ZeroHour

Vulnerabilities

54 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-44373
+1 in the same advisory: …44372
Nitro is a next generation server toolkit.

Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by sending percent-encoded path traversal (..%2f) in the URL, causing Nitro to forward a request that the upstream resolved outside the configured scope. This vulnerability is fixed in 3.0.260429-beta.

NVD description · AI analysis pending
5.3<1%
  • nitro nitro
CVE-2025-69627
+2 in the same advisory: …66769 …69624
Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc().

Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated and then freed prematurely, after which the freed pointer is still passed into UI and logging helper functions. Because the freed memory region may contain unpredictable heap data or remnants of attacker-controlled JavaScript strings, downstream routines such as wcscmp() may process invalid or stale pointers. This can result in access violations and non-deterministic crashes.

NVD description · AI analysis pending
8.4
group max
<1%
  • gonitro nitro pdf pro
CVE-2025-67825
An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34.

An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subject. This could allow a document to present inconsistent signer details. The display logic was updated to ensure signer information consistently reflects the verified certificate identity.

NVD description · AI analysis pending
5.5<1%
  • gonitro nitro pdf pro
CVE-2024-43922
Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc.

Improper Control of Generation of Code ('Code Injection') vulnerability in NitroPack Inc. NitroPack allows Code Injection.This issue affects NitroPack: from n/a through 1.16.7.

NVD description · AI analysis pending
9.8<1%
  • nitropack nitropack
CVE-2024-38435
Unitronics Vision PLC – CWE-703:

Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service

NVD description · AI analysis pending
7.5<1%
  • unitronics visilogic
CVE-2024-27768
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22:

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

NVD description · AI analysis pending
9.8
group max
<1%
  • unitronics unilogic
CVE-2023-52121
Cross-Site Request Forgery (CSRF) vulnerability in NitroPack Inc.

Cross-Site Request Forgery (CSRF) vulnerability in NitroPack Inc. NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images.This issue affects NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images: from n/a through 1.10.2.

NVD description · AI analysis pending
8.8<1%
  • nitropack nitropack
CVE-2023-6448
Default Admin Password in Unitronics Vision PLC and HMI (VisiLogic < 9.9.00)

Unitronics VisiLogic software before version 9.9.00, which runs on Vision and Samba PLCs and HMIs, ships with a default administrative password that many deployments never change. An unauthenticated attacker with network access to the device can authenticate with these default credentials, requiring no exploit development or user interaction. A successful login grants full administrative control of the PLC/HMI, allowing the attacker to modify configuration and program logic and potentially disrupt the physical process (such as water treatment and distribution) the device controls. Any deployment of the listed Unitronics Vision models (and, per CISA's description, Samba devices) running VisiLogic prior to 9.9.00 is affected, with the greatest risk for units directly exposed to the internet at utilities and small industrial sites. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-11, indicating confirmed exploitation in the wild, and CISA has urged water facilities to secure their Unitronics PLCs.

Do: Upgrade to VisiLogic 9.9.00 or later and set a strong, unique administrative password on every Vision/Samba device. Restrict network access to affected devices (firewall or VPN rather than direct internet exposure) and review device logs for unexpected administrative logins. Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

9.82% KEV
  • Unitronics Vision130 PLC/HMI VisiLogic before 9.9.00
  • Unitronics Vision230 PLC/HMI VisiLogic before 9.9.00
  • Unitronics Vision280 PLC/HMI VisiLogic before 9.9.00
  • +9 more
large~tens of thousands of deployed devices (subset of the vendor-cited installed base of hundreds of thousands of controllers; likely only a low-thousands subset…
CVE-2023-2003
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded

Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.

NVD description · AI analysis pending
9.8<1%
  • unitronics vision1210 firmware
CVE-2023-22686
Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions.

Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions.

NVD description · AI analysis pending
8.8<1%
  • trinitronic nice paypal button lite
CVE-2021-21796
+1 in the same advisory: …21797
An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF.

An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-free vulnerability, which can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger this vulnerability.

NVD description · AI analysis pending
7.816% PoC
  • gonitro nitro pro
CVE-2021-21798
An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF.

An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, resulting in the application dereferencing a stale pointer. This can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger the vulnerability.

NVD description · AI analysis pending
7.816% PoC
  • gonitro nitro pro
CVE-2021-3543
A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor.

A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.

NVD description · AI analysis pending
6.7<1%
  • nitro enclaves project nitro enclaves
  • nitro enclaves project enterprise linux
  • nitro enclaves project fedora
CVE-2020-27208
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token.

