ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-39126
+2 in the same advisory: …39124 …39125
Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.

Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.

NVD description · AI analysis pending
5.4<1%
  • roundup-tracker roundup
CVE-2019-10904
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.

Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.

NVD description · AI analysis pending
6.12% PoC ×3
  • debian debian linux
  • debian roundup