Zerof's vulnerability footprint centers on a small set of web-facing products—a web server and expert application—where disclosed weaknesses recur around application-layer input handling: SQL injection and cross-site scripting. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zerof over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-30175CRITICAL ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page. | Apr 13, 2021 | 9.8 | 46 | NO | YES |
CVE-2021-30176CRITICAL The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint. | Apr 13, 2021 | 9.8 | 43 | NO | NO |
CVE-2022-25322CRITICAL ZEROF Web Server 2.0 allows /HandleEvent SQL Injection. | Feb 18, 2022 | 9.8 | 38 | NO | YES |
CVE-2022-25323MEDIUM ZEROF Web Server 2.0 allows /admin.back XSS. | Feb 18, 2022 | 6.1 | 31 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zerof.
Media articles that mention a CVE ID that affects a product developed by Zerof — matched by CVE ID, not by vendor name.