Powerjob is a job-scheduling and task-distribution platform whose vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling. The exposure centers on the product's core scheduling engine and recurs through access-control and authorization weakