Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2024-57438
Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.
Ruoyi
No fix yet
HIGH 7.2
CVE-2025-0734
A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function getBeanName of the …
Ruoyi
after 4.8.0
MEDIUM 6.3
CVE-2024-54762
Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter S…
Ruoyi
after 4.7.9
CRITICAL 9.8
CVE-2024-46076
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of maliciou…
Ruoyi
after 4.7.9
MEDIUM 6.1
CVE-2024-9048
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUser…
Ruoyi
after 4.7.9
MEDIUM 6.1
CVE-2024-42900
Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /…
Ruoyi
after 4.7.9
CRITICAL 9.8
CVE-2024-42913
RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
Ruoyi
Mitigation only
MEDIUM 6.1
CVE-2024-41599
Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method
Ruoyi
after 4.7.9
MEDIUM 6.1
CVE-2024-6511
A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function isJsonRequest of t…
Ruoyi
after 4.7.9
HIGH 7.5
CVE-2024-29400
An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.
Ruoyi
No fix yet
MEDIUM 6.1
CVE-2023-7133
A vulnerability was found in y_project RuoYi 4.7.8. It has been declared as problematic. This vulnerability affects unknown code of the file /login o…
Ruoyi
No fix yet
CRITICAL 9.8
CVE-2023-49371
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
Ruoyi
after 4.6.0
CRITICAL 9.8
CVE-2021-28411
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote a…
Ruoyi
No fix yet
MEDIUM 6.1
CVE-2023-3815
A vulnerability, which was classified as problematic, has been found in y_project RuoYi up to 4.7.7. Affected by this issue is the function uploadFil…
Ruoyi
after 4.7.7
HIGH 7.5
CVE-2023-3163
A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the function filterKeyword. The manipula…
Ruoyi
after 4.7.7
HIGH 7.5
CVE-2023-27025
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files i…
Ruoyi
after 4.7.6
CRITICAL 9.8
CVE-2022-48114
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
Ruoyi
after 4.7.5
CRITICAL 9.8
CVE-2021-38241
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
Ruoyi
4.6.1+
CRITICAL 9.8
CVE-2022-4566
A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file co…
Ruoyi
No fix yet
MEDIUM 6.1
CVE-2022-4348
A vulnerability was found in y_project RuoYi-Cloud. It has been rated as problematic. Affected by this issue is some unknown functionality of the com…
Ruoyi Cloud
No fix yet
MEDIUM 5.4
CVE-2022-32065
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a…
Ruoyi
after 4.7.3
HIGH 7.8
CVE-2022-23868
RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.
Ruoyi
No fix yet
MEDIUM 6.5
CVE-2022-23869
In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be res…
Ruoyi
No fix yet