Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | com.alibaba:fastjson | unspecified ~ 1.2.83 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | [fastjson 1.2.80] CVE-2022-25845 aspectj fileread & groovy remote classload | https://github.com/hosch3n/FastjsonVulns | POC Details |
| 2 | None | https://github.com/nerowander/CVE-2022-25845-exploit | POC Details |
| 3 | a scenario based on CVE-2022-25845 yielding a TP for metadata based SCA but a FN if the callgraph is used | https://github.com/scabench/fastjson-tp1fn1 | POC Details |
| 4 | CVE-2022-25845(fastjson1.2.80) exploit in Spring Env! | https://github.com/luelueking/CVE-2022-25845-In-Spring | POC Details |
| 5 | exploit by python | https://github.com/ph0ebus/CVE-2022-25845-In-Spring | POC Details |
| 6 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E6%A1%86%E6%9E%B6%E6%BC%8F%E6%B4%9E/Fastjson%20%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2022-25845.md | POC Details |
| 7 | None | https://github.com/cuijiung/fastjson-CVE-2022-25845 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-25863 | 8.1 HIGH | Deserialization of Untrusted Data |
| CVE-2022-25851 | 7.5 HIGH | Denial of Service (DoS) |
| CVE-2022-24278 | 7.5 HIGH | Directory Traversal |
| CVE-2022-24429 | 7.5 HIGH | Arbitrary Code Injection |
| CVE-2022-24376 | 7.2 HIGH | Command Injection |
| CVE-2022-21211 | 5.9 MEDIUM | Denial of Service (DoS) |
| CVE-2022-31285 | Bento4 安全漏洞 | |
| CVE-2022-32563 | Couchbase Sync Gateway 信任管理问题漏洞 | |
| CVE-2022-27502 | RealVNC VNC Server 安全漏洞 | |
| CVE-2022-31788 | Idea LMS SQL注入漏洞 | |
| CVE-2021-44582 | Money Transfer Management System 安全漏洞 | |
| CVE-2021-44117 | FUEL CMS 跨站请求伪造漏洞 | |
| CVE-2022-32978 | libjpeg 安全漏洞 | |
| CVE-2022-29948 | Lepin EP-KP001 安全漏洞 | |
| CVE-2022-31402 | ITOP 跨站脚本漏洞 | |
| CVE-2018-17240 | Netwave IP camera 安全漏洞 | |
| CVE-2022-31282 | Bento4 安全漏洞 | |
| CVE-2021-41756 | dynamicMarkt SQL注入漏洞 | |
| CVE-2022-31287 | Bento4 安全漏洞 | |
| CVE-2022-32981 | Linux kernel 安全漏洞 |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet