ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-0528
Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1.

NVD description · AI analysis pending
7.5<1% PoC
  • transloadit uppy
CVE-2022-0086
uppy is vulnerable to Server-Side Request Forgery (SSRF)

uppy is vulnerable to Server-Side Request Forgery (SSRF)

NVD description · AI analysis pending
9.81% PoC
  • transloadit uppy
CVE-2021-44150
The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.

The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.

NVD description · AI analysis pending
7.5<1%
  • transloadit tusdotnet
CVE-2020-8205
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or

The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.

NVD description · AI analysis pending
7.51% PoC
  • transloadit uppy