ZeroHour

Vulnerabilities

29 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-6815
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider.

An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the application's intended storage sandbox.

NVD description · AI analysis pending
5.9<1%
  • casbin casdoor
CVE-2026-5469
+2 in the same advisory: …5467 …5468
A weakness has been identified in Casdoor 2.356.0.

A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.1
group max
<1%
  • casbin casdoor
CVE-2025-40639
+1 in the same advisory: …40638
A SQL injection vulnerability has been found in Eventobot.

A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.

NVD description · AI analysis pending
8.7
group max
<1%
  • sbitsoft eventobot
CVE-2024-41657
+1 in the same advisory: …41658
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform.

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a prefix when authenticating the Origin header, any domain can create a valid subdomain with a valid subdomain prefix (Ex: localhost.example.com), allowing the website to make requests to Casdoor as the current signed-in user.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • casbin casdoor
CVE-2024-41264
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.

NVD description · AI analysis pending
7.5<1%
  • casbin casdoor
CVE-2023-48050
SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v.

SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the controllers/controllers.py component.

NVD description · AI analysis pending
9.8<1%
  • camsbiometrics zkteco\, essl\, cams biometrics integration module
  • camsbiometrics biometric attendance
CVE-2023-4005
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.

Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.

NVD description · AI analysis pending
9.8<1%
  • fossbilling fossbilling
CVE-2023-3568
Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

NVD description · AI analysis pending
4.8<1%
  • fossbilling fossbilling
CVE-2023-3521
Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.

Cross-site Scripting (XSS) - Reflected in GitHub repository fossbilling/fossbilling prior to 0.5.4.

NVD description · AI analysis pending
6.1<1% PoC
  • fossbilling fossbilling
CVE-2023-3490
+2 in the same advisory: …3491 …3493
SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • fossbilling fossbilling
CVE-2023-3393
+1 in the same advisory: …3394
Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.

NVD description · AI analysis pending
7.2
group max
1% PoC
  • fossbilling fossbilling
CVE-2023-34927
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password.

Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.

NVD description · AI analysis pending
6.53% PoC
  • casbin casdoor
CVE-2023-3230
+3 in the same advisory: …3229 …3228 …3227
Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.

Missing Authorization in GitHub repository fossbilling/fossbilling prior to 0.5.0.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • fossbilling fossbilling
CVE-2022-44942
Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.

Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.

NVD description · AI analysis pending
8.1<1% PoC
  • casbin casdoor
CVE-2022-38638
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.

Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.

NVD description · AI analysis pending
9.11% PoC
  • casbin casdoor
CVE-2022-24124
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.

The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.

NVD description · AI analysis pending
7.555% PoC ×3
  • casbin casdoor
CVE-2018-17404
The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow an attacker to sniff private information such as mobile number, PAN number (

The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow an attacker to sniff private information such as mobile number, PAN number (from a government-issued ID), and date of birth.

NVD description · AI analysis pending
5.3<1% PoC
  • sbi sbi buddy
CVE-2018-17108
The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeover attacks by intercepting a security-que

The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeover attacks by intercepting a security-question response during the initial configuration of the application.

NVD description · AI analysis pending
8.81% PoC
  • sbi sbi buddy
CVE-2017-10885
Untrusted search path vulnerability in HYPER SBI Ver.

Untrusted search path vulnerability in HYPER SBI Ver. 2.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

NVD description · AI analysis pending
7.81%
  • sbisec hyper sbi