Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
hutool hutool vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-24163
SQL Inection vulnerability in Dromara hutool prior to 5.8.21 allows malicious user to execute arbitrary code via the aviator template engine.
Hutool Hutool
7.1
CVSSv3
CVE-2023-33695
Hutool v5.8.17 and below exists to contain an information disclosure vulnerability via the File.createTempFile() function at /core/io/FileUtil.java.
Hutool Hutool
7.5
CVSSv3
CVE-2022-4565
A vulnerability classified as problematic was found in Dromara HuTool up to 5.8.10. This vulnerability affects unknown code of the file cn.hutool.core.util.ZipUtil.java. The manipulation leads to resource consumption. The attack can be initiated remotely. The exploit has been dis...
Hutool Hutool
7.5
CVSSv3
CVE-2018-17297
The unzip function in ZipUtil.java in Hutool prior to 4.1.12 allows remote malicious users to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.
Hutool Hutool
7.5
CVSSv3
CVE-2023-51075
hutool-core v5.8.23 exists to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows malicious users to cause a Denial of Service (DoS) via manipulation of the first two parameters.
Hutool Hutool 5.8.23
7.5
CVSSv3
CVE-2023-51080
The NumberUtil.toBigDecimal method in hutool-core v5.8.23 exists to contain a stack overflow.
Hutool Hutool 5.8.23
9.8
CVSSv3
CVE-2022-22885
Hutool v5.7.18's HttpRequest exists to ignore all TLS/SSL certificate validation.
Hutool Hutool 5.7.18
2 Github repositories
9.8
CVSSv3
CVE-2023-24162
Deserialization vulnerability in Dromara Hutool v5.8.11 allows malicious user to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.
Hutool Hutool 5.8.11
9.8
CVSSv3
CVE-2023-42276
hutool v5.8.21 exists to contain a buffer overflow via the component jsonArray.
Hutool Hutool 5.8.21
9.8
CVSSv3
CVE-2023-42277
hutool v5.8.21 exists to contain a buffer overflow via the component jsonObject.putByPath.
Hutool Hutool 5.8.21
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »