ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-25814
PlaciPy is a placement management system designed for educational institutions.

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, User-controlled query parameters are passed directly into DynamoDB query/filter construction without validation or sanitization.

NVD description · AI analysis pending
9.3
group max
<1%
  • prasklatechnology placipy
CVE-2026-25753
PlaciPy is a placement management system designed for educational institutions.

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, the application uses a hard-coded, static default password for all newly created student accounts. This results in mass account takeover, allowing any attacker to log in as any student once the password is known.

NVD description · AI analysis pending
9.3<1%
  • prasklatechnology placipy