ZeroHour

Vulnerabilities

29 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-60645
+1 in the same advisory: …60646
A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.

A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.

NVD description · AI analysis pending
6.5
group max
<1% PoC ×2
  • xuxueli xxl-api
CVE-2025-9264
A vulnerability was found in Xuxueli xxl-job up to 3.1.1.

A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

NVD description · AI analysis pending
2.1<1% PoC ×2
  • xuxueli xxl-job
CVE-2025-9263
A vulnerability has been found in Xuxueli xxl-job up to 3.1.1.

A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of resource identifiers. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.1<1% PoC ×2
  • xuxueli xxl-job
CVE-2025-7789
+2 in the same advisory: …7788 …7787
A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic.

A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insufficient computational effort. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
2.9
group max
<1% PoC
  • xuxueli xxl-job
CVE-2025-6700
+1 in the same advisory: …6701
A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0.

A vulnerability classified as problematic was found in Xuxueli xxl-sso 1.1.0. This vulnerability affects unknown code of the file /xxl-sso-server/login. The manipulation of the argument errorMsg leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1
group max
<1% PoC
  • xuxueli xxl-sso
CVE-2024-42681
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.

Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.

NVD description · AI analysis pending
8.8<1% PoC
  • xuxueli xxl-job
CVE-2024-3366
A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1.

A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259480.

NVD description · AI analysis pending
9.8<1% PoC
  • xuxueli xxl-job
CVE-2024-24113
xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.

xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.

NVD description · AI analysis pending
8.8<1% PoC
  • xuxueli xxl-job
CVE-2023-48089
+2 in the same advisory: …48088 …48087
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.

xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.

NVD description · AI analysis pending
8.8
group max
1% PoC
  • xuxueli xxl-job
CVE-2020-24922
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code an

Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.

NVD description · AI analysis pending
8.8<1% PoC
  • xuxueli xxl-job
CVE-2023-33779
A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request t

A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/.

NVD description · AI analysis pending
8.8<1% PoC
  • xuxueli xxl-job
CVE-2023-26120
This affects all versions of the package com.xuxueli:xxl-job.

This affects all versions of the package com.xuxueli:xxl-job. HTML uploaded payload executed successfully through /xxl-job-admin/user/add and /xxl-job-admin/user/update.

NVD description · AI analysis pending
6.1<1% PoC
  • xuxueli xxl-job
CVE-2023-27087
Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.

Permissions vulnerabiltiy found in Xuxueli xxl-job v2.2.0, v 2.3.0 and v.2.3.1 allows attacker to obtain sensitive information via the pageList parameter.

NVD description · AI analysis pending
7.5<1% PoC
  • xuxueli xxl-job
CVE-2023-0674
A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1.

A vulnerability, which was classified as problematic, has been found in XXL-JOB 2.3.1. Affected by this issue is some unknown functionality of the file /user/updatePwd of the component New Password Handler. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-220196.

NVD description · AI analysis pending
6.5<1% PoC
  • xuxueli xxl-job
CVE-2022-43183
XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.

XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.

NVD description · AI analysis pending
8.82% PoC
  • xuxueli xxl-job
CVE-2022-40929
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks.

XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).

NVD description · AI analysis pending
9.81% PoC
  • xuxueli xxl-job
CVE-2022-36157
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.

XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.

NVD description · AI analysis pending
8.81%
  • xuxueli xxl-job
CVE-2022-29770
XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.

XXL-Job v2.3.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /xxl-job-admin/jobinfo.

NVD description · AI analysis pending
5.4<1% PoC
  • xuxueli xxl-job
CVE-2022-29002
A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.

A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.

NVD description · AI analysis pending
8.8<1% PoC
  • xuxueli xxl-job
CVE-2020-29204
XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.

XXL-JOB 2.2.0 allows Stored XSS (in Add User) to bypass the 20-character limit via xxl-job-admin/src/main/java/com/xxl/job/admin/controller/UserController.java.

NVD description · AI analysis pending
6.1<1% PoC
  • xuxueli xxl-job
CVE-2020-23811
+1 in the same advisory: …23814
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.

xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.

NVD description · AI analysis pending
7.5
group max
1%
  • xuxueli xxl-job
CVE-2018-20094
An issue was discovered in XXL-CONF 1.6.0.

An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via ../ in the keys parameter that can download any configuration file, related to ConfController.java and PropUtil.java.

NVD description · AI analysis pending
7.52% PoC
  • xuxueli xxl-conf