ZeroHour

Vulnerabilities

41 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-35546
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads.

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.

NVD description · AI analysis pending
9.8
group max
<1%
  • anviz cx7 firmware
  • anviz cx2 lite firmware
CVE-2026-40434
+1 in the same advisory: …32650
Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to alter or di

Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an attacker on the same network to alter or disrupt application traffic.

NVD description · AI analysis pending
8.1
group max
<1%
  • anviz crosschex standard
CVE-2026-35682
Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), r

Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑level access.

NVD description · AI analysis pending
8.82%
  • anviz cx2 lite firmware
CVE-2024-36400
nano-id is a unique string ID generator for Rust.

nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the `nano_id::base62` and `nano_id::base58` functions. Specifically, the `base62` function used a character set of 32 symbols instead of the intended 62 symbols, and the `base58` function used a character set of 16 symbols instead of the intended 58 symbols. Additionally, the `nano_id::gen` macro is also affected when a custom character set that is not a power of 2 in size is specified. It should be noted that `nano_id::base64` is not affected by this vulnerability. This can result in a significant reduction in entropy, making the generated IDs predictable and vulnerable to brute-force attacks when the IDs are used in security-sensitive contexts such as session tokens or unique identifiers. The vulnerability is fixed in 0.4.0.

NVD description · AI analysis pending
9.8<1% PoC
  • viz nano id
CVE-2023-46045
Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file.

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.

NVD description · AI analysis pending
7.8<1% PoC
  • graphviz graphviz
CVE-2023-41613
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.

EzViz Studio v2.2.0 is vulnerable to DLL hijacking.

NVD description · AI analysis pending
7.8<1% PoC
  • ezviz ezviz studio
CVE-2023-48121
An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x bu

An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows remote attackers to obtain sensitive information by sending crafted messages to the affected devices.

NVD description · AI analysis pending
5.3<1%
  • ezviz cs-c6n-a0-1c2wfr firmware
  • ezviz cs-cv310-a0-1c2wfr firmware
  • ezviz cs-c6cn-a0-3h2wfr firmware
  • +1 more
CVE-2023-34552
+1 in the same advisory: …34551
In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type functions of the SADP multicast protocol ca

In certain EZVIZ products, two stack based buffer overflows in mulicast_parse_sadp_packet and mulicast_get_pack_type functions of the SADP multicast protocol can allow an unauthenticated attacker present on the same local network as the camera to achieve remote code execution. This affects CS-C6N-B0-1G2WF Firmware versions before V5.3.0 build 230215 and CS-C6N-R101-1G2WF Firmware versions before V5.3.0 build 230215 and CS-CV310-A0-1B2WFR Firmware versions before V5.3.0 build 230221 and CS-CV310-A0-1C2WFR-C Firmware versions before V5.3.2 build 230221 and CS-C6N-A0-1C2WFR-MUL Firmware versions before V5.3.2 build 230218 and CS-CV310-A0-3C2WFRL-1080p Firmware versions before V5.2.7 build 230302 and CS-CV310-A0-1C2WFR Wifi IP66 2.8mm 1080p Firmware versions before V5.3.2 build 230214 and CS-CV248-A0-32WMFR Firmware versions before V5.2.3 build 230217 and EZVIZ LC1C Firmware versions before V5.3.4 build 230214.

NVD description · AI analysis pending
8.8
group max
<1%
  • ezviz cs-c6n-b0-1g2wf firmware
  • ezviz cs-c6n-r101-1g2wf firmware
  • ezviz cs-cv310-a0-1b2wfr firmware
  • +1 more
CVE-2023-23809
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Moris Dov Stock market charts from finviz plugin <= 1.0.1 versions.

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Moris Dov Stock market charts from finviz plugin <= 1.0.1 versions.

NVD description · AI analysis pending
4.8<1%
  • finviz stock market charts from finviz
CVE-2022-4232
+1 in the same advisory: …4233
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0.

