ZeroHour

Vulnerabilities

111 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-3278
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scriptin

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execute arbitrary JavaScript leading to unauthorized actions on behalf of the user.This issue affects ZENworks Service Desk: 25.2, 25.3.

NVD description · AI analysis pending
7.4<1%
  • opentext zenworks service desk
CVE-2025-12455
+2 in the same advisory: …12454 …12453
Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.

Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing. The vulnerability could lead to Password Brute Forcing in Vertica management console application.This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X.

NVD description · AI analysis pending
5.1<1%
  • opentext vertica
CVE-2026-3266
Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass.

Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2.

NVD description · AI analysis pending
8.3<1%
  • opentext filr
CVE-2026-1658
User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning.

User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning. The vulnerability could be exploited by a bad actor to inject manipulated text into the OpenText application, potentially misleading users. This issue affects Directory Services: from 20.4.1 through 25.2.

NVD description · AI analysis pending
5.3<1%
  • opentext directory services
CVE-2025-9208
+2 in the same advisory: …13672 …13671
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to compromise user sessions and data. This issue affects Web Site Management Server: 16.7.X, 16.8, 16.8.1.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • opentext web site management server
CVE-2025-8054
+1 in the same advisory: …8055
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows Path Traversal.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows Path Traversal. The vulnerability could allow an attacker to arbitrarily disclose content of files on the local filesystem. This issue affects XM Fax: 24.2.

NVD description · AI analysis pending
7.1
group max
<1%
  • opentext xm fax
CVE-2025-8050
External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal.

External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2.

NVD description · AI analysis pending
5.3<1%
  • opentext flipper
CVE-2025-8051
+4 in the same advisory: …8048 …8049 …8052 …8053
Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal.

Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal. The vulnerability could allow a user to access files hosted on the server. This issue affects Flipper: 3.1.2.

NVD description · AI analysis pending
5.3
group max
<1%
  • opentext flipper
CVE-2024-6360
Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privil

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0 through 12.X, from 23.0 through 23.X, from 24.0 through 24.X.

NVD description · AI analysis pending
6.9<1%
  • microfocus vertica
CVE-2021-22518
A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file.

A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0

NVD description · AI analysis pending
5.5<1%
  • opentext identity manager azuread driver
CVE-2023-7260
Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4.

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.

NVD description · AI analysis pending
6.9<1%
  • opentext cx-e voice
CVE-2023-7249
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.

NVD description · AI analysis pending
6.3<1%
  • opentext directory services
CVE-2024-6359
+2 in the same advisory: …6358 …6357
Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

NVD description · AI analysis pending
9.8
group max
<1%
  • opentext arcsight intelligence
CVE-2024-6361
Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane.

Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all version prior to version 23.4. The vulnerability could cause remote code execution attack.

NVD description · AI analysis pending
7.3<1%
  • opentext alm octane
CVE-2024-4187
Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2.

Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when clicking links to external sites.

NVD description · AI analysis pending
2.1<1%
  • opentext filr
CVE-2023-7248
Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.

Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests. The vulnerability would affect one of Vertica’s authentication functionalities by allowing specially crafted requests and sequences. This issue impacts the following Vertica Management Console versions: 10.x 11.1.1-24 or lower 12.0.4-18 or lower Please upgrade to one of the following Vertica Management Console versions: 10.x to upgrade to latest versions from below. 11.1.1-25 12.0.4-19 23.x 24.x

NVD description · AI analysis pending
9.8<1%
  • opentext vertica
CVE-2023-38535
+2 in the same advisory: …38534 …38536
Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2.

Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.

NVD description · AI analysis pending
9.8
group max
<1%
  • opentext exceed turbox
CVE-2020-11862
Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This i

Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2.

NVD description · AI analysis pending
7.5<1%
  • opentext netiq privileged account manager
CVE-2023-6123
Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above.

Improper Neutralization vulnerability affects OpenText ALM Octane version 16.2.100 and above. The vulnerability could result in a remote code execution attack.

NVD description · AI analysis pending
6.1<1%
  • opentext alm octane
CVE-2023-4551
+4 in the same advisory: …4550 …4552 …4554 …4553
Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection.

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is vulnerable to command injection. This allows authenticated users to inject arbitrary operating system commands into the executing process. This issue affects AppBuilder: from 21.2 before 23.2.

NVD description · AI analysis pending
8.8
group max
1%
  • opentext appbuilder
CVE-2022-41221
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks.

The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft XML files that, when processed by the application, would cause a negative security impact such as data exfiltration or localized denial of service against the application instance and system of the user running it.

NVD description · AI analysis pending
7.1<1% PoC
  • opentext archive center administration
CVE-2023-31871
OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root.

OpenText Documentum Content Server before 23.2 has a flaw that allows for privilege escalation from a non-privileged Documentum user to root. The software comes prepackaged with a root owned SUID binary dm_secure_writer. The binary has security controls in place preventing creation of a file in a non-owned directory, or as the root user. However, these controls can be carefully bypassed to allow for an arbitrary file write as root.

NVD description · AI analysis pending
7.8<1% PoC
  • opentext documentum content server
CVE-2022-35898
OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation.

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.

NVD description · AI analysis pending
9.8<1%
  • opentext bizmanager
CVE-2022-45926
An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803).

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports.

NVD description · AI analysis pending
8.8
group max
17% PoC ×3
  • opentext opentext extended ecm
CVE-2021-31504
+1 in the same advisory: …31503
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134).

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.3.84 (package 16.6.3.134). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of a user-supplied value prior to dereferencing it as a pointer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12691.

NVD description · AI analysis pending
7.81%
  • opentext brava\! desktop
CVE-2021-31514
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop Build 16.6.4.55. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-13679.

NVD description · AI analysis pending
7.82%
  • opentext brava\! desktop