java-aodeng records
2 published records for vendor java-aodeng.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-45611No exploit | Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET requesjava-aodeng · hope-boot · CWE-284 | Critical9.8 | — | 0.5% | May 5, 2025 |
8Monitor | CVE-2025-6551No exploit | java-aodeng Hope-Boot WebController.java login cross site scriptingjava-aodeng · hope-boot · CWE-79 | Low2.0 | — | 0.5% | Jun 23, 2025 |
- CVE-2025-4561139Monitor
Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET reques
CriticalCVSS 9.8No exploitEPSS 1%java-aodeng · hope-bootMay 5, 2025
- CVE-2025-65518Monitor
java-aodeng Hope-Boot WebController.java login cross site scripting
LowCVSS 2.0No exploitEPSS 0%java-aodeng · hope-bootJun 23, 2025