ZeroHour

Vulnerabilities

2,394 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50289
systeminformation is a System and OS information library for node.js.

systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu interfaces(5) source directive because lib/network.js checkLinuxDCHPInterfaces() reads /etc/network/interfaces, extracts a source token from file content, and interpolates it unquoted into cat ${file} 2> /dev/null | grep 'iface\|source' executed by execSync(cmd, util.execOptsLinux), allowing a path containing shell metacharacters to execute commands in any process that calls networkInterfaces(), including via getStaticData() and getAllData(). This issue is fixed in version 5.31.7.

NVD description · AI analysis pending
8.72% PoC
  • systeminformation systeminformation
CVE-2026-13241
+1 in the same advisory: …13240
Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing.

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.

NVD description · AI analysis pending
6.5<1%
  • md-systems paragraphs
CVE-2026-42097
+3 in the same advisory: …42096 …42099 …42100
Sparx Pro Cloud Server requires authentication based on requested URL.

Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

NVD description · AI analysis pending
9.3
group max
<1% PoC
  • sparxsystems pro cloud server
CVE-2018-25265
+1 in the same advisory: …25268
LanSpy 2.0.1.159 contains a local buffer overflow vulnerability in the scan section that allows local attackers to execute arbitrary code by exploiting structur

LanSpy 2.0.1.159 contains a local buffer overflow vulnerability in the scan section that allows local attackers to execute arbitrary code by exploiting structured exception handling mechanisms. Attackers can craft malicious payloads using egghunter techniques to locate and execute shellcode, triggering code execution through SEH chain manipulation and controlled jumps.

NVD description · AI analysis pending
8.6<1% PoC
  • lizardsystems lanspy
CVE-2018-25267
UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwri

UltraISO 9.7.1.3519 contains a local buffer overflow vulnerability in the Output FileName field of the Make CD/DVD Image dialog that allows attackers to overwrite SEH and SE handler records. Attackers can craft a malicious filename string with 304 bytes of data followed by SEH record overwrite values and paste it into the Output FileName field to trigger a denial of service crash.

NVD description · AI analysis pending
6.9<1% PoC
  • ezbsystems ultraiso
CVE-2018-25259
Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary

Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH handler pointer to execute calc.exe or other payloads when imported through the add computers wizard.

NVD description · AI analysis pending
8.6<1% PoC
  • lizardsystems terminal services manager
CVE-2026-40602
The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant.

The Home Assistant Command-line interface (hass-cli) is a command-line tool for Home Assistant. Up to 1.0.0 of home-assitant-cli an unrestricted environment was used to handle Jninja2 templates instead of a sandboxed one. The user-supplied input within Jinja2 templates was rendered locally with no restrictions. This gave users access to Python's internals and extended the scope of templating beyond the intended usage. This vulnerability is fixed in 1.0.0.

NVD description · AI analysis pending
5.6<1%
  • home-assistant-ecosystem home assistant command-line interface
CVE-2025-15625
+2 in the same advisory: …15624 …15623
Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.

NVD description · AI analysis pending
9.5
group max
<1%
  • sparxsystems pro cloud server
CVE-2025-15621
Insufficiently Protected Credentials in Sparx Systems Pty Ltd.

Insufficiently Protected Credentials in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client does not verify the receiver of OAuth2 credentials during OpenID authentication

NVD description · AI analysis pending
5.7<1%
  • sparxsystems enterprise architect
CVE-2026-40224
In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

In systemd 259 before 260, there is local privilege escalation in systemd-machined because varlink can be used to reach the root namespace.

NVD description · AI analysis pending
7.3
group max
<1%
  • systemd project systemd
CVE-2026-34184
+2 in the same advisory: …34185 …4901
AlanWeb SCADA does not enforce authorization for some directories.

AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database. This issue was fixed in AlanWeb SCADA version 9.8.5

NVD description · AI analysis pending
8.8
group max
<1%
  • hydrosystem.poznan control system
CVE-2026-29111
systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data.

systemd, a system and service manager, (as PID 1) hits an assert and freezes execution when an unprivileged IPC API call is made with spurious data. On version v249 and older the effect is not an assert, but stack overwriting, with the attacker controlled content. From version v250 and newer this is not possible as the safety check causes an assert instead. This IPC call was added in v239, so versions older than that are not affected. Versions 260-rc1, 259.2, 258.5, and 257.11 contain patches. No known workarounds are available.

NVD description · AI analysis pending
5.5<1%
  • systemd project systemd
CVE-2019-25566
TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the application by supplying an excessively

TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can create a malicious file with 1000 repeated characters, paste the content into the volume name field during disk image creation, and trigger an application crash.

NVD description · AI analysis pending
6.9<1% PoC
  • acutesystems transmac
CVE-2019-25545
Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long s

Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed.

NVD description · AI analysis pending
6.9<1% PoC
  • lizardsystems terminal services manager
CVE-2026-21628
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

NVD description · AI analysis pending
10.0<1%
  • templaza astroid framework
CVE-2026-26318
+1 in the same advisory: …26280
systeminformation is a System and OS information library for node.js.

