Java Exploits

370 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-9005 GITEE LOW java
mtons mblog < 3.5.0 - Information Exposure via Error Message in Registration Endpoint
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
by mtons
3,324 stars
CVSS 3.7
CVE-2025-9407 GITEE LOW java
mblog < 3.5.0 - Cross-Site Scripting via Profile Settings Signature Parameter
A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing manipulation of the argument signature can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Other parameters might be affected as well.
by mtons
3,324 stars
CVSS 3.5
CVE-2025-9429 GITEE LOW java
mblog < 3.5.0 - Cross-Site Scripting via Post Handler Content/Title Parameter
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulation of the argument content/title/ leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
by mtons
3,324 stars
CVSS 3.5
CVE-2025-9429 GITEE LOW java
mblog < 3.5.0 - Cross-Site Scripting via Post Handler Content/Title Parameter
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulation of the argument content/title/ leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
by mtons
3,324 stars
CVSS 3.5
CVE-2025-9430 GITEE LOW java
mtons mblog < 3.5.0 - Cross-Site Scripting via /admin/options/update Input Parameter
A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
by mtons
3,324 stars
CVSS 2.4
CVE-2025-9431 GITEE MEDIUM java
mtons mblog < 3.5.0 - Cross-Site Scripting via Search Endpoint kw Parameter
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-9432 GITEE MEDIUM java
mtons mblog < 3.5.0 - Cross-Site Scripting via Admin Panel Title Parameter
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation of the argument Title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-9433 GITEE MEDIUM java
mtons mblog < 3.5.0 - Cross-Site Scripting via Admin Panel Name Parameter
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-9647 GITEE MEDIUM java
mtons mblog < 3.5.0 - Cross-Site Scripting via /admin/role/list Name Parameter
A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-8752 GITEE HIGH java
wangzhixuan spring-shiro-training - OS Command Injection via /role/add Endpoint
A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This vulnerability affects unknown code of the file /role/add. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
by wangzhixuan
2,385 stars
CVSS 7.3
CVE-2025-8815 GITEE HIGH java
Morning - Path Traversal in Shiro Configuration
A vulnerability was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. It has been classified as critical. Affected is an unknown function of the file /index of the component Shiro Configuration. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
by morning-pro
2,312 stars
CVSS 7.3
CVE-2025-8123 GITEE MEDIUM java
deer-wms-2 < 3.3 - SQL Injection via /system/dept/edit Ancestors Parameter
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8124 GITEE MEDIUM java
deer-wms-2 < 3.3 - SQL Injection via params[dataScope]
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/unallocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8125 GITEE MEDIUM java
deer-wms-2 < 3.3 - SQL Injection via params[dataScope]
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/role/authUser/allocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8126 GITEE MEDIUM java
deer-wms-2 < 3.3 - SQL Injection via params[dataScope]
A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8127 GITEE MEDIUM java
deer-wms-2 < 3.3 - SQL Injection via params[dataScope]
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. This vulnerability affects unknown code of the file /system/user/list. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8161 GITEE MEDIUM java
deer-wms-2 < 3.3 - SQL Injection via /system/role/export params[dataScope]
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. Affected by this vulnerability is an unknown functionality of the file /system/role/export. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8162 GITEE MEDIUM java
deer-wms-2 < 3.3 - SQL Injection via params[dataScope]
A vulnerability, which was classified as critical, has been found in deerwms deer-wms-2 up to 3.3. Affected by this issue is some unknown functionality of the file /system/dept/list. The manipulation of the argument params[dataScope] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8163 GITEE MEDIUM java
deer-wms-2 < 3.3 - SQL Injection via params[dataScope]
A vulnerability, which was classified as critical, was found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/role/list. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2026-23552 GITHUB CRITICAL java
Apache Camel 4.15.0-4.17.0 - Auth Bypass
Cross-Realm Token Acceptance Bypass in KeycloakSecurityPolicy Apache Camel Keycloak component.  The Camel-Keycloak KeycloakSecurityPolicy does not validate the iss (issuer) claim of JWT tokens against the configured realm. A token issued by one Keycloak realm is silently accepted by a policy configured for a completely different realm, breaking tenant isolation. This issue affects Apache Camel: from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue.