The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade the RDP level and access secrets such as private ECC keys from SRAM via the debug interface.

NVD description · AI analysis pending
6.8<1% PoC
  • solokeys solo firmware
  • solokeys somu firmware
  • solokeys fido2 firmware
CVE-2020-12061
An issue was discovered in Nitrokey FIDO U2F firmware through 1.1.

An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credentials in plain. This allows an adversary to eavesdrop the communication and derive the secrets stored in the microcontroller. As a result, the attacker is able to arbitrarily manipulate the firmware of the microcontroller.

NVD description · AI analysis pending
9.82% PoC
  • nitrokey fido u2f firmware
CVE-2018-18689
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures.

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.

NVD description · AI analysis pending
5.34%
  • avanquest expert pdf ultimate
  • avanquest pdf experte ultimate
  • avanquest foxit reader
  • +1 more
CVE-2018-18688
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures.

The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability exists in multiple products. When an attacker uses the Incremental Saving feature to add pages or annotations, Body Updates are displayed to the user without any action by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects LibreOffice, Master PDF Editor, Nitro Pro, Nitro Reader, Nuance Power PDF Standard, PDF Editor 6 Pro, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, Perfect PDF 10 Premium, and Perfect PDF Reader.

NVD description · AI analysis pending
5.31%
  • code-industry master pdf editor
  • code-industry foxit reader
  • code-industry phantompdf
  • +1 more
CVE-2020-6113
+3 in the same advisory: …6116 …6112 …6115
An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference

An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When processing an object stream from a PDF document, the application will perform a calculation in order to allocate memory for the list of indirect objects. Due to an error when calculating this size, an integer overflow may occur which can result in an undersized buffer being allocated. Later when initializing this buffer, the application can write outside its bounds which can cause a memory corruption that can lead to code execution. A specially crafted document can be delivered to a victim in order to trigger this vulnerability.

NVD description · AI analysis pending
7.865% PoC
  • gonitro nitro pro
CVE-2020-6146
An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300.

An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from an 'ICCBased' colorspace, the application will read a length from the file and use it as a loop sentinel when writing data into the member of an object. Due to the object member being a buffer of a static size allocated on the heap, this can result in a heap-based buffer overflow. A specially crafted document must be loaded by a victim in order to trigger this vulnerability.

NVD description · AI analysis pending
8.876% PoC
  • gonitro nitro pro
CVE-2020-6074
+2 in the same advisory: …6092 …6093
An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155.

An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

NVD description · AI analysis pending
8.8
group max
41% PoC
  • gonitro nitro pro
CVE-2020-10223
+1 in the same advisory: …10222
npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_mark

npdf.dll in Nitro Pro before 13.13.2.242 is vulnerable to JBIG2Decode CNxJBIG2DecodeStream Heap Corruption at npdf!CAPPDAnnotHandlerUtils::create_popup_for_markup+0x12fbe via a crafted PDF document.

NVD description · AI analysis pending
8.12% PoC ×2
  • gonitro nitro pro
CVE-2019-19819
The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereferenc

The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x90ec NULL Pointer Dereference via crafted Unicode content.

NVD description · AI analysis pending
5.51% PoC ×2
  • gonitro nitropdf
CVE-2019-19817
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via c

The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0x2e8a Out-of-Bounds Read via crafted Unicode content.

NVD description · AI analysis pending
5.51% PoC ×2
  • gonitro nitro free pdf reader
CVE-2019-19818
The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via c

The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDestroyData2+0xa08a Out-of-Bounds Read via crafted Unicode content.

NVD description · AI analysis pending
5.51% PoC ×2
  • gonitro nitro free pdf reader
CVE-2019-18958
Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed.

NVD description · AI analysis pending
7.8<1% PoC
  • gonitro nitro pro
CVE-2019-5050
A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522.

A specifically crafted PDF file can lead to a heap corruption when opened in NitroPDF 12.12.1.522. With careful memory manipulation, this can lead to arbitrary code execution. In order to trigger this vulnerability, the victim would need to open the malicious file.

NVD description · AI analysis pending
7.83% PoC
  • gonitro nitropdf
CVE-2017-7442
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.

Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.

NVD description · AI analysis pending
8.841% PoC
  • gonitro nitro pro
CVE-2017-7950
Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.

Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.

NVD description · AI analysis pending
5.52%
  • gonitro nitro pro