Vulnerabilities

Summary — last 7 days

New vulnerabilities2,761▲ 86 vs. last week
Critical / high1,460▲ 350 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)91▼ 420 vs. last week
–

12 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.5)0.50%—DocsysAI8/26/20269/9/2026
In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:
DeferredHigh (7.5)0.48%—DocsysAI8/26/20269/9/2026
DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.
DeferredCritical (9.8)0.52%—DocsysAI8/26/20269/1/2026
In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:
DeferredCritical (9.8)0.86%—Rainygao DocsysAI8/17/20268/31/2026
File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code
AnalyzedLow (2.1)0.43%—Docsys Project Docsys1/9/20266/17/2026
A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSystem/mapping/UserMapper.xml. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The…
AnalyzedLow (2.1)0.45%—Docsys Project Docsys1/9/20266/17/2026
A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/DocSystem/mapping/ReposAuthMapper.xml. Executing a manipulation of the argument searchWord can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and…
AnalyzedLow (2.1)0.43%—Docsys Project Docsys1/9/20266/17/2026
A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file src/com/DocSystem/mapping/GroupMemberMapper.xml. Performing a manipulation of the argument searchWord results in sql injection. It is possible to initiate the attack remotely. The exploit is now…
AnalyzedLow (2.1)0.80%—Docsys Project Docsys10/12/20256/17/2026
A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of the argument path can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be…
AnalyzedLow (2.1)0.72%—Docsys Project Docsys10/12/20256/17/2026
A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulation of the argument path results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be…
AnalyzedLow (2.1)0.41%—Docsys Project Docsys10/12/20259/30/2026
A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early…
ModifiedHigh (7.5)0.80%—Docsys Project Docsys12/15/20226/17/2026
A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unknown functionality of the component com.DocSystem.controller.UserController#getUserImg. The manipulation leads to path traversal: '../filedir'. The attack can be launched remotely. The exploit has been…
ModifiedHigh (7.2)0.76%—Docsys Project Docsys12/11/20226/17/2026
A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the component ZIP File Decompression Handler. The manipulation leads to path traversal: '../filedir'. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be…