ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-28256
A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitiv

A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.

NVD description · AI analysis pending
6.9<1%
  • trane tracer sc\+ firmware
  • trane tracer sc firmware
  • trane tracer concierge
CVE-2026-28252
+3 in the same advisory: …28253 …28255 …28254
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authenti

A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.

NVD description · AI analysis pending
9.2
group max
<1%
  • trane tracer sc firmware
  • trane tracer sc\+ firmware
  • trane tracer concierge
CVE-2023-4212
​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using

​A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

NVD description · AI analysis pending
6.81%
  • trane xl824 firmware
  • trane xl850 firmware
  • trane xl1050 firmware
  • +1 more
CVE-2021-38448
The affected controllers do not properly sanitize the input containing code syntax.

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

NVD description · AI analysis pending
7.6<1%
  • trane symbio 700
  • trane symbio 800
CVE-2021-38450
The affected controllers do not properly sanitize the input containing code syntax.

The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

NVD description · AI analysis pending
8.81%
  • trane tracer concierge
  • trane tracer sc firmware
  • trane tracer sc\+ firmware
CVE-2021-42534
The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code in the inp

The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code in the input forms.

NVD description · AI analysis pending
6.1<1%
  • trane tracer sc firmware
CVE-2017-8081
Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitr

Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.

NVD description · AI analysis pending
8.81%
  • cagintranetworks getsimple cms
CVE-2016-4526
+1 in the same advisory: …0870
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

NVD description · AI analysis pending
7.5
group max
<1%
  • trane tracer sc