ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-14518
A vulnerability was identified in PowerJob up to 5.1.2.

A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

NVD description · AI analysis pending
2.1<1% PoC ×2
  • powerjob powerjob
CVE-2025-11580
+1 in the same advisory: …11581
A weakness has been identified in PowerJob up to 5.1.2.

A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

NVD description · AI analysis pending
5.51%
  • powerjob powerjob
CVE-2024-44546
Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.

Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.

NVD description · AI analysis pending
9.8<1%
  • powerjob powerjob
CVE-2023-36106
An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying v

An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.

NVD description · AI analysis pending
7.5<1%
  • powerjob powerjob
CVE-2023-37754
PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.

PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.

NVD description · AI analysis pending
9.830% PoC ×2
  • powerjob powerjob
CVE-2023-29924
PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.

PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.

NVD description · AI analysis pending
9.81%
  • powerjob powerjob
CVE-2023-29926
PowerJob V4.3.2 has unauthorized interface that causes remote code execution.

PowerJob V4.3.2 has unauthorized interface that causes remote code execution.

NVD description · AI analysis pending
9.81%
  • powerjob powerjob
CVE-2023-29923
+2 in the same advisory: …29922 …29921
PowerJob V4.3.1 is vulnerable to Insecure Permissions.

PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.

NVD description · AI analysis pending
5.310% PoC
  • powerjob powerjob
CVE-2020-28865
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.

An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.

NVD description · AI analysis pending
7.5<1%
  • powerjob powerjob