ZeroHour

Vulnerabilities

38 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-5789
Vulnerability related to an unquoted search path in CivetWeb v1.16.

Vulnerability related to an unquoted search path in CivetWeb v1.16. This vulnerability allows a local attacker to execute arbitrary code with elevated privileges by placing a malicious executable in a directory that is scanned before the intended application path (C:\Program Files\CivetWeb\CivetWeb.exe --), due to the absence of quotes in the service configuration.

NVD description · AI analysis pending
8.5<1%
  • civetweb project civetweb
CVE-2025-13250
+1 in the same advisory: …13251
A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2.

A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job Handler. Performing manipulation results in improper access controls. The attack may be initiated remotely. The exploit is now public and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • datax-web project datax-web
CVE-2025-55763
Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request.

Buffer Overflow in the URI parser of CivetWeb 1.14 through 1.16 (latest) allows a remote attacker to achieve remote code execution via a crafted HTTP request. This vulnerability is triggered during request processing and may allow an attacker to corrupt heap memory, potentially leading to denial of service or arbitrary code execution.

NVD description · AI analysis pending
7.51% PoC
  • civetweb project civetweb
CVE-2025-27590
Unauthenticated Path Traversal in Oxidized Web RANCID Migration Page

CVE-2025-27590 is a path traversal flaw (CWE-22) in the RANCID migration page of oxidized-web, the web interface for the Oxidized network device configuration backup tool, affecting all versions before 0.15.0. An unauthenticated attacker can send a crafted HTTP request to the migration page with attacker-controlled path input, allowing them to manipulate files on the host as the service. As a result, the attacker gains control over the Linux user account under which oxidized-web runs, which typically means the ability to read, write, or execute as that account on the Oxidized server — a system that stores network device credentials and configurations. Any deployment running oxidized-web prior to 0.15.0 is affected, including installations where the web interface is exposed to untrusted networks. Exploitation has not been observed in the wild and no public proof-of-concept is known, but the 27.6% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within 30 days.

Do: Upgrade oxidized-web to version 0.15.0 or later. Until then, restrict access to the oxidized-web interface to trusted management networks via firewall rules, ACLs, or an authenticating reverse proxy, since the vulnerable page requires no authentication. Also audit the Linux account running oxidized-web (e.g., check authorized_keys, cron jobs, and recent activity) for signs of compromise.

9.828%
  • oxidized web project oxidized web all versions before 0.15.0
nichelikely low thousands of deployments worldwide, mostly on internal management networks; internet-exposed instances probably in the hundreds
CVE-2024-12358
A vulnerability was found in WeiYe-Jing datax-web 2.1.1.

A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.35% PoC
  • datax-web project datax-web
CVE-2022-4960
A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0.

A vulnerability, which was classified as problematic, has been found in cloudfavorites favorites-web 1.3.0. Affected by this issue is some unknown functionality of the component Nickname Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-250238 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
5.4<1% PoC
  • favorites-web project favorites-web
CVE-2023-7116
A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2.

A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue is some unknown functionality of the file /api/log/killJob of the component HTTP POST Request Handler. The manipulation of the argument processId leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249086 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.810% PoC
  • datax-web project datax-web
CVE-2023-25015
Clockwork Web before 0.1.2, when Rails before 5.2 is used, allows CSRF.

Clockwork Web before 0.1.2, when Rails before 5.2 is used, allows CSRF.

NVD description · AI analysis pending
6.5<1%
  • clockwork web project clockwork web
CVE-2023-0287
A vulnerability was found in ityouknow favorites-web.

A vulnerability was found in ityouknow favorites-web. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Comment Handler. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-218294 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
5.4<1% PoC
  • favorites-web project favorites-web
CVE-2022-46478
The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via cra

The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian serialized data.

NVD description · AI analysis pending
9.81% PoC
  • datax-web project datax-web
CVE-2021-4236
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to

Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.

NVD description · AI analysis pending
9.81% PoC
  • web project web
CVE-2019-25088
A vulnerability was found in ytti Oxidized Web.

A vulnerability was found in ytti Oxidized Web. It has been classified as problematic. Affected is an unknown function of the file lib/oxidized/web/views/conf_search.haml. The manipulation of the argument to_research leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
5.4<1%
  • oxidized web project oxidized web
CVE-2020-24600
Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.

Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.

NVD description · AI analysis pending
9.8<1% PoC
  • capexweb project capexweb
CVE-2022-31542
The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

NVD description · AI analysis pending
9.31% PoC
  • mdweb project mdweb
CVE-2022-31534
The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

NVD description · AI analysis pending
9.31% PoC
  • pythonweb project pythonweb
CVE-2022-31504
The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used uns

The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

NVD description · AI analysis pending
9.31% PoC ×2
  • baiduwenkuspider flaskweb project baiduwenkuspider flaskweb
CVE-2021-43725
There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web scri

There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.

NVD description · AI analysis pending
6.13% PoC
  • spotweb project spotweb
CVE-2021-33966
Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

Cross site scripting (XSS) vulnerability in spotweb 1.4.9, allows authenticated attackers to execute arbitrary code via crafted GET request to the login page.

NVD description · AI analysis pending
5.4<1% PoC
  • spotweb project spotweb
CVE-2020-27304
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mech

The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled filename in the output path, are susceptible to directory traversal

NVD description · AI analysis pending
9.83% PoC
  • civetweb project civetweb
  • civetweb project sinec infrastructure network services
CVE-2021-41568
Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and u

Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in the system.

NVD description · AI analysis pending
6.51%
  • tad web project tad web
CVE-2021-40973
Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web scrip

Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the lastname parameter.

NVD description · AI analysis pending
6.12% PoC
  • spotweb project spotweb
CVE-2021-23404
This affects all versions of package sqlite-web.

This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack.

NVD description · AI analysis pending
8.8<1% PoC
  • sqlite-web project sqlite-web
CVE-2021-3286
SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used.

SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variation of the payload may be used. NOTE: this issue exists because of an incomplete fix for CVE-2020-35545.

NVD description · AI analysis pending
9.81%
  • spotweb project spotweb
CVE-2020-35545
Time-based SQL injection exists in Spotweb 1.4.9 via the query string.

Time-based SQL injection exists in Spotweb 1.4.9 via the query string.

NVD description · AI analysis pending
9.84%
  • spotweb project spotweb
CVE-2019-10185
+2 in the same advisory: …10181 …10182
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file.

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

NVD description · AI analysis pending
8.6
group max
4%
  • icedtea-web project icedtea-web
  • icedtea-web project debian linux
  • icedtea-web project leap
CVE-2018-16450
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.

CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • craftedweb project craftedweb
CVE-2018-12919
In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.

In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • craftedweb project craftedweb
CVE-2018-12684
Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure

Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.

NVD description · AI analysis pending
7.11%
  • civetweb project civetweb
CVE-2017-12097
An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails gem version 1.4.

An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails gem version 1.4. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.

NVD description · AI analysis pending
6.11% PoC
  • delayed job web project delayed job web
CVE-2017-6087
EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in

EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in module/monitoring_ged/ged_functions.php or the (4) module parameter to module/index.php.

NVD description · AI analysis pending
8.87% PoC
  • eonweb project eonweb