ZeroHour

Vulnerabilities

41 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-1034
There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

NVD description · AI analysis pending
7.21% PoC
  • showdoc showdoc
CVE-2022-0951
File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.

File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • showdoc showdoc
CVE-2022-0962
Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.

Stored XSS viva .webma file upload in GitHub repository star7th/showdoc prior to 2.10.4.

NVD description · AI analysis pending
5.4<1% PoC
  • showdoc showdoc
CVE-2022-0880
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

NVD description · AI analysis pending
5.4<1% PoC
  • showdoc showdoc
CVE-2022-0409
Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.

Unrestricted Upload of File with Dangerous Type in Packagist showdoc/showdoc prior to 2.10.2.

NVD description · AI analysis pending
7.8<1% PoC
  • showdoc showdoc
CVE-2022-0362
SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.

SQL Injection in Packagist showdoc/showdoc prior to 2.10.3.

NVD description · AI analysis pending
9.81% PoC
  • showdoc showdoc
CVE-2021-4172
Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.

NVD description · AI analysis pending
5.4<1% PoC
  • showdoc showdoc
CVE-2022-0079
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information

showdoc is vulnerable to Generation of Error Message Containing Sensitive Information

NVD description · AI analysis pending
5.3<1% PoC
  • showdoc showdoc
CVE-2021-4168
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

NVD description · AI analysis pending
8.8<1% PoC
  • showdoc showdoc
CVE-2021-4000
showdoc is vulnerable to URL Redirection to Untrusted Site

showdoc is vulnerable to URL Redirection to Untrusted Site

NVD description · AI analysis pending
6.1<1% PoC
  • showdoc showdoc
CVE-2021-4017
+3 in the same advisory: …3990 …3993 …3989
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • showdoc showdoc
CVE-2021-3683
+2 in the same advisory: …3775 …3776
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • showdoc showdoc
CVE-2021-41745
ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

NVD description · AI analysis pending
9.81%
  • showdoc showdoc
CVE-2021-36440
Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController

Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'.

NVD description · AI analysis pending
9.85% PoC
  • showdoc showdoc
CVE-2021-3678
+1 in the same advisory: …3680
showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

NVD description · AI analysis pending
5.9
group max
1%
  • showdoc showdoc
CVE-2018-19621
+1 in the same advisory: …19620
server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.

server/index.php?s=/api/teamMember/save in ShowDoc 2.4.2 has a CSRF that can add members to a team.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • showdoc showdoc
CVE-2018-19609
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discove

ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.

NVD description · AI analysis pending
6.51% PoC
  • showdoc showdoc
CVE-2018-19433
ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.

ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.

NVD description · AI analysis pending
6.1<1% PoC
  • showdoc showdoc
CVE-2018-16342
ShowDoc v1.8.0 has XSS via a new page.

ShowDoc v1.8.0 has XSS via a new page.

NVD description · AI analysis pending
5.4<1% PoC
  • showdoc showdoc