ZeroHour

Vulnerabilities

55 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50736
+3 in the same advisory: …50737 …50738 …50735
The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the sub

The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default installations. A party acting as the publisher can send crafted queue messages that cause arbitrary SQL to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser and breaking the isolation between tenants in shared deployments. To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.

NVD description · AI analysis pending
9.0
group max
<1%
  • enterprisedb pglogical
CVE-2026-0949
PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject

PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript when creating a new chart, which is then executed by any user accessing the chart. By default only the superuser and users with pem_admin or pem_super_admin privileges are able to access the Manage Charts menu.

NVD description · AI analysis pending
4.8<1%
  • enterprisedb postgres enterprise manager
CVE-2025-37164
Unauthenticated Remote Code Execution in HPE OneView

HPE OneView, HPE's infrastructure management platform, contains a code-injection flaw (CWE-94) that permits unauthenticated remote code execution, with a network-vector, low-complexity CVSS 3.1 score of 9.8 meaning no credentials, privileges, or user interaction are required. An attacker triggers the flaw by sending crafted code-injection input to the OneView appliance over the network, gaining code execution with high impact on the confidentiality, integrity, and availability of the appliance. A compromised OneView instance can serve as a foothold into the HPE server estate it manages, and the RondoDox botnet has already been observed folding this flaw into its exploitation waves. Any organization running an HPE OneView appliance is affected, particularly where the appliance is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-07, a public Metasploit exploit module is available, and EPSS assigns a 90.2% probability of exploitation within 30 days (100th percentile).

Do: Upgrade OneView to the fixed release specified in the HPE security bulletin for CVE-2025-37164 (exact version numbers are not included in this data), and treat patching as urgent given confirmed in-the-wild exploitation and the public Metasploit module. Until patched, remove unnecessary internet exposure of the OneView appliance and review appliance and network logs for signs of compromise, including possible RondoDox botnet infection. US federal agencies must apply mitigations per vendor instructions and BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable.

9.890% KEV PoC
  • HPE OneView
large≈ tens of thousands of deployed OneView appliance instances worldwide, with the internet-exposed subset likely in the thousands
CVE-2025-14038
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints.

EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive data or possibly cause a denial-of-service by writing malformed data to certain gRPC endpoints. This flaw has been remediated in EDB Hybrid Manager 1.3.3, and customers should consider upgrading to 1.3.3 as soon as possible. The flaw is due to a misconfiguration in the Istio Gateway, which manages authentication and authorization for the affected endpoints. The security policy relies on an explicit definition of required permissions in the Istio Gateway configuration, and the affected endpoints were not defined in the configuration. This allowed requests to bypass both authentication and authorization within a Hybrid Manager service. All versions of Hybrid Manager - LTS should be upgraded to 1.3.3, and all versions of Hybrid Manager - Innovation should be upgraded to 2025.12.

NVD description · AI analysis pending
7.0<1%
  • enterprisedb hybrid manager
CVE-2025-25939
Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.

Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.

NVD description · AI analysis pending
6.1<1%
  • reprisesoftware reprise license manager
CVE-2023-43183
+1 in the same advisory: …44031
Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows read-only users to arbitrarily change the password of an ad

Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows read-only users to arbitrarily change the password of an admin and hijack their account.

NVD description · AI analysis pending
8.8
group max
1% PoC ×2
  • reprisesoftware reprise license manager
CVE-2023-41117
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.

An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks.

NVD description · AI analysis pending
9.8
group max
<1%
  • enterprisedb postgres advanced server
CVE-2023-31043
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER

EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and 14.6.0.

NVD description · AI analysis pending
7.5<1%
  • enterprisedb postgres advanced server
CVE-2022-2560
This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server.

This vulnerability allows remote attackers to delete arbitrary files on affected installations of EnterpriseDT CompleteFTP 22.1.0 Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HttpFile class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to delete files in the context of SYSTEM. Was ZDI-CAN-17481.

NVD description · AI analysis pending
9.178%
  • enterprisedt completeftp server
CVE-2022-31405
MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.

MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.

NVD description · AI analysis pending
6.5<1% PoC ×2
  • mv idigital clinic enterprise project mv idigital clinic enterprise
CVE-2021-37500
+2 in the same advisory: …37499 …37498
Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficien

Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to overwrite any file the on the server.

NVD description · AI analysis pending
8.1
group max
<1%
  • reprisesoftware reprise license manager
CVE-2022-30519
XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.

XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary code via password field.

NVD description · AI analysis pending
6.13% PoC
  • reprisesoftware reprise license manager
CVE-2022-39054
Cowell enterprise travel management system has insufficient filtering for special characters within web URL.

Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

NVD description · AI analysis pending
6.1<1%
  • cowell enterprise travel management system project cowell enterprise travel management system
CVE-2022-28363
+2 in the same advisory: …28364 …28365
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET.

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability (XSS) in the /goform/login_process username parameter via GET. No authentication is required.

NVD description · AI analysis pending
6.1
group max
5% PoC ×2
  • reprisesoftware reprise license manager
CVE-2019-16864
CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH ac

CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM.

NVD description · AI analysis pending
8.88% PoC
  • enterprisedt completeftp server
CVE-2021-45422
Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET.

Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_process "count" parameter via GET. No authentication is required.

NVD description · AI analysis pending
6.13% PoC ×2
  • reprisesoftware reprise license manager
CVE-2021-44152
+4 in the same advisory: …44151 …44153 …44154 …44155
An issue was discovered in Reprise RLM 14.2.

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

NVD description · AI analysis pending
9.8
group max
59% PoC
  • reprisesoftware reprise license manager
CVE-2019-20049
+1 in the same advisory: …20047
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices.

An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a directory traversal (which helps to bypass authentication) with an insecure file upload to achieve Remote Code Execution as SYSTEM. The directory traversal is in the __construct() whereas the insecure file upload is in SetSkinImages().

NVD description · AI analysis pending
9.8
group max
13% PoC ×3
  • al-enterprise omnivista 4760
CVE-2019-20048
An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2.

An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with elevated privileges in the Web Directory component on port 389, may upload a PHP file to achieve Remote Code Execution as SYSTEM.

NVD description · AI analysis pending
7.26% PoC ×2
  • al-enterprise omnivista 8770
CVE-2019-16116
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file.

EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.

NVD description · AI analysis pending
4.34% PoC
  • enterprisedt completeftp server
CVE-2019-15088
An issue was discovered in PRiSE adAS 1.7.0.

An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under specific circumstances, it is possible to bypass login authentication.

NVD description · AI analysis pending
9.8
group max
2%
  • prise adas