Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Zhaizejiang

#23913of 57,416
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2026-90726
4.3
2026-09-12
Xuxueli · Xxl-Job · CVE-2026-90487
**Name of the Vulnerable Software and Affected Versions** Xuxueli xxl-job versions prior to 3.4.3 **Description** Improper privilege management exists in the `JobGroupController.java` file. This issue allows a remote attacker to manipulate functionality within the `xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java` component to bypass intended access controls. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-90727
6.5
2026-09-12
Xuxueli · Xxl-Job · CVE-2026-90488
**Name of the Vulnerable Software and Affected Versions** Xuxueli xxl-job versions prior to 3.4.3 **Description** A code injection flaw exists that allows for remote exploitation. The issue resides in the `GroovyClassLoader.parseClass()` function within the `xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java` file. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the `GroovyClassLoader.parseClass()` function to minimize the risk of exploitation.