ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-6019
+2 in the same advisory: …6021 …6020
A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely withou

A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

NVD description · AI analysis pending
9.8
group max
75% PoC
  • ray project ray
CVE-2022-41958
super-xray is a web vulnerability scanning tool.

super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. This issue has been addressed in commit `4d0d5966` and will be included in future releases. Users are advised to upgrade. There are no known workarounds for this issue.

NVD description · AI analysis pending
7.8<1% PoC
  • super xray project super xray
CVE-2022-41950
super-xray is the GUI alternative for vulnerability scanning tool xray.

super-xray is the GUI alternative for vulnerability scanning tool xray. In 0.2-beta, a privilege escalation vulnerability was discovered. This caused inaccurate default xray permissions. Note: this vulnerability only affects Linux and Mac OS systems. Users should upgrade to super-xray 0.3-beta.

NVD description · AI analysis pending
7.8<1% PoC
  • super xray project super xray
CVE-2022-41945
super-xray is a vulnerability scanner (xray) GUI launcher.

super-xray is a vulnerability scanner (xray) GUI launcher. In version 0.1-beta, the URL is not filtered and directly spliced ​​into the command, resulting in a possible RCE vulnerability. Users should upgrade to super-xray 0.2-beta.

NVD description · AI analysis pending
9.8<1% PoC
  • super-xray project super-xray
CVE-2020-36465
An issue was discovered in the generic-array crate before 0.13.3 for Rust.

An issue was discovered in the generic-array crate before 0.13.3 for Rust. It violates soundness by using the arr! macro to extend lifetimes.

NVD description · AI analysis pending
7.51% PoC
  • generic-array project generic-array
CVE-2019-10798
rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution.

rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.

NVD description · AI analysis pending
5.31% PoC
  • rdf-graph-array project rdf-graph-array