ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-25780
It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM.

It is identified a vulnerability of insufficient authentication in an important specific function of Status PowerBPM. A LAN attacker with normal user privilege can exploit this vulnerability to modify substitute agent to arbitrary users, resulting in serious consequence.

NVD description · AI analysis pending
5.7<1%
  • status powerbpm
CVE-2022-42906
powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution.

powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When using powerline-gitstatus, changing to a directory automatically runs git commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory to one controlled by the attacker, such as in a shared filesystem or extracted archive, powerline-gitstatus will run arbitrary commands under the attacker's control. NOTE: this is similar to CVE-2022-20001.

NVD description · AI analysis pending
7.8<1% PoC
  • powerline gitstatus project powerline gitstatus
  • powerline gitstatus project debian linux
CVE-2022-31094
ScratchTools is a web extension designed to make interacting with the Scratch programming language community (Scratching) easier.

ScratchTools is a web extension designed to make interacting with the Scratch programming language community (Scratching) easier. In affected versions anybody who uses the Recently Viewed Projects feature is vulnerable to having their account taken over if they view a project that tries to. The issue is that if a user visits a project that includes Javascript in the title, then when the Recently Viewed Projects feature displays it, it could run the Javascript. This issue has been addressed in the 2.5.2 release. Users having issues scratching should open an issue in the project issue tracker https://github.com/STForScratch/ScratchTools/

NVD description · AI analysis pending
6.1<1%
  • scratchstatus scratchtools
CVE-2021-24846
The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authen

The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL injection, exploitable by any authenticated users, such as subscriber

NVD description · AI analysis pending
8.81% PoC
  • ni woocommerce custom order status project ni woocommerce custom order status
CVE-2021-24662
The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it in SQL statement, leading to an Authenti

The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it in SQL statement, leading to an Authenticated SQL Injection in an admin page

NVD description · AI analysis pending
7.21% PoC
  • game-server-status project game-server-status
CVE-2021-24670
The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-S

The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks

NVD description · AI analysis pending
5.4<1% PoC
  • status301 coolclock
CVE-2019-16524
The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to imp

The easy-fancybox plugin before 1.8.18 for WordPress (aka Easy FancyBox) is susceptible to Stored XSS in the Settings Menu inc/class-easyfancybox.php due to improper encoding of arbitrarily submitted settings parameters. This occurs because there is no inline styles output filter.

NVD description · AI analysis pending
4.81% PoC ×2
  • status301 easy fancybox
CVE-2019-15479
+1 in the same advisory: …15478
Status Board 1.1.81 has reflected XSS via dashboard.ts.

Status Board 1.1.81 has reflected XSS via dashboard.ts.

NVD description · AI analysis pending
6.1<1%
  • status board project status board
CVE-2019-12164
ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.

ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution.

NVD description · AI analysis pending
9.84%
  • status react native desktop