ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28155
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP t

The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

NVD description · AI analysis pending
6.1<1% PoC ×2
  • request project request
CVE-2020-28502
This affects the package xmlhttprequest before 1.7.0;

This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.

NVD description · AI analysis pending
8.15% PoC ×4
  • xmlhttprequest project xmlhttprequest
CVE-2020-13482
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the librar

EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.

NVD description · AI analysis pending
7.4<1% PoC ×2
  • em-http-request project em-http-request
  • em-http-request project fedora
CVE-2020-7646
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

NVD description · AI analysis pending
9.82% PoC
  • curlrequest project curlrequest
CVE-2019-1010206
OSS Http Request (Apache Cordova Plugin) 6 is affected by:

OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.

NVD description · AI analysis pending
5.9<1%
  • http request project http request
CVE-2017-16073
noderequest was a malicious module published with the intent to hijack environment variables.

noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

NVD description · AI analysis pending
7.51%
  • noderequest project noderequest
CVE-2017-16026
Request is an http client.

Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 2.51.0 <=2.67.0.

NVD description · AI analysis pending
5.93% PoC ×3
  • request project request