ZeroHour

Vulnerabilities

126 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-1626
+1 in the same advisory: …1627
An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH comm

An attacker may exploit the use of weak CBC-based cipher suites in the device’s SSH service to potentially observe or manipulate parts of the encrypted SSH communication, if they are able to intercept or interact with the network traffic.

NVD description · AI analysis pending
9.1
group max
<1%
  • sick lms1000 firmware
  • sick mrs1000 firmware
CVE-2026-22644
+2 in the same advisory: …22646 …22645
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer h

Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft through server logs, proxy logs and Referer headers, which could allow an attacker to hijack the user's session and gain unauthorized access.

NVD description · AI analysis pending
7.5
group max
<1%
  • sick incoming goods suite
CVE-2026-22908
Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality.

NVD description · AI analysis pending
9.1
group max
<1%
  • sick tdc-x401gl firmware
CVE-2025-59461
+4 in the same advisory: …59462 …59460 …59463 …59459
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.

NVD description · AI analysis pending
9.8
group max
<1%
  • sick tloc100-100 firmware
CVE-2025-58587
The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an a

The application does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it possible for an attacker to guess user credentials.

NVD description · AI analysis pending
9.8
group max
<1%
  • sick baggage analytics
  • sick enterprise analytics
  • sick logistic diagnostic analytics
  • +1 more
CVE-2025-58582
+4 in the same advisory: …58580 …58583 …58581 …58578
If a user tries to login but the provided credentials are incorrect a log is created.

If a user tries to login but the provided credentials are incorrect a log is created. The data for this POST requests is not validated and it’s possible to send giant payloads which are then logged.

NVD description · AI analysis pending
7.5
group max
<1%
  • sick enterprise analytics
CVE-2025-49199
The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it.

The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP, modify and re-upload it. This allows the attacker to disrupt the application by configuring the services in a way that they are unable to run, making the application unusable. They can redirect traffic that is meant to be internal to their own hosted services and gathering information.

NVD description · AI analysis pending
9.8
group max
<1%
  • sick field analytics
CVE-2025-49195
+4 in the same advisory: …49198 …49194 …49197 …49189
The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the

The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server.

NVD description · AI analysis pending
9.8
group max
<1%
  • sick media server
CVE-2025-49193
The application fails to implement several security headers.

The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks).

NVD description · AI analysis pending
6.1<1%
  • sick baggage analytics
  • sick field analytics
  • sick logistic diagnostic analytics
  • +1 more