Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-8736

    Oinone Pamirs RestController LocalFileClient.java request.getParameter path traversal

    Last Modified: May 18, 2026
    Published: May 17, 2026

    CVE-2026-8735

    Oinone Pamirs appConfigQuery PamirsParserConfig.java JsonUtils.parseMap deserialization

    Last Modified: May 18, 2026
    Published: May 17, 2026

    CVE-2026-8734

    Oinone Pamirs queryListByWrapper RSQLToSQLNodeConnector.makeVariable sql injection

    Last Modified: May 18, 2026
    Published: May 17, 2026

    CVE-2026-39052

    Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled script expressions through the underlying script engine without sandboxing or allowlist restrictions.

    Last Modified: May 17, 2026
    Published: May 15, 2026

    CVE-2026-39053

    Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils.fromXML(...) or ViewXmlUtils.fromXML(...), unsafe XML processing can lead to file disclosure or SSRF.

    Last Modified: May 17, 2026
    Published: May 15, 2026
    Items Per Page
    Oinone Vulnerabilities & Security CVEs | CVE-DB