Dromara kayıtları
dromara üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %42,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-284 Improper Access Control1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-798 Use of Hard-coded Credentials1
- CWE-863 Incorrect Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-44794İstismar yok | An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.dromara · sa-token · CWE-284 | Kritik9,8 | — | %1,0 | 25 Eki 2023 |
39İzleyin | CVE-2023-31581İstismar yok | Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.dromara · sureness · CWE-798 | Kritik9,8 | — | %0,8 | 25 Eki 2023 |
37İzleyin | CVE-2025-66916İstismar yok | The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpredromara · ruoyi-vue-plus · CWE-94 | Kritik9,4 | — | %0,7 | 8 Oca 2026 |
35İzleyin | CVE-2023-43961İstismar yok | An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authdromara · sa-token · CWE-863 | Yüksek8,8 | — | %0,8 | 25 Eki 2023 |
30İzleyin | CVE-2023-3276İstismar yok | Dromara HuTool XML Parsing Module XmlUtil.java readBySax xml external entity referencedromara · hutool · CWE-611 | Yüksek7,5 | — | %0,7 | 15 Haz 2023 |
22İzleyin | CVE-2025-6925İstismar yok | Dromara RuoYi-Vue-Plus Mail MailController.java path traversaldromara · ruoyi-vue-plus · CWE-22 | Orta5,5 | — | %1,0 | 30 Haz 2025 |
17İzleyin | CVE-2024-3928İstismar yok | Dromara open-capacity-platform auth-server heapdump information disclosuredromara · open-capacity-platform · CWE-200 | Orta4,3 | — | %0,5 | 17 Nis 2024 |
- CVE-2023-4479439İzleyin
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
KritikCVSS 9,8İstismar yokEPSS %1dromara · sa-token25 Eki 2023
- CVE-2023-3158139İzleyin
Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.
KritikCVSS 9,8İstismar yokEPSS %1dromara · sureness25 Eki 2023
- CVE-2025-6691637İzleyin
The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpre
KritikCVSS 9,4İstismar yokEPSS %1dromara · ruoyi-vue-plus8 Oca 2026
- CVE-2023-4396135İzleyin
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an auth
YüksekCVSS 8,8İstismar yokEPSS %1dromara · sa-token25 Eki 2023
- CVE-2023-327630İzleyin
Dromara HuTool XML Parsing Module XmlUtil.java readBySax xml external entity reference
YüksekCVSS 7,5İstismar yokEPSS %1dromara · hutool15 Haz 2023
- CVE-2025-692522İzleyin
Dromara RuoYi-Vue-Plus Mail MailController.java path traversal
OrtaCVSS 5,5İstismar yokEPSS %1dromara · ruoyi-vue-plus30 Haz 2025
- CVE-2024-392817İzleyin
Dromara open-capacity-platform auth-server heapdump information disclosure
OrtaCVSS 4,3İstismar yokEPSS %1dromara · open-capacity-platform17 Nis 2024