Java Aodeng
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-45611 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2025 | Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request. | ||
| CVE-2022-44371 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2022 | hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE). | ||
| CVE-2025-6552 | Med | 0.28 | 4.3 | 0.00 | Jun 24, 2025 | A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the component Login. The manipulation of the argument redirect_url leads to open… | ||
| CVE-2025-6551 | Low | 0.23 | 3.5 | 0.00 | Jun 24, 2025 | A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. The manipulation of the argument errorMsg leads to cross site scripting. The attack… |
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.
- risk 0.64cvss 9.8epss 0.01
hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the component Login. The manipulation of the argument redirect_url leads to open…
- risk 0.23cvss 3.5epss 0.00
A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. The manipulation of the argument errorMsg leads to cross site scripting. The attack…