Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-70986 Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data. Ruoyi No fix yet Fix from $1,9502026-01-23 CRITICAL 9.1 CVE-2025-70985 Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope. Ruoyi No fix yet Fix from $2,3002026-01-23 CRITICAL 10.0 CVE-2024-57521 SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.ja… Ruoyi after 4.7.9 Fix from $2,3002025-12-23 HIGH 8.8 CVE-2025-14856 A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/get… Ruoyi after 4.8.1 Fix from $1,9502025-12-18 HIGH 7.5 CVE-2025-46175 Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserContr… Ruoyi Mitigation only Fix from $1,9502025-11-26 HIGH 8.8 CVE-2025-56396 An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the act… Ruoyi No fix yet Fix from $1,9502025-11-26 HIGH 7.5 CVE-2025-46174 Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserControll… Ruoyi Mitigation only Fix from $1,9502025-11-26 HIGH 8.8 CVE-2025-10989 A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/sel… Ruoyi after 4.8.1 Fix from $1,9502025-09-26 CRITICAL 9.8 CVE-2025-10473 A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/ruoyi/common/utils/s… Ruoyi after 4.8.1 Fix from $2,3002025-09-15 MEDIUM 5.4 CVE-2025-10384 A flaw has been found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the file /system/role/authUse… Ruoyi after 4.8.1 Fix from $1,6002025-09-13 MEDIUM 5.4 CVE-2025-8847 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /system/notice/edit. Th… Ruoyi after 4.8.1 Fix from $1,6002025-08-11 MEDIUM 5.4 CVE-2025-7906 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi… Ruoyi after 4.8.1 Fix from $1,6002025-07-20 MEDIUM 5.4 CVE-2025-7903 A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of… Ruoyi after 4.8.1 Fix from $1,6002025-07-20 MEDIUM 6.1 CVE-2025-7901 A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the fil… Ruoyi after 4.8.1 Fix from $1,6002025-07-20 MEDIUM 5.4 CVE-2025-7902 A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function addSave of the file com/ruoyi/w… Ruoyi after 4.8.1 Fix from $1,6002025-07-20 CRITICAL 9.8 CVE-2025-28410 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the req… Ruoyi No fix yet Fix from $2,3002025-04-07 CRITICAL 9.8 CVE-2025-28411 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave Ruoyi No fix yet Fix from $2,3002025-04-07 CRITICAL 9.8 CVE-2025-28412 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController Ruoyi No fix yet Fix from $2,3002025-04-07 CRITICAL 9.8 CVE-2025-28413 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component Ruoyi No fix yet Fix from $2,3002025-04-07 HIGH 8.8 CVE-2025-28409 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly valida… Ruoyi No fix yet Fix from $1,9502025-04-07 CRITICAL 9.8 CVE-2025-28402 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter Ruoyi No fix yet Fix from $2,3002025-04-07 CRITICAL 9.8 CVE-2025-28405 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method Ruoyi No fix yet Fix from $2,3002025-04-07 CRITICAL 9.8 CVE-2025-28406 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter Ruoyi No fix yet Fix from $2,3002025-04-07 CRITICAL 9.8 CVE-2025-28408 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does… Ruoyi No fix yet Fix from $2,3002025-04-07 HIGH 8.8 CVE-2025-28407 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly valida… Ruoyi No fix yet Fix from $1,9502025-04-07 HIGH 7.2 CVE-2025-28403 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting u… Ruoyi No fix yet Fix from $1,9502025-04-07 MEDIUM 6.7 CVE-2025-28400 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method Ruoyi No fix yet Fix from $1,6002025-04-07 MEDIUM 6.7 CVE-2025-28401 An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter Ruoyi No fix yet Fix from $1,6002025-04-07 HIGH 7.2 CVE-2024-57436 RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attack… Ruoyi No fix yet Fix from $1,9502025-01-29 MEDIUM 6.5 CVE-2024-57437 RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list. Ruoyi No fix yet Fix from $1,6002025-01-29