Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Aaluoxiang

First CVE: Mar 4, 2025Active for: 1 yearTotal CVEs: 7

Aaluoxiang's vulnerability footprint concentrates in a narrowly scoped office-automation system where vulnerabilities skew strongly toward critical-severity outcomes. The recurring exposure pattern centers on input-handling and path-traversal flaws—SQL injection, path traversal, and downstream injection—that are characteristic of web-facing business applications where sanitization and access controls bear directly on confidentiality and integrity. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
7.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 79% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Aaluoxiang over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2025
16 months ago
Most Recent CVE
Sep 16, 2025
314 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-44033CRITICAL
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mapp
Aug 29, 20259.832NONO
CVE-2025-44034HIGH
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/Ad
Sep 16, 20258.026NONO
CVE-2025-1958CRITICAL
A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/add
Mar 4, 20259.825NONO
CVE-2025-6829HIGH
A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function outAddress of the compo
Jun 28, 20258.824NONO
CVE-2025-5544HIGH
A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this issue is the function image of
Jun 3, 20257.522NONO
CVE-2025-29592MEDIUM
oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
Sep 10, 20255.620NONO
CVE-2025-5545HIGH
A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file src/mai
Jun 4, 20257.520NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
57%
29%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (14.3%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Aaluoxiang.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Aaluoxiang — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Aaluoxiang's Products

View all 2 CNAs →

Top CWEs