ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-24275
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.

A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.

NVD description · AI analysis pending
6.5<1% PoC
  • swoole swoole
CVE-2021-43676
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.

matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.

NVD description · AI analysis pending
9.81% PoC
  • swoole swoole php framework
CVE-2019-15518
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.

NVD description · AI analysis pending
5.32%
  • swoole swoole
CVE-2018-15503
The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process.

The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process. An attacker can craft a serialized object to exploit this vulnerability and cause a SEGV.

NVD description · AI analysis pending
7.52%
  • swoole swoole