ZeroHour

Vulnerabilities

100 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15083
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA:

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.1.20, from 3.0.0 to 3.0.12, from 3.1.0 to 3.1.4.

NVD description · AI analysis pending
4.2<1%
  • jurgenhaas eca\
CVE-2026-13234
+3 in the same advisory: …13237 …13236 …13235
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scri

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI (Artificial Intelligence) allows Cross-Site Scripting (XSS). This issue affects AI (Artificial Intelligence) versions: from 0.0.0 to 1.2.17, from 1.3.0 to 1.3.8, from 1.4.0 to 1.4.3.

NVD description · AI analysis pending
6.1
group max
<1%
  • artificial intelligence project artificial intelligence
CVE-2026-12535
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection.

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.

NVD description · AI analysis pending
9.8<1%
  • zroger formatter field
CVE-2026-59193
Grav is a file-based Web platform.

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted ZIP archive through the Direct Install tool because Installer::unZip calls ZipArchive::extractTo without limits on uncompressed size, entry count, or directory depth. This issue is fixed in version 2.0.0.

NVD description · AI analysis pending
6.9<1% PoC
  • getgrav grav
CVE-2026-56373
+1 in the same advisory: …56366
ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails.

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

NVD description · AI analysis pending
6.3
group max
<1%
  • imagemagick imagemagick
CVE-2026-56374
+1 in the same advisory: …56362
ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format.

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.

NVD description · AI analysis pending
4.8
group max
<1%
  • imagemagick imagemagick
CVE-2026-53466
ImageMagick is free and open-source software used for editing and manipulating digital images.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

NVD description · AI analysis pending
6.5
group max
<1%
  • imagemagick imagemagick
CVE-2026-56369
ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse.

ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.

NVD description · AI analysis pending
6.3
group max
<1%
  • imagemagick imagemagick
CVE-2020-37256
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration.

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.

NVD description · AI analysis pending
5.1<1%
  • getgrav grav
CVE-2026-56368
+1 in the same advisory: …56370
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed.

ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service.

NVD description · AI analysis pending
6.3
group max
<1%
  • imagemagick imagemagick
CVE-2026-56379
+2 in the same advisory: …56371 …56376
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing co

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.

NVD description · AI analysis pending
9.2
group max
<1%
  • imagemagick imagemagick
CVE-2026-48109
MessagePack for C# is a MessagePack serializer for C#.

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optional LZ4 decompression path used by MessagePack compression modes Lz4Block and Lz4BlockArray. The decoder implementation is based on a deprecated fast-decompression algorithm that does not take a source-length bound. A remote attacker can send a crafted MessagePack payload with manipulated LZ4 token/length fields to force out-of-bounds reads from the compressed input buffer. In affected environments, this can trigger an AccessViolationException during decompression, causing process termination (denial of service). Under some conditions, limited unintended memory disclosure from over-read data may also be possible before failure. This vulnerability is fixed in 2.5.301 and 3.1.7.

NVD description · AI analysis pending
8.2
group max
<1%
  • messagepack messagepack
CVE-2026-56367
+1 in the same advisory: …56378
ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) th

ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. Processing a crafted PSB file can lead to information disclosure or a crash.

NVD description · AI analysis pending
6.3<1%
  • imagemagick imagemagick
CVE-2026-48939
Unauthenticated File-Upload RCE in Joomlic iCagenda for Joomla

Joomlic's iCagenda event-management extension for Joomla contains an unrestricted file-upload flaw (CWE-434) in its file attachment feature, exploitable over the network without authentication or user interaction (CVSS 4.0 score 10.0). Because the extension accepts arbitrary file types, an attacker can upload a malicious PHP file through the attachment feature and have the web server execute it as PHP code. Successful exploitation gives unauthenticated attackers remote code execution on the affected Joomla site, which typically leads to full site or web-server compromise. Any Joomla installation running the iCagenda extension is affected; the available advisory data specifies no affected or fixed version range, so no version numbers can be stated. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-10 (reportedly exploited as a zero-day, with ransomware use currently unknown), public proof-of-concept code is available, and EPSS assigns roughly a 20% probability of exploitation within 30 days.

Do: Joomla administrators running iCagenda should update to the latest release published by Joomlic (no specific fixed version is stated in the available data) and, per the KEV required action, apply vendor mitigations in accordance with CISA BOD 26-04, prioritizing internet-exposed instances. Until patched, restrict or disable the file-attachment upload feature (e.g., prevent PHP execution/uploads in the attachments directory) and review web server logs and upload directories for unexpected .php files indicating prior compromise. Given confirmed in-the-wild exploitation reportedly predating disclosure, assume potential compromise and follow CISA's forensics triage requirements where applicable.

10.020% KEV PoC
  • Joomlic iCagenda (Joomla extension)
moderatelikely thousands to tens of thousands of Joomla sites (estimate; no install-count data in the source record)
CVE-2017-20261
Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inje

Joomla! Component Bargain Product VM3 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can supply crafted SQL statements in GET requests to the brainy and alice views to extract sensitive database information.

NVD description · AI analysis pending
8.8<1% PoC
  • weborange bargain product vm3
CVE-2017-20260
Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting

Joomla! Component Price Alert 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the product_id parameter. Attackers can send requests to the subscribeajax view with crafted SQL payloads in the product_id parameter to extract sensitive database information including credentials and configuration data.

NVD description · AI analysis pending
8.8<1% PoC
  • weborange price alert
CVE-2017-20254
Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mal

Joomla! Component User Bench 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the userid parameter. Attackers can send GET requests to index.php with the option=com_userbench&view=detail&userid parameter containing SQL injection payloads to extract sensitive database information including credentials and configuration data.

NVD description · AI analysis pending
8.8<1% PoC
  • gegabyte user bench
CVE-2017-20253
Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting ma

Joomla! Component My Projects 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the VerAyari parameter. Attackers can craft requests to the component endpoint with SQL injection payloads to extract sensitive database information including credentials and system data.

NVD description · AI analysis pending
8.8<1% PoC
  • gegabyte my projects
CVE-2017-20252
Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname p

Joomla NextGen Editor 2.1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands through the plname parameter. Attackers can send GET requests to index.php with option=com_nge&view=config and inject malicious SQL code in the plname parameter to extract sensitive database information.

NVD description · AI analysis pending
8.8<1% PoC
  • nextgeneditor nextgen editor