ZeroHour

Vulnerabilities

17 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-22187
+1 in the same advisory: …22186
Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image process

Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing. The loci.formats.Memoizer class automatically loads and deserializes memo files associated with images without validation, integrity checks, or trust enforcement. An attacker who can supply a crafted .bfmemo file alongside an image can trigger deserialization of untrusted data, which may result in denial of service, logic manipulation, or potentially remote code execution in environments where suitable gadget chains are present on the classpath.

NVD description · AI analysis pending
6.8
group max
<1%
  • openmicroscopy bio-formats
CVE-2025-54791
OMERO.web provides a web based client and plugin infrastructure.

OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using the Forgot Password option in OMERO.web, the error message displayed on the Web page can disclose information about the user. This issue has been patched in version 5.29.2. A workaround involves disabling the Forgot password option in OMERO.web using the omero.web.show_forgot_password configuration property.

NVD description · AI analysis pending
5.3<1%
  • openmicroscopy omero-web
CVE-2024-35180
OMERO.web provides a web based client and plugin infrastructure.

OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `callback` parameter that can be passed to various OMERO.web endpoints that have JSONP enabled. This vulnerability has been patched in version 5.26.0.

NVD description · AI analysis pending
6.1<1%
  • openmicroscopy omero-web
CVE-2021-41132
OMERO.web provides a web based client and plugin infrastructure.

OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitization through HTML escaping. Due to the lack of sanitization and use of ``jQuery.html()``, there are a whole host of cross-site scripting possibilities with specially crafted input to a variety of fields. This issue is patched in version 5.11.0. There are no known workarounds aside from upgrading.

NVD description · AI analysis pending
6.11%
  • openmicroscopy omero-figure
  • openmicroscopy omero-web
CVE-2021-21376
+1 in the same advisory: …21377
OMERO.web is open source Django-based software for managing microscopy imaging.

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the current user such as their id, name and the groups they are in, and these are available on the main webclient pages. This represents an information exposure vulnerability. Some additional information being loaded is not used by the webclient and is being removed in this release. This is fixed in version 5.9.0.

NVD description · AI analysis pending
6.5
group max
1%
  • openmicroscopy omero.web
CVE-2019-16244
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.

OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.

NVD description · AI analysis pending
9.81%
  • openmicroscopy omero.server
CVE-2020-7932
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters.

OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a user into clicking a malicious link in OMERO.web, the information in the query parameters may be exposed in the Referer header seen by the target. Information in the URL path such as object IDs may also be exposed.

NVD description · AI analysis pending
5.7<1%
  • openmicroscopy omero.web
CVE-2019-16245
+1 in the same advisory: …6752
OMERO before 5.6.1 makes the details of each user available to all users.

OMERO before 5.6.1 makes the details of each user available to all users.

NVD description · AI analysis pending
5.3
group max
<1%
  • openmicroscopy omero
CVE-2019-9944
+1 in the same advisory: …9943
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions.

In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions restrictions. This occurs because the Bio-Formats feature allows an image file to have embedded pathnames.

NVD description · AI analysis pending
7.51%
  • openmicroscopy omero.server
CVE-2018-1000633
+2 in the same advisory: …1000634 …1000635
The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the login form and change p

The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the login form and change password form that can result in User's password being revealed. Attacker can log in as that user. This attack appear to be exploitable via an attacker reading the web server log. This vulnerability appears to have been fixed in 5.4.7.

NVD description · AI analysis pending
7.2
group max
1%
  • openmicroscopy omero
CVE-2017-1000438
In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, t

In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.

NVD description · AI analysis pending
8.3<1%
  • openmicroscopy omero