ZeroHour

Vulnerabilities

11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-9645
+1 in the same advisory: …9646
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server.

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.

NVD description · AI analysis pending
9.9
group max
<1%
  • scadabr scadabr
CVE-2026-8602
+3 in the same advisory: …8603 …8604 …8605
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to th

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings.

NVD description · AI analysis pending
8.8
group max
<1%
  • scadabr scadabr
CVE-2025-70973
ScadaBR 1.12.4 is vulnerable to Session Fixation.

ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an attacker who knows the session ID to hijack an authenticated session.

NVD description · AI analysis pending
4.8<1% PoC
  • scadabr scadabr
CVE-2021-26828
+1 in the same advisory: …26829
Authenticated JSP File Upload RCE in OpenPLC ScadaBR (view_edit.shtm)

OpenPLC ScadaBR contains an unrestricted file upload flaw (CWE-434) in its web interface that lets a remote, authenticated user upload arbitrary JSP files through view_edit.shtm. Once uploaded, the malicious JSP is executed by the application server, giving the attacker remote code execution on the host running ScadaBR. Because exploitation requires valid credentials, risk is highest in deployments where default, shared, or weak passwords are used, which is common in OT/SCADA environments. The flaw affects OpenPLC's ScadaBR SCADA/HMI software. CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-03, confirming active exploitation in the wild, and EPSS puts its 30-day exploitation probability at 39.4% (99th percentile); no public PoC is known.

Do: Update ScadaBR/OpenPLC to the latest vendor release per vendor guidance, as required by CISA's KEV listing and BOD 22-01 for federal agencies. Until patched, restrict access to the ScadaBR web interface (including view_edit.shtm) to trusted users and networks, enforce strong unique credentials since exploitation requires authentication, and check the ScadaBR webapps/upload directories and access logs for unexpected .jsp files or recent uploads.

8.8
group max
39% KEV PoC ×3
  • OpenPLC ScadaBR
moderate~1,000-3,000 internet-exposed ScadaBR instances (rough order-of-magnitude estimate)
CVE-2019-16344
A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HT

A cross-site scripting (XSS) vulnerability in the login form (/ScadaBR/login.htm) in ScadaBR 1.0CE allows a remote attacker to inject arbitrary web script or HTML via the username or password parameter.

NVD description · AI analysis pending
6.11% PoC
  • scadabr scadabr
CVE-2019-16321
ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.

ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.

NVD description · AI analysis pending
6.1<1% PoC
  • scadabr scadabr