ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-14591
In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characte

In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked.

NVD description · AI analysis pending
5.3<1%
  • perforce delphix continuous compliance
CVE-2024-3930
+2 in the same advisory: …5249 …5250
In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

NVD description · AI analysis pending
9.8
group max
<1%
  • perforce akana api
CVE-2024-0325
In Helix Sync versions prior to 2024.1, a local command injection was identified.

In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.

NVD description · AI analysis pending
7.8<1%
  • perforce helix sync
CVE-2023-45849
+3 in the same advisory: …5759 …35767 …45319
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2.

An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.

NVD description · AI analysis pending
9.8
group max
1%
  • perforce helix core
CVE-2022-2394
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, su

Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise.

NVD description · AI analysis pending
3.5<1%
  • perforce puppet bolt
CVE-2021-28973
The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configure

The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.

NVD description · AI analysis pending
4.9<1% PoC
  • perforce helix alm
CVE-2018-1000147
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows atta

An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to obtain Perforce passwords configured in jobs to obtain them

NVD description · AI analysis pending
6.5<1%
  • perforce perforce