ZeroHour

Vulnerabilities

85 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-21404
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation.

NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants access to privileged WCF methods, enabling an attacker to write or overwrite files within application-defined paths.

NVD description · AI analysis pending
5.8<1%
  • navtor navbox firmware
CVE-2026-30162
Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.

Cross Site Scripting (xss) vulnerability in Timo 2.0.3 via crafted links in the title field.

NVD description · AI analysis pending
6.1<1% PoC
  • auntvt timo
CVE-2026-2754
+2 in the same advisory: …2753 …2752
Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints.

Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to the device can execute HTTP GET requests to TCP port 8080 to retrieve internal network parameters including ECDIS & OT Information, device identifiers, and service status logs.

NVD description · AI analysis pending
7.5
group max
<1%
  • navtor navbox firmware
CVE-2026-25538
Devtron is an open source tool integration platform for Kubernetes.

Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API interface, allowing any authenticated user (including low-privileged CI/CD Developers) to obtain the global API Token signing key by accessing the /orchestrator/attributes?key=apiTokenSecret endpoint. After obtaining the key, attackers can forge JWT tokens for arbitrary user identities offline, thereby gaining complete control over the Devtron platform and laterally moving to the underlying Kubernetes cluster. This issue has been patched via commit d2b0d26.

NVD description · AI analysis pending
8.7<1% PoC
  • devtron devtron
CVE-2022-50928
BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arb

BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in 'C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe' to inject malicious executables and escalate privileges.

NVD description · AI analysis pending
8.5<1% PoC
  • ivtcorporation bluesoleilcs
CVE-2026-22685
DevToys is a desktop app for developers.

DevToys is a desktop app for developers. In versions from 2.0.0.0 to before 2.0.9.0, a path traversal vulnerability exists in the DevToys extension installation mechanism. When processing extension packages (NUPKG archives), DevToys does not sufficiently validate file paths contained within the archive. A malicious extension package could include crafted file entries such as ../../…/target-file, causing the extraction process to write files outside the intended extensions directory. This flaw enables an attacker to overwrite arbitrary files on the user’s system with the privileges of the DevToys process. Depending on the environment, this may lead to code execution, configuration tampering, or corruption of application or system files. This issue has been patched in version 2.0.9.0.

NVD description · AI analysis pending
9.8<1%
  • devtoys devtoys
CVE-2025-57201
+4 in the same advisory: …57199 …57198 …57200 …57202
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server fun

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

NVD description · AI analysis pending
8.8
group max
17% PoC
  • avtech dgm1104 firmware
CVE-2025-57108
+2 in the same advisory: …57106 …57107
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader.

Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • vtk vtk
CVE-2025-46408
+1 in the same advisory: …50944
An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH Eagl

An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • avtech eagleeyes\(lite\)
CVE-2025-7231
+4 in the same advisory: …7230 …7229 …7228 …7227
INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.

INVT VT-Designer PM3 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of INVT VT-Designer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PM3 files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25724.

NVD description · AI analysis pending
7.8<1%
  • invt vt designer
CVE-2025-7226
+3 in the same advisory: …7225 …7224 …7223
INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability.

INVT HMITool VPM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of INVT HMITool. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of VPM files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25048.

NVD description · AI analysis pending
7.8<1%
  • invt hmitool
CVE-2025-34036
Unauthenticated command-injection RCE in TVT white-label DVR 'Cross Web Server'

An unauthenticated OS command injection vulnerability (CWE-78) exists in the 'Cross Web Server' custom HTTP service embedded in white-labeled DVRs manufactured by TVT, which listens on TCP ports 81 and 82. When the service handles a request for /language/[lang]/index.html, it passes the [lang] portion of the URI path into a tar extraction command without sanitization or escaping, allowing an attacker to append arbitrary shell commands to the request. Because the web service runs as root, successful injection results in arbitrary command execution with full root privileges on the device. Any TVT-manufactured white-label DVR running the affected Cross Web Server software — including the listed TD-series models, which are sold under many rebrand names — is affected when the service is reachable by an attacker. Exploitation in the wild was observed by the Shadowserver Foundation on 2025-02-06 UTC, and with public exploit code documented since 2016, a maximum CVSS 4.0 score of 10.0, and a 26.9% EPSS probability of exploitation within 30 days, defenders should assume active scanning and compromise attempts.

