Search Results (9 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-19827 1 Alldata 1 Alldata 2026-08-14 5.3 Medium
A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This manipulation of the argument executorAddress causes path traversal. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project closed the issue report as "not planned" without any further explanation.
CVE-2026-19826 1 Alldata 1 Alldata 2026-08-14 7.3 High
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.
CVE-2024-29433 1 Alldata 1 Alldata 2025-05-07 9.8 Critical
A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.
CVE-2024-29435 1 Alldata 1 Alldata 2025-05-07 4.1 Medium
An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.
CVE-2024-29434 1 Alldata 1 Alldata 2025-04-30 8.3 High
An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.
CVE-2024-29432 1 Alldata 1 Alldata 2025-04-30 9.8 Critical
Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.
CVE-2024-27602 1 Alldata 1 Alldata 2025-04-30 9.1 Critical
Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.
CVE-2024-27605 1 Alldata 1 Alldata 2025-03-28 7.5 High
Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system.
CVE-2024-27604 1 Alldata 1 Alldata 2025-03-27 9.8 Critical
Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.