A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. Affected is an unknown function. The manipulation of the argument cmd leads to unrestricted upload. It is possible to launch the attack remotely. VDB-214590 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.8
group max
<1%
  • rinvizle event registration system
CVE-2022-2471
+1 in the same advisory: …2472
Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6

Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A0-3H4WFRL allows a remote attacker to execute remote code on the device. This issue affects: EZVIZ CS-CV248 versions prior to 5.2.3 build 220725. EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428. EZVIZ CS-DB1C-A0-1E2W2FR versions prior to 5.3.0 build 220802. EZVIZ CS-C6N-B0-1G2WF versions prior to 5.3.0 build 220712. EZVIZ CS-C3W-A0-3H4WFRL versions prior to 5.3.5 build 220723.

NVD description · AI analysis pending
9.8
group max
1%
  • ezviz cs-c6n-a0-1c2wfr firmware
  • ezviz cs-db1c-a0-1e2w2fr firmware
  • ezviz cs-c6n-b0-1g2wf firmware
  • +1 more
CVE-2021-27944
Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat

Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality, leading to OS command execution. The specific attack methodology is a file upload.

NVD description · AI analysis pending
9.84% PoC
  • vizio p65-f1 firmware
  • vizio e50x-e1 firmware
CVE-2021-27942
Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality, beca

Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB drive via the Smart Cast functionality, because files on the USB drive are effectively under the web root and can be executed.

NVD description · AI analysis pending
6.8<1% PoC
  • vizio p65-f1 firmware
  • vizio e50x-e1 firmware
CVE-2021-27943
The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (agains

The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vulnerable to a brute-force attack (against only 10000 possibilities), allowing a threat actor to forcefully pair the device, leading to remote control of the TV settings and configurations.

NVD description · AI analysis pending
7.5<1% PoC
  • vizio p65-f1 firmware
  • vizio e50x-e1 firmware
CVE-2020-18032
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of

Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.

NVD description · AI analysis pending
7.83% PoC
  • graphviz graphviz
  • graphviz debian linux
  • graphviz fedora
CVE-2020-7747
This affects all versions of package lightning-server.

This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.

NVD description · AI analysis pending
6.3<1% PoC ×2
  • lightning-viz lightning
CVE-2019-12518
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.

Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.

NVD description · AI analysis pending
9.851% PoC
  • anviz crosschex
CVE-2019-12394
+2 in the same advisory: …12391 …12393
Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.

Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.

NVD description · AI analysis pending
9.8
group max
2%
  • anviz management system
CVE-2019-12392
+3 in the same advisory: …12389 …12388 …12390
Anviz access control devices allow remote attackers to issue commands without a password.

Anviz access control devices allow remote attackers to issue commands without a password.

NVD description · AI analysis pending
9.8
group max
2%
  • anviz anviz firmware
CVE-2019-11523
Anviz Global M3 Outdoor RFID Access Control executes any command received from any source.

Anviz Global M3 Outdoor RFID Access Control executes any command received from any source. No authentication/encryption is done. Attackers can fully interact with the device: for example, send the "open door" command, download the users list (which includes RFID codes and passcodes in cleartext), or update/create users. The same attack can be executed on a local network and over the internet (if the device is exposed on a public IP address).

NVD description · AI analysis pending
9.81% PoC
  • anviz m3 firmware
CVE-2019-11023
The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.

The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as demonstrated by graphml2gv.

NVD description · AI analysis pending
8.85% PoC ×2
  • graphviz graphviz
CVE-2019-9904
An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1.

An issue was discovered in lib\cdt\dttree.c in libcdt.a in graphviz 2.40.1. Stack consumption occurs because of recursive agclose calls in lib\cgraph\graph.c in libcgraph.a, related to agfstsubg in lib\cgraph\subg.c.

NVD description · AI analysis pending
6.53% PoC ×2
  • graphviz graphviz
CVE-2018-13723
The mintToken function of a smart contract implementation for SERVVIZIOToken, an Ethereum token, has an integer overflow that allows the owner of the contract t

The mintToken function of a smart contract implementation for SERVVIZIOToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

NVD description · AI analysis pending
7.51% PoC
  • servviziotoken project servviziotoken
CVE-2018-10196
NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to c

NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.

NVD description · AI analysis pending
5.52%
  • graphviz graphviz
  • graphviz fedora
  • graphviz ubuntu linux