CVE-2025-12305Medium· 6.3▾ SunlitA vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJobController.java of the component Job Handler. The manipulation results in deserializat…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJobController.java of the component Job Handler. The manipulation results in deserialization. The attack can be executed remotely. The exploit has been made public and could be used.
shiyi-blog <= 1.2.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10768Medium· 6.3A flaw has been found in h2oai h2o-3 up to 3.46.08
CVE-2026-90527Medium· 4.3A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1
CVE-2026-90564Low· 3.5A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1
CVE-2026-90567Low· 3.5A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1
CVE-2025-14606Medium· 5.0A security vulnerability has been detected in tiny-rdm Tiny RDM up to 1.2.5
CVE-2025-15117Low· 3.1A weakness has been identified in Dromara Sa-Token up to 1.44.0