Vulnerabilities
12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-14518 | A vulnerability was identified in PowerJob up to 5.1.2. A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongUtils.java of the component Network Request Handler. The manipulation of the argument targetIp/targetPort leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. NVD description · AI analysis pending | 2.1 | <1% | PoC ×2 |
| — | |
| CVE-2025-11580 +1 in the same advisory: …11581 | A weakness has been identified in PowerJob up to 5.1.2. A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. NVD description · AI analysis pending | 5.5 | 1% |
| — | ||
| CVE-2024-44546 | Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter. Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-36106 | An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying v An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-37754 | PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail. PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail. NVD description · AI analysis pending | 9.8 | 30% | PoC ×2 |
| — | |
| CVE-2023-29924 | PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution. PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2023-29926 | PowerJob V4.3.2 has unauthorized interface that causes remote code execution. PowerJob V4.3.2 has unauthorized interface that causes remote code execution. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2023-29923 | PowerJob V4.3.1 is vulnerable to Insecure Permissions. PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface. NVD description · AI analysis pending | 5.3 | 10% | PoC |
| — | |
| CVE-2020-28865 | An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save. An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save. NVD description · AI analysis pending | 7.5 | <1% |
| — |