VendorsZimaspacezimaosany version
Vulnerabilities

Zimaspace IceWhale Technology ZimaOS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-28798
Arbitrary internal service access via /v1/sys/proxy when Cloudflare Tunnel is enabled on ZimaOS
Published 2026-04-03 · Analyzed
10.0EPSS 0.005
CVE-2026-21891
ZimaOS has Authentication Bypass via System-Level Username
Published 2026-01-08 · Analyzed
9.8EPSS 0.024
CVE-2025-58432
ZimaOS Privilege Escalation using localhost calls to File API Upload
Published 2025-09-17 · Analyzed
7.8EPSS 0.002
CVE-2024-49357
ZimaOS (Installed Applications and System Information) has Unauthorized Sensitive Data Leak
Published 2024-10-24 · Analyzed
7.5EPSS 0.237
CVE-2024-49359
ZimaOS vulnerable to Directory Listing via Parameter Manipulation
Published 2024-10-24 · Analyzed
7.5EPSS 0.010
CVE-2024-48931
ZimaOS Arbitrary File Read via Parameter Manipulation
Published 2024-10-24 · Analyzed
7.5EPSS 0.007
CVE-2025-64427
ZimaOS is vulnerable to Server-Side Request Forgery (SSRF)
Published 2026-03-02 · Analyzed
7.1EPSS 0.002
CVE-2025-58431
ZimaOS reads arbitrary files using localhost calls to File API Download
Published 2025-09-17 · Analyzed
6.2EPSS 0.002
CVE-2024-48932
ZimaOS Unauthenticated API Discloses Usernames
Published 2024-10-24 · Modified
5.3EPSS 0.005
CVE-2024-49358
ZimaOS vulnerable to Username Enumeration via API Responses
Published 2024-10-24 · Analyzed
5.3EPSS 0.005