Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2026-3026 A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRem… Jeewms after 3.7 Fix from $1,9502026-02-23 MEDIUM 6.1 CVE-2026-3027 A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp… Jeewms after 3.7 Fix from $1,6002026-02-23 CRITICAL 9.8 CVE-2024-53499 Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API. Jeewms Mitigation only Fix from $2,3002025-08-22 CRITICAL 9.8 CVE-2025-50901 JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file… Jeewms Mitigation only Fix from $2,3002025-08-20 MEDIUM 5.5 CVE-2025-29213 A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Z… Jeewms No fix yet Fix from $1,6002025-04-15 HIGH 7.5 CVE-2024-57757 JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava. Jeewms 2025.01.01+ Fix from $1,9502025-01-15 MEDIUM 6.5 CVE-2024-57760 JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java. Jeewms 2025.01.01+ Fix from $1,6002025-01-15 HIGH 7.5 CVE-2024-27765 Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateControlle… Jeewms after 3.7 Fix from $1,9502024-03-05 CRITICAL 9.8 CVE-2024-27764 An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component. Jeewms after 3.7 Fix from $2,3002024-03-05