ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-48942
+1 in the same advisory: …48941
The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plug

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to easily brute-force the 2FA PIN via the plugins/servlet/twofactor/public/pinvalidation endpoint. The last 30 and the next 30 tokens are valid.

NVD description · AI analysis pending
5.9
group max
<1%
  • syracom secure login
CVE-2023-22958
The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target p

The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • syracom secure login
CVE-2022-0472
Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.

Unrestricted Upload of File with Dangerous Type in Packagist jsdecena/laracom prior to v2.0.9.

NVD description · AI analysis pending
5.4<1% PoC
  • laracom project laracom
CVE-2021-20074
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.

NVD description · AI analysis pending
8.8
group max
1%
  • racom m\!dge firmware
CVE-2019-15489
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.

laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.

NVD description · AI analysis pending
6.1<1% PoC
  • laracom laracom