Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Jfinal
CRITICAL 9.8
CVE-2021-31635
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
Mitigation only
Fix from $2,300
2023-06-26
Jfinal
CRITICAL 9.8
CVE-2021-31649
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
Fix: after 4.9.08
Fix from $2,300
2021-06-24
Jfinal
MEDIUM 6.1
CVE-2021-33348
An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtere…
Fix: after 4.9.10
Fix from $1,600
2021-06-24
Jfinal
HIGH 7.5
CVE-2019-17352
In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type o…
Fix: 4.4+
Fix from $1,950
2019-10-08