Anji-plus
Anji-plus Aj-report: vulnerabilidades y CVE
Anji-plus Aj-report tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-52786 | Crítica (9.8) | 0.80% | — | 22 ago 2025 | An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL. |
| CVE-2024-5356 | Media (5.3) | 1.0% | — | 26 may 2024 | A vulnerability, which was classified as critical, was found in anji-plus AJ-Report up to 1.4.1. Affected is an unknown function of the file /dataSet/testTransform;swagger-ui. The manipulation of the argument… |
| CVE-2024-5355 | Media (5.3) | 3.2% | — | 26 may 2024 | A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects the function IGroovyHandler. The manipulation leads to command injection. The attack may be… |
| CVE-2024-5354 | Media (5.3) | 0.63% | — | 26 may 2024 | A vulnerability classified as problematic was found in anji-plus AJ-Report up to 1.4.1. This vulnerability affects unknown code of the file /reportShare/detailByCode. The manipulation of the argument shareToken leads to… |
| CVE-2024-5353 | Media (5.3) | 0.80% | — | 26 may 2024 | A vulnerability classified as critical has been found in anji-plus AJ-Report up to 1.4.1. This affects the function decompress of the component ZIP File Handler. The manipulation leads to path traversal. It is possible… |
| CVE-2024-5352 | Media (5.3) | 0.77% | — | 26 may 2024 | A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been rated as critical. Affected by this issue is the function validationRules of the component… |
| CVE-2024-5351 | Media (5.3) | 0.77% | — | 26 may 2024 | A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been declared as critical. Affected by this vulnerability is the function getValueFromJs of the component Javascript Handler. The manipulation leads… |
| CVE-2024-5350 | Media (5.3) | 0.60% | — | 25 may 2024 | A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been classified as critical. Affected is the function pageList of the file /pageList. The manipulation of the argument p leads to sql injection. It is… |
| CVE-2022-46973 | Crítica (9.8) | 0.83% | — | 3 mar 2023 | Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability. |
| CVE-2022-42983 | Alta (8.8) | 1.4% | — | 17 oct 2022 | anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.