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

NVD description · AI analysis pending
8.8
group max
1% PoC
  • systeminformation systeminformation
CVE-2026-25108
Authenticated OS Command Injection in Soliton FileZen Exploited in the Wild

Soliton Systems' FileZen contains an OS command injection flaw (CWE-78) that allows a logged-in user to execute arbitrary operating system commands by sending a specially crafted HTTP request. The vulnerability is only triggerable when the FileZen Antivirus Check Option is enabled, so deployments without that option are not exposed to this specific attack path. Successful exploitation yields full command execution on the host, reflected in the high confidentiality, integrity, and availability impacts and the 8.7 (High) CVSS 4.0 score. Any organization running Soliton FileZen with the Antivirus Check Option enabled is affected, particularly those exposing the management or transfer interface to untrusted networks. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-02-24, confirming active exploitation in the wild, though no public proof-of-concept is known and ransomware use is listed as unknown.

Do: Apply the vendor's mitigations or updated software per Soliton's instructions immediately, as the flaw is confirmed exploited in the wild and carries a BOD 22-01 obligation for US federal agencies. As an interim measure, consider disabling the Antivirus Check Option or restricting network access to the FileZen interface, and review web/application logs for suspicious authenticated HTTP requests or unexpected command execution. Verify current FileZen versions against the vendor/JPCERT advisory to confirm you are on a fixed release.

8.75% KEV
  • Soliton Systems K.K FileZen
nichelikely thousands of deployments, concentrated in Japan (no public install counts available)
CVE-2025-71179
Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the stri

Creativeitem Academy LMS 7.0 contains reflected Cross-Site Scripting (XSS) vulnerabilities via the search parameter to the /academy/blogs endpoint, and the string parameter to the /academy/course_bundles/search/query endpoint. These vulnerabilities are distinct from the patch for CVE-2023-4119, which only fixed XSS in query and sort_by parameters to the /academy/home/courses endpoint.

NVD description · AI analysis pending
6.1<1% PoC ×2
  • creativeitem academy lms
CVE-2021-47792
Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges.

Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the RemoteMouseService to inject malicious executables and gain administrative access.

NVD description · AI analysis pending
8.5<1% PoC
  • remotemouse remote mouse
CVE-2025-66802
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution).

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.

NVD description · AI analysis pending
9.8<1% PoC
  • covid-19 contact tracing system project covid-19 contact tracing system
CVE-2025-56425
An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earli

An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 11.10.0.183 and earlier of enaio 11.10. The vulnerability allows authenticated remote attackers to inject arbitrary SMTP commands via crafted input to the /osrest/api/organization/sendmail endpoint

NVD description · AI analysis pending
9.1<1% PoC
  • optimal-systems enaio
CVE-2023-53983
+1 in the same advisory: …58338
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed.

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.

NVD description · AI analysis pending
9.3
group max
<1% PoC
  • ateme flamingo xl firmware
  • ateme flamingo xs firmware
  • ateme soaplive
  • +1 more
CVE-2025-67013
The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) pro

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

NVD description · AI analysis pending
6.5<1% PoC
  • etlsystems d0116s1ula-22454 firmware
  • etlsystems d0116s1uia-22474 firmware
  • etlsystems c0401s1ula-22418 firmware
  • +1 more
CVE-2023-53921
SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory.

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.

NVD description · AI analysis pending
8.7<1% PoC
  • sitemagic sitemagic cms
CVE-2025-68154
systeminformation is a System and OS information library for node.js.

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch.

NVD description · AI analysis pending
8.113% PoC
  • systeminformation systeminformation
CVE-2023-53893
Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass

Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.

NVD description · AI analysis pending
5.3<1% PoC
  • ateme titan file
CVE-2023-53879
NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attackers to crash the application.

NVClient 5.0 contains a stack buffer overflow vulnerability in the user configuration contact field that allows attackers to crash the application. Attackers can overwrite 846 bytes of memory by pasting a crafted payload into the contact box, causing a denial of service condition.

NVD description · AI analysis pending
6.7<1% PoC
  • eyemaxsystems nvclient
CVE-2023-53876
Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads.

Academy LMS 6.1 contains a file upload vulnerability that allows authenticated users to upload malicious SVG files with stored cross-site scripting payloads. Attackers can inject malicious scripts through the profile avatar upload feature by modifying file extensions and embedding executable JavaScript code.

NVD description · AI analysis pending
5.1<1% PoC
  • creativeitem academy lms
CVE-2023-36337
+1 in the same advisory: …36338
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrar

A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • inventory management system project inventory management system
CVE-2025-61258
Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length.

Outsystems Platform Server 11.18.1.37828 allows attackers to cause a denial of service via a crafted content-length value mismatching the body length. NOTE: the Supplier indicates that they are unable to reproduce this.

NVD description · AI analysis pending
7.5<1% PoC
  • outsystems platform server
CVE-2022-47425
Missing Authorization vulnerability in Repute Infosystems ARMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AR

Missing Authorization vulnerability in Repute Infosystems ARMember allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ARMember: from n/a through 3.4.10.

NVD description · AI analysis pending
8.8<1%
  • reputeinfosystems armember
CVE-2025-63095
Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cause a Denial of Service (DoS

Improper input validation in the BitstreamWriter::write_bits() function of Tempus Ex hello-video-codec v0.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.

NVD description · AI analysis pending
6.5<1% PoC
  • tempus-ex hello-video-codec
CVE-2025-64030
Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager

Eximbills Enterprise 4.1.5 (Built on 2020-10-30) is vulnerable to authenticated stored cross-site scripting (CWE-79) via the /EximBillWeb/servlets/WSTrxManager endpoint. Unsanitized user input in the TMPL_INFO parameter is stored server-side and rendered to other users, enabling arbitrary JavaScript execution in their browsers.

NVD description · AI analysis pending
5.4<1% PoC
  • chinasystems eximbills enterprise