Do: Inventory all TVT-based and white-label DVRs exposing the Cross Web Server on TCP ports 81/82, restrict access with firewall rules or VPN rather than direct internet port forwarding, and obtain patched firmware from your DVR brand/vendor (TVT OEM) as it becomes available, since no fixed version numbers are provided in the available data. Because exploitation yields root-level code execution, treat any device showing signs of compromise — requests to /language/[lang]/index.html paths, unexpected processes, or unexplained outbound connections since 2025-02-06 — as fully compromised and reflash or replace it. Continue monitoring vendor advisories and Shadowserver/CISA reporting for updated indicators of compromise and patch guidance.

10.027% PoC ×2
  • tvt td-2108ts-cl firmware
  • tvt td-2108ts-cl-a firmware
  • tvt td-2116ts-cl firmware
  • +9 more
mass≈100,000+ internet-exposed TVT-based DVRs (order-of-magnitude estimate)
CVE-2025-34034
+1 in the same advisory: …34033
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems.

A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded Linux systems. The application contains multiple known default and hardcoded user accounts that are not disclosed in public documentation. These accounts allow unauthenticated or low-privilege attackers to gain administrative access to the device’s web interface. Exploitation evidence was observed by the Shadowserver Foundation on 2025-01-26 UTC.

NVD description · AI analysis pending
9.3
group max
<1% PoC
  • 5vtechnologies blue angel software suite
CVE-2025-45753
+1 in the same advisory: …45755
A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import fun

A vulnerability in Vtiger CRM Open Source Edition v8.3.0 allows an attacker with admin privileges to execute arbitrary PHP code by exploiting the ZIP import functionality in the Module Import feature.

NVD description · AI analysis pending
7.2
group max
<1%
  • vtiger vtiger crm
CVE-2025-1618
A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic.

A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.0 is able to address this issue. It is recommended to upgrade the affected component.

NVD description · AI analysis pending
5.3<1%
  • vtiger vtiger crm
CVE-2024-54687
Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.

NVD description · AI analysis pending
6.1<1% PoC
  • vtiger vtiger crm
CVE-2024-45794
devtron is an open source tool integration platform for Kubernetes.

devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection to allow the execution of malicious SQL queries via CreateUser API (/orchestrator/user). This issue has been addressed in version 0.7.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

NVD description · AI analysis pending
8.8<1% PoC
  • devtron devtron
CVE-2024-49624
Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This issue affects

Deserialization of Untrusted Data vulnerability in smartdevth Advanced Advertising System advanced-advertising-system allows Object Injection.This issue affects Advanced Advertising System: from n/a through <= 1.3.1.

NVD description · AI analysis pending
9.8<1%
  • smartdevth advanced advertising system
CVE-2024-48119
Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter.

Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

NVD description · AI analysis pending
5.4<1% PoC
  • vtiger vtiger crm
CVE-2024-44779
+3 in the same advisory: …44778 …44777 …44776
A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code

A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload.

NVD description · AI analysis pending
9.6
group max
<1%
  • vtiger vtiger crm
CVE-2024-39776
+1 in the same advisory: …42418
Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

NVD description · AI analysis pending
8.7<1%
  • avtecinc outpost uploader utility
  • avtecinc outpost 0810 firmware
CVE-2024-42995
+1 in the same advisory: …42994
VTiger CRM <= 8.1.0 does not correctly check user privileges.

VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.

NVD description · AI analysis pending
8.3
group max
<1% PoC
  • vtiger vtiger crm
CVE-2024-7029
Commands can be injected over the network and executed without authentication.

Commands can be injected over the network and executed without authentication.

NVD description · AI analysis pending
8.739% PoC
  • avtech avm1203 firmware
CVE-2024-7339
A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problemati

A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION DVR AV108T and classified as problematic. This vulnerability affects unknown code of the file /queryDevInfo. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273262 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
6.932% PoC
  • provision-isr sh-4050a5-5l\(mm\) firmware
  • provision-isr avision av108t firmware
  • provision-isr td-2104ts-cl firmware
  • +1 more
CVE-2023-46304
modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code to the config.inc.php file (executed on every page load).

NVD description · AI analysis pending
8.12% PoC
  • vtiger vtiger crm
CVE-2024-22824
An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.

An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.

NVD description · AI analysis pending
9.81% PoC
  • auntvt timo
CVE-2023-38891
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRu

SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.

NVD description · AI analysis pending
8.8<1%
  • vtiger vtiger crm