ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-52150
Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L.

Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5.

NVD description · AI analysis pending
8.8<1%
  • ovation dynamic content for elementor
CVE-2022-29594
eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.

eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.

NVD description · AI analysis pending
7.8<1% PoC
  • eginnovations eg agent
  • eginnovations eg manager
  • eginnovations eg rum collectors
  • +1 more
CVE-2021-3327
Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.

Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • ovation dynamic content
CVE-2020-29001
An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devi

An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application.

NVD description · AI analysis pending
7.21% PoC
  • merkuryinnovations geeni gnc-cw028 firmware
  • merkuryinnovations geeni gnc-cw025 firmware
  • merkuryinnovations merkury mi-cw024 firmware
  • +1 more
CVE-2020-8591
+1 in the same advisory: …8592
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.

eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.

NVD description · AI analysis pending
9.81% PoC
  • eginnovations eg manager
CVE-2018-15885
Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for d

Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for discovering the product's capabilities or purpose. This makes it easier for adversaries to detect the covert operation. Specifically, the product uses a compression technique to prevent the identification of certain libraries in the software by obfuscation. The software relies on a TLS callback and an additional executable file to enable these libraries and their access to certain websites. The unpacked software can be exploited by several different types of documented techniques.

NVD description · AI analysis pending
7.51% PoC
  • ovation findme