ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-25322
+1 in the same advisory: …25323
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.

ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.

NVD description · AI analysis pending
9.8
group max
8% PoC
  • zerof web server
CVE-2021-30176
The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.

The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.

NVD description · AI analysis pending
9.829%
  • zerof expert
CVE-2021-30175
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

NVD description · AI analysis pending
9.89%
  • zerof web server