Skip to content
Noroxi

hutool records

15 published records for vendor hutool.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
73.3%
Median publish → KEV
No record has entered KEV

All records

15 records
  • SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.

    CriticalCVSS 9.8No exploitEPSS 1%

    hutool · hutoolJan 31, 2023

  • Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.

    CriticalCVSS 9.8No exploitEPSS 1%

    hutool · hutoolFeb 16, 2022

  • Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml paramete

    CriticalCVSS 9.8No exploitEPSS 1%

    hutool · hutoolJan 31, 2023

  • hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.

    CriticalCVSS 9.8No exploitEPSS 1%

    hutool · hutoolSep 8, 2023

  • hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.

    CriticalCVSS 9.8No exploitEPSS 1%

    hutool · hutoolSep 8, 2023

  • The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequ

    HighCVSS 7.5Proof of conceptEPSS 3%

    hutool · hutoolSep 21, 2018

  • A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JS

    HighCVSS 7.5Proof of conceptEPSS 1%

    hutool · hutoolDec 13, 2022

  • A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attackers to cause a Denial

    HighCVSS 7.5No exploitEPSS 1%

    hutool · hutoolDec 13, 2022

  • CVE-2022-4565
    30Monitor

    Dromara HuTool cn.hutool.core.util.ZipUtil.java resource consumption

    HighCVSS 7.5No exploitEPSS 1%

    hutool · hutoolDec 16, 2022

  • hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse().

    HighCVSS 7.5No exploitEPSS 1%

    hutool · hutoolSep 8, 2023

  • hutool-json v5.8.10 was discovered to contain an out of memory error.

    HighCVSS 7.5No exploitEPSS 1%

    hutool · hutoolDec 13, 2022

  • hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function.

    HighCVSS 7.5No exploitEPSS 1%

    hutool · hutoolDec 27, 2023

  • The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.

    HighCVSS 7.5No exploitEPSS 1%

    hutool · hutoolDec 27, 2023

  • Hutool v5.8.17 and below was discovered to contain an information disclosure vulnerability via the File.createTempFile() function at /core/i

    HighCVSS 7.1No exploitEPSS 0%

    hutool · hutoolJun 13, 2023

  • An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary meth

    MediumCVSS 6.5No exploitEPSS 0%

    hutool · hutoolSep 25, 2025