Exploit Database

148,724 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-3691 GITEE LOW javascript
layui < 2.8.0 - Cross-Site Scripting via Title Attribute
A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown part of the component HTML Attribute Handler. The manipulation of the argument title leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.8.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-234237 was assigned to this vulnerability.
by sentsim
16,635 stars
CVSS 3.5
CVE-2023-3691 GITEE LOW javascript
layui < 2.8.0 - Cross-Site Scripting via Title Attribute
A vulnerability, which was classified as problematic, was found in layui up to v2.8.0-rc.16. This affects an unknown part of the component HTML Attribute Handler. The manipulation of the argument title leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.8.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-234237 was assigned to this vulnerability.
by sentsim
16,635 stars
CVSS 3.5
CVE-2023-0909 GITEE LOW c++
cxasm notepad-- 1.22 - Denial of Service in Directory Comparison Handler
A vulnerability, which was classified as problematic, was found in cxasm notepad-- 1.22. This affects an unknown part of the component Directory Comparison Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The associated identifier of this vulnerability is VDB-221475.
by cxasm
15,338 stars
CVSS 3.3
CVE-2022-23330 GITEE HIGH java
jpress 4.2.0 - Remote Code Execution via Crafted JAR Package
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a crafted JAR package.
by fuhai
6,311 stars
CVSS 8.8
CVE-2023-42178 GITEE MEDIUM java
lenosp 1.0.0-1.2.0 - SQL Injection via Log Query Module
Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.
by bweird
6,275 stars
CVSS 6.5
CVE-2023-42180 GITEE HIGH java
lenosp 1.0-1.2.0 - Arbitrary File Upload via /user/upload Component
An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file.
by bweird
6,275 stars
CVSS 8.8
CVE-2023-7259 GITEE LOW java
zzdevelop lenosp < 20230831 - Cross-Site Scripting via Username Parameter
** DISPUTED ** A vulnerability was found in zzdevelop lenosp up to 20230831. It has been classified as problematic. This affects an unknown part of the component Adduser Page. The manipulation of the argument username with the input <script>alert(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-266127. NOTE: The vendor rejected the issue because he claims that XSS which require administrative privileges are not of any use for attackers.
by bweird
6,275 stars
CVSS 2.4
CVE-2022-26249 GITEE CRITICAL java
Survey King v0.3.0 - Code Injection
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.
by surveyking
5,811 stars
CVSS 9.8
CVE-2023-2474 GITEE MEDIUM java
Rebuild 3.2 - Cross-Site Request Forgery
A vulnerability has been found in Rebuild 3.2 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to change the configuration settings. VDB-227866 is the identifier assigned to this vulnerability.
by getrebuild
5,313 stars
CVSS 4.3
CVE-2022-34011 GITEE MEDIUM java
OneBlog v2.3.4 - Server-Side Request Forgery via entryUrls Parameter
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
by yadong.zhang
5,303 stars
CVSS 4.3
CVE-2022-34012 GITEE MEDIUM java
OneBlog v2.3.4 - Privilege Escalation
Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrators who hold greater privileges.
by yadong.zhang
5,303 stars
CVSS 6.5
CVE-2022-34013 GITEE MEDIUM java
OneBlog 2.3.4 - Server-Side Request Forgery via Logo Parameter
OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under the Link module.
by yadong.zhang
5,303 stars
CVSS 4.3
CVE-2022-4402 GITEE MEDIUM java
docsys < 2.02.37 - Path Traversal via ZIP File Decompression Handler
A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-215271.
by RainyGao
4,102 stars
CVSS 4.7
CVE-2022-4416 GITEE MEDIUM java
mxsdoc - SQL Injection via searchWord/reposId Parameter in getReposAllUsers Function
A vulnerability was found in RainyGao DocSys. It has been declared as critical. This vulnerability affects the function getReposAllUsers of the file /DocSystem/Repos/getReposAllUsers.do. The manipulation of the argument searchWord/reposId leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-215278 is the identifier assigned to this vulnerability.
by RainyGao
4,102 stars
CVSS 6.3
CVE-2022-4511 GITEE MEDIUM java
DocSys - Path Traversal in UserController#getUserImg
A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the component com.DocSystem.controller.UserController#getUserImg. The manipulation leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215851.
by RainyGao
4,102 stars
CVSS 5.3
CVE-2022-26555 GITEE MEDIUM java
Eova 1.6.0 - Stored Cross-Site Scripting via Button Name Text Box
A stored cross-site scripting (XSS) vulnerability in the Add a Button function of Eova v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the button name text box.
by jieven
3,391 stars
CVSS 5.4
CVE-2023-3029 GITEE MEDIUM php
Guangdong Pythagorean OA Office System <4.50.31 - CSRF
A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. This vulnerability affects unknown code of the file /note/index/delete. The manipulation of the argument id leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-230458 is the identifier assigned to this vulnerability.
by gougufree
3,351 stars
CVSS 4.3
CVE-2023-3035 GITEE LOW php
Guangdong Pythagorean OA Office System <4.50.31 - XSS
A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Schedule Handler. The manipulation of the argument description leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230467.
by gougufree
3,351 stars
CVSS 3.5
CVE-2023-2477 GITEE LOW php
funadmin < 3.2.3 - Cross-Site Scripting via tagLoad Function in Cx.php
A vulnerability was found in Funadmin up to 3.2.3. It has been declared as problematic. Affected by this vulnerability is the function tagLoad of the file Cx.php. The manipulation of the argument file leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227869 was assigned to this vulnerability.
by funcmf
3,230 stars
CVSS 3.5
CVE-2023-2220 GITEE LOW java
Dream Technology mica < 3.0.5 - Cross-Site Scripting in Form Object Handler
A vulnerability was found in Dream Technology mica up to 3.0.5. It has been classified as problematic. Affected is an unknown function of the component Form Object Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. VDB-226986 is the identifier assigned to this vulnerability.
by dreamlu
2,744 stars
CVSS 3.5
CVE-2024-11070 GITEE LOW java
PublicCMS 5.202406.d - Cross-Site Scripting in Tag Type Handler via Name Argument
A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of the file /admin/cmsTagType/save of the component Tag Type Handler. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
by sanluan
2,673 stars
CVSS 3.5
CVE-2024-11175 GITEE LOW java
PublicCMS 5.202406.d - Cross-Site Scripting in Voting Management
A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of the file /admin/cmsVote/save of the component Voting Management. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named b9530b9cc1f5cfdad4b637874f59029a6283a65c. It is recommended to apply a patch to fix this issue.
by sanluan
2,673 stars
CVSS 3.5
CVE-2023-30417 GITEE MEDIUM java
Pear-Admin-Boot < 2.0.2 - Stored Cross-Site Scripting via Private Message Title
A cross-site scripting (XSS) vulnerability in Pear-Admin-Boot up to v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title of a private message.
by Jmysy
2,495 stars
CVSS 5.4
CVE-2022-28930 GITEE CRITICAL java
ERP-Pro 3.7.5 - SQL Injection via SysEveMenuAuthPointMapper.xml
ERP-Pro v3.7.5 was discovered to contain a SQL injection vulnerability via the component /base/SysEveMenuAuthPointMapper.xml..
by doc_wei01_admin
2,258 stars
CVSS 9.8
CVE-2021-28890 GITEE CRITICAL java
j2eefast 2.2.1 - SQL Injection via compId deptId or roleId Parameter
J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parameter to fast/sys/role/authUser/list, related to the use of ${} to join SQL statements.
by yu199195
2,242 stars
CVSS 9.8