ZeroHour

Vulnerabilities

141 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-41049
+4 in the same advisory: …41048 …41046 …41045 …41047
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions a

Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.

NVD description · AI analysis pending
8.4
group max
<1%
  • presire qsnapper
CVE-2025-66944
SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search A

SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint

NVD description · AI analysis pending
9.8<1% PoC ×2
  • databasir databasir
CVE-2025-61464
+1 in the same advisory: …60859
gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.

gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.php.

NVD description · AI analysis pending
6.5
group max
<1% PoC ×2
  • sir gnuboard
CVE-2025-7786
A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10.

A vulnerability, which was classified as problematic, has been found in Gnuboard g6 up to 6.0.10. This issue affects some unknown processing of the file /bbs/scrap_popin_update/qa/ of the component Post Reply Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.0<1% PoC
  • sir gnuboard
CVE-2024-37656
+2 in the same advisory: …37657 …37658
An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php.

NVD description · AI analysis pending
6.1<1% PoC
  • sir gnuboard
CVE-2025-46233
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.Thi

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sirv CDN and Image Hosting Sirv sirv allows Stored XSS.This issue affects Sirv: from n/a through <= 7.5.3.

NVD description · AI analysis pending
5.4<1%
  • sirv sirv
CVE-2024-10855
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the filename parameter of the sirv_upload_file_by_chunks() function and lack of in all versions up to, and including, 7.3.0. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary option values on the WordPress site. This can be leveraged to delete an option that would create an error on the site and deny service to legitimate users.

NVD description · AI analysis pending
8.1<1%
  • sirv sirv
CVE-2024-8964
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and in

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 7.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.

NVD description · AI analysis pending
5.4<1%
  • sirv sirv
CVE-2024-8480
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'si

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sirv_save_prevented_sizes' function in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Contributor-level access and above, to exploit the 'sirv_upload_file_by_chunks_callback' function, which lacks proper file type validation, allowing attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

NVD description · AI analysis pending
8.8<1%
  • sirv sirv
CVE-2024-39097
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.

There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.

NVD description · AI analysis pending
6.1<1% PoC ×2
  • sir gnuboard
CVE-2024-41475
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

NVD description · AI analysis pending
8.8<1% PoC
  • sir gnuboard
CVE-2024-6223
+1 in the same advisory: …6224
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leadin

The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • yasirwazir send email only on reply to my comment
CVE-2024-6392
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modification due to missing capability checks on the plugin functions in all versions up to, and including, 7.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the connected Sirv account to an attacker-controlled one.

NVD description · AI analysis pending
5.4<1%
  • sirv sirv
CVE-2024-5853
The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the sirv_upload_file_by_chanks AJAX action in all versions up to, and including, 7.2.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

NVD description · AI analysis pending
8.8<1%
  • sirv sirv
CVE-2024-6056
A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0.

A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-password of the component Password Reset Handler. The manipulation of the argument Email leads to observable response discrepancy. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268784. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.3<1% PoC
  • nasirkhan laravel starter
CVE-2024-32959
Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv:

Incorrect Privilege Assignment vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.2.

NVD description · AI analysis pending
8.8<1%
  • sirv sirv
CVE-2024-24157
Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.

Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.

NVD description · AI analysis pending
6.1<1% PoC
  • sir gnuboard
CVE-2024-33782
+3 in the same advisory: …33781 …33780 …33783
MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp.

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • csiro multi-protocol spdz
CVE-2024-24156
Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary

Cross Site Scripting (XSS) vulnerability in Gnuboard g6 before Github commit 58c737a263ac0c523592fd87ff71b9e3c07d7cf5, allows remote attackers execute arbitrary code via the wr_content parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • sir gnuboard
CVE-2023-50898
Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv:

Missing Authorization vulnerability in sirv.Com Sirv.This issue affects Sirv: from n/a through 7.1.2.

NVD description · AI analysis pending
8.8<1%
  • sirv sirv
CVE-2024-27950
+1 in the same advisory: …27949
Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv:

Missing Authorization vulnerability in Sirv CDN and Image Hosting Sirv sirv.This issue affects Sirv: from n/a through <= 7.2.0.

NVD description · AI analysis pending
8.8
group max
<1%
  • sirv sirv
CVE-2023-35857
In Siren Investigate before 13.2.2, session keys remain active even after logging out.

In Siren Investigate before 13.2.2, session keys remain active even after logging out.

NVD description · AI analysis pending
9.8<1%
  • siren investigate
CVE-2023-27821
Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.

Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.

NVD description · AI analysis pending
9.82% PoC ×2
  • databasir databasir
CVE-2022-48111
A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitra

A cross-site scripting (XSS) vulnerability in the check_login function of SIPE s.r.l WI400 between version 8 and 11 included allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the f parameter.

NVD description · AI analysis pending
6.1<1% PoC ×2
  • siri-informatica wi400
CVE-2022-44216
Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions.

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password.

NVD description · AI analysis pending
7.5<1%
  • sir gnuboard
CVE-2022-42484
+1 in the same advisory: …38451
An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5.

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
9.8
group max
6% PoC
  • freshtomato freshtomato
  • freshtomato quartz-gold firmware
CVE-2022-44264
+1 in the same advisory: …44263
Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.

Dentsply Sirona Sidexis <= 4.3 is vulnerable to Unquoted Service Path.

NVD description · AI analysis pending
7.8<1%
  • dentsplysirona sidexis
CVE-2022-42493
Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020.

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's DOWNLOAD_INFO command.

NVD description · AI analysis pending
9.8
group max
3%
  • siretta quartz-gold firmware