ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25585
+4 in the same advisory: …25590 …25580 …25582 …25586
Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Admini

Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords.

NVD description · AI analysis pending
7.3
group max
<1% PoC
  • r1bbit yimioa
CVE-2025-1226
+4 in the same advisory: …1216 …1227 …1224 …1225
A vulnerability was found in ywoa up to 2024.07.03.

A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.

NVD description · AI analysis pending
6.9
group max
<1% PoC
  • r1bbit yimioa