ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-9848
+1 in the same advisory: …9847
A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0.

A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

NVD description · AI analysis pending
5.5
group max
<1% PoC
  • scriptandtools real estate management system
CVE-2025-6329
A vulnerability was found in ScriptAndTools Real Estate Management System 1.0.

A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • scriptandtools real estate management system
CVE-2025-5128
A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0.

A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component Admin Login Panel. The manipulation of the argument Password leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.9<1% PoC
  • scriptandtools real estate management system
CVE-2025-4066
+3 in the same advisory: …4067 …4064 …4065
A vulnerability was found in ScriptAndTools Online-Travling-System 1.0.

A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/addpackage.php. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9<1%
  • scriptandtools online traveling system
CVE-2025-3975
A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic.

A vulnerability was found in ScriptAndTools eCommerce-website-in-PHP 3.0 and classified as problematic. This issue affects some unknown processing of the file /admin/subscriber-csv.php. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
6.9<1% PoC
  • scriptandtools ecommerce-website-in-php
CVE-2025-3556
+2 in the same advisory: …3555 …3557
A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0.

A vulnerability classified as problematic was found in ScriptAndTools eCommerce-website-in-PHP 3.0. Affected by this vulnerability is an unknown functionality of the file /admin/login.php. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.3
group max
<1% PoC
  • scriptandtools ecommerce-website-in-php