Zero-day Vulnerabilities
These are the zero-day vulnerabilities discovered and published by the Help AG penetration testing team. Over a hundred and counting.
Dec 2025
CVE-2025-55182
React2Shell: The maximum-severity RCE Vulnerability affecting React Server Components and Next.js
19 Sep 2025
CVE-2025–57644
Remote Code Execution in Accela Automation Platform
28 March 2025
CVE-2025-22953
Unauthenticated blind SQL Injection on Epicor HCM
14 May 2024
CVE-2024-21760
Code injection in playbook code snippet step
04 January 2018
CVE-2018-8045
Error based SQL Injection on Joomla core
04 January 2018
CVE-2018-7708
WordPress through 4.9.4 has XSS via the checked array parameter