Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-1546 A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshER… Jsherp after 3.6 Fix from $2,3002026-01-28 CRITICAL 9.8 CVE-2025-51744 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks. Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-51745 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks. Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-51746 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks. Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-51743 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization att… Jsherp after 2.3.1 Fix from $2,3002025-11-25 CRITICAL 9.8 CVE-2025-51742 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter direc… Jsherp after 2.3.1 Fix from $2,3002025-11-25 HIGH 7.5 CVE-2025-60800 Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via … Jsherp 2025-08-07+ Fix from $1,9502025-10-28 HIGH 8.2 CVE-2025-60801 jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function. Jsherp 2025-08-14+ Fix from $1,9502025-10-24 MEDIUM 5.3 CVE-2025-55371 Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the informatio… Jsherp No fix yet Fix from $1,6002025-08-21 HIGH 8.8 CVE-2025-55368 Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supp… Jsherp No fix yet Fix from $1,9502025-08-21 HIGH 8.8 CVE-2025-55370 Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the correspo… Jsherp No fix yet Fix from $1,9502025-08-21 MEDIUM 5.3 CVE-2025-55366 Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords… Jsherp No fix yet Fix from $1,6002025-08-21 MEDIUM 5.3 CVE-2025-55367 Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the … Jsherp No fix yet Fix from $1,6002025-08-21 MEDIUM 5.4 CVE-2025-8840 A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoi… Jsherp No fix yet Fix from $1,6002025-08-11 HIGH 8.8 CVE-2025-8839 A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endp… Jsherp No fix yet Fix from $1,9502025-08-11 MEDIUM 6.5 CVE-2025-7948 A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshE… Jsherp after 3.5 Fix from $1,6002025-07-22 HIGH 8.1 CVE-2025-7947 A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component … Jsherp after 3.5 Fix from $1,9502025-07-22 HIGH 7.2 CVE-2025-7566 A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file… Jsherp after 3.5 Fix from $1,9502025-07-14 CRITICAL 9.8 CVE-2024-24003 jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount… Jsherp No fix yet Fix from $2,3002024-02-08 CRITICAL 9.8 CVE-2024-24001 jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDeta… Jsherp No fix yet Fix from $2,3002024-02-07 CRITICAL 9.8 CVE-2024-24002 jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() func… Jsherp No fix yet Fix from $2,3002024-02-07 CRITICAL 9.8 CVE-2024-24004 jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() func… Jsherp No fix yet Fix from $2,3002024-02-07