Vulnerabilities > Zerof

DATE CVE VULNERABILITY TITLE RISK
2022-02-18 CVE-2022-25322 SQL Injection vulnerability in Zerof web Server 2.0
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
network
low complexity
zerof CWE-89
7.5
2022-02-18 CVE-2022-25323 Cross-site Scripting vulnerability in Zerof web Server 2.0
ZEROF Web Server 2.0 allows /admin.back XSS.
network
zerof CWE-79
4.3
2021-04-13 CVE-2021-30176 SQL Injection vulnerability in Zerof Expert 2.0
The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.
network
low complexity
zerof CWE-89
7.5
2021-04-13 CVE-2021-30175 SQL Injection vulnerability in Zerof web Server 1.0
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
network
low complexity
zerof CWE-89
7.5