ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-61498
+1 in the same advisory: …60121
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticate

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.

NVD description · AI analysis pending
9.34% PoC ×2
  • vitec flamingo
CVE-2021-42109
VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.

VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.

NVD description · AI analysis pending
9.82% PoC
  • vitec exterity avediaserver
  • vitec exterity avediastream encoders firmware
  • vitec avediastream m9605 firmware
  • +1 more
CVE-2017-9758
Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible Subversion

Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible Subversion."

NVD description · AI analysis pending
7.41% PoC
  • savitech-ic savitech driver
CVE-2017-9625
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5.

An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely.

NVD description · AI analysis pending
8.22%
  • envitech envidas ultimate