by oscerd
CVSS 9.1
CVE-2026-25747 GITHUB HIGH java
Apache Camel LevelDB - Deserialization
Deserialization of Untrusted Data vulnerability in Apache Camel LevelDB component. The Camel-LevelDB DefaultLevelDBSerializer class deserializes data read from the LevelDB aggregation repository using java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. An attacker who can write to the LevelDB database files used by a Camel application can inject a crafted serialized Java object that, when deserialized during normal aggregation repository operations, results in arbitrary code execution in the context of the application. This issue affects Apache Camel: from 4.10.0 before 4.10.8, from 4.14.0 before 4.14.5, from 4.15.0 before 4.18.0. Users are recommended to upgrade to version 4.18.0, which fixes the issue. For the 4.10.x LTS releases, users are recommended to upgrade to 4.10.9, while for 4.14.x LTS releases, users are recommended to upgrade to 4.14.5
by oscerd
CVSS 8.8
CVE-2025-63497 GITHUB HIGH java
Rickxy Hospital Management System <1.0 - SQL Injection
The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role) to execute arbitrary SQL queries.
by cristibtz
1 stars
CVSS 7.1
CVE-2025-62369 GITHUB HIGH java
Xibo 4.1.0-4.3.0 - Authenticated Remote Code Execution via CMS Developer Module Templating
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authenticated users with "System -> Add/Edit custom modules and templates" permissions to manipulate Twig filters and execute arbitrary server-side functions as the web server user. This issue is fixed in version 4.3.1. To workaround this issue, use the 4.1 and 4.2 patch commits.
by cristibtz
1 stars
CVSS 7.2
CVE-2025-49619 GITHUB HIGH java
Skyvern SSTI Remote Code Execution
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE).
by cristibtz
1 stars
CVSS 8.5
CVE-2025-27636 GITHUB MEDIUM java
Apache Camel <4.10.2 - Command Injection
Bypass/Injection vulnerability in Apache Camel components under particular conditions. This issue affects Apache Camel: from 4.10.0 through <= 4.10.1, from 4.8.0 through <= 4.8.4, from 3.10.0 through <= 3.22.3. Users are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases. This vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can alter the behaviours such as the camel-bean component, to call another method on the bean, than was coded in the application. In the camel-jms component, then a malicious header can be used to send the message to another queue (on the same broker) than was coded in the application. This could also be seen by using the camel-exec component The attacker would need to inject custom headers, such as HTTP protocols. So if you have Camel applications that are directly connected to the internet via HTTP, then an attacker could include malicious HTTP headers in the HTTP requests that are send to the Camel application. All the known Camel HTTP component such as camel-servlet, camel-jetty, camel-undertow, camel-platform-http, and camel-netty-http would be vulnerable out of the box. In these conditions an attacker could be able to forge a Camel header name and make the bean component invoking other methods in the same bean. In terms of usage of the default header filter strategy the list of components using that is: * camel-activemq * camel-activemq6 * camel-amqp * camel-aws2-sqs * camel-azure-servicebus * camel-cxf-rest * camel-cxf-soap * camel-http * camel-jetty * camel-jms * camel-kafka * camel-knative * camel-mail * camel-nats * camel-netty-http * camel-platform-http * camel-rest * camel-sjms * camel-spring-rabbitmq * camel-stomp * camel-tahu * camel-undertow * camel-xmpp The vulnerability arises due to a bug in the default filtering mechanism that only blocks headers starting with "Camel", "camel", or "org.apache.camel.".  Mitigation: You can easily work around this in your Camel applications by removing the headers in your Camel routes. There are many ways of doing this, also globally or per route. This means you could use the removeHeaders EIP, to filter out anything like "cAmel, cAMEL" etc, or in general everything not starting with "Camel", "camel" or "org.apache.camel.".
by Crystallen1
CVSS 5.6