Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-25322 +1 in the same advisory: …25323 | ZEROF Web Server 2.0 allows /HandleEvent SQL Injection. ZEROF Web Server 2.0 allows /HandleEvent SQL Injection. NVD description · AI analysis pending | 9.8 group max | 8% | PoC |
| — | |
| CVE-2021-30176 | The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint. The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint. NVD description · AI analysis pending | 9.8 | 29% |
| — | ||
| CVE-2021-30175 | ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page. ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page. NVD description · AI analysis pending | 9.8 | 9% |
| — |