CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2025-32352 MEDIUM

A type confusion vulnerability in lib/NSSAuthenticator.php in ZendTo before v5.04-7 allows remote attackers to bypass authentication for users with passwords s…

CVSS 4.8 EPSS 0.33% Apr 5, 2025
CVE-2021-47667 CRITICAL

An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbit…

CVSS 10.0 EPSS 36.61% Apr 5, 2025
CVE-2024-9129 CRITICAL

Format String Injection in Zend Server

CVSS 9.3 EPSS 0.43% Oct 22, 2024
CVE-2020-29312 CRITICAL

An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been dispute…

CVSS 9.8 EPSS 1.26% Apr 4, 2023
CVE-2021-27888 MEDIUM

ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters.

CVSS 6.1 EPSS 0.65% Mar 2, 2021
CVE-2021-3007 CRITICAL

Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content…

CVSS 9.8 EPSS 75.31% Jan 4, 2021
CVE-2020-8986 CRITICAL

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain admini…

CVSS 9.8 EPSS 1.54% Mar 24, 2020
CVE-2020-8985 HIGH

ZendTo prior to 5.22-2 Beta allowed reflected XSS and CSRF via the unlock.tpl unlock user functionality.

CVSS 8.8 EPSS 0.51% Mar 24, 2020
CVE-2020-8984 HIGH

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

CVSS 7.5 EPSS 0.49% Mar 24, 2020
CVE-2014-8089 CRITICAL

SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote att…

CVSS 9.8 EPSS 2.55% Feb 17, 2020
CVE-2015-3154 MEDIUM

CRLF injection vulnerability in Zend\Mail (Zend_Mail) in Zend Framework before 1.12.12, 2.x before 2.3.8, and 2.4.x before 2.4.1 allows remote attackers to inj…

CVSS 6.1 EPSS 1.01% Jan 27, 2020
CVE-2012-4451 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unsp…

CVSS 6.1 EPSS 1.37% Jan 3, 2020
CVE-2014-4913 MEDIUM

ZF2014-03 has a potential cross site scripting vector in multiple view helpers

CVSS 6.1 EPSS 1.21% Dec 15, 2019
CVE-2011-1939 CRITICAL

SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql…

CVSS 9.8 EPSS 3.86% Nov 26, 2019
CVE-2015-0270 CRITICAL

Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.

CVSS 9.8 EPSS 1.10% Oct 25, 2019
CVE-2018-1000841 MEDIUM

Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitra…

CVSS 6.1 EPSS 0.70% Dec 20, 2018
CVE-2018-10230 MEDIUM

Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.

CVSS 6.1 EPSS 2.61% Apr 19, 2018
CVE-2014-4914 CRITICAL

The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection…

CVSS 9.8 EPSS 2.33% Dec 29, 2017
CVE-2015-7503 HIGH

Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.

CVSS 7.5 EPSS 1.36% Oct 10, 2017
CVE-2015-3257 MEDIUM

Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site script…

CVSS 6.1 EPSS 0.91% Aug 25, 2017
CVE-2015-1555 CRITICAL

Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session val…

CVSS 9.1 EPSS 1.39% Aug 7, 2017
CVE-2015-1786 HIGH

Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.

CVSS 8.8 EPSS 0.66% Jun 8, 2017
CVE-2016-6233 CRITICAL

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via ve…

CVSS 9.8 EPSS 2.05% Feb 16, 2017
CVE-2016-4861 CRITICAL

The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by lev…

CVSS 9.8 EPSS 4.12% Feb 16, 2017
CVE-2016-10034 CRITICAL

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 m…

CVSS 9.8 EPSS 38.44% Dec 30, 2016

Showing 1 to 25 CVEs · page 1 (more available)