ZeroHour

Vulnerabilities

13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-45180
SquaredUp DS for SCOM 6.2.1.11104 allows XSS.

SquaredUp DS for SCOM 6.2.1.11104 allows XSS.

NVD description · AI analysis pending
5.4<1%
  • squaredup squaredup ds for scom
CVE-2022-46785
+2 in the same advisory: …46784 …46786
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).

SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).

NVD description · AI analysis pending
6.1
group max
<1%
  • squaredup dashboard server
CVE-2021-40096
+4 in the same advisory: …40093 …40092 …40094 …40095
A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script

A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.

NVD description · AI analysis pending
5.4
group max
<1%
  • squaredup squaredup
CVE-2021-40091
An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.

An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.

NVD description · AI analysis pending
9.81%
  • squaredup squaredup
CVE-2020-9388
+2 in the same advisory: …9390 …9389
CSRF protection was not present in SquaredUp before version 4.6.0.

CSRF protection was not present in SquaredUp before version 4.6.0. A CSRF attack could have been possible by an administrator executing arbitrary code in a HTML dashboard tile via a crafted HTML page, or by uploading a malicious SVG payload into a dashboard.

NVD description · AI analysis pending
6.5
group max
<1%
  • squaredup squaredup