system project mikrotik-router-monitoring-system
CVE-2018-18798
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=vie

Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.

NVD description · AI analysis pending
9.83% PoC ×2
  • school attendance monitoring system project school attendance monitoring system
CVE-2018-18806
School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.

School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.

NVD description · AI analysis pending
9.82% PoC
  • school equipment monitoring system project school equipment monitoring system
CVE-2018-18799
+1 in the same advisory: …18797
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.

School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.

NVD description · AI analysis pending
8.82% PoC ×2
  • school attendance monitoring system project school attendance monitoring system
CVE-2017-6188
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled.

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.

NVD description · AI analysis pending
5.5<1%
  • munin-monitoring munin
  • munin-monitoring debian linux