ZerofCVEs & Vulnerabilities
4 CVEs affecting Zerof products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
web server 3expert 1
CVE-2022-25322KEVCRITICALin the wild
ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.
11 Apr 2026
9.8
CVSS
CVE-2022-25323MEDIUM
ZEROF Web Server 2.0 allows /admin.back XSS.
18 Feb 2022
6.1
CVSS
CVE-2021-30176CRITICAL
The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/devices/add endpoint.
13 Apr 2021
9.8
CVSS
CVE-2021-30175CRITICAL
ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
13 Apr 2021
9.8
CVSS
← PrevPage 1 / 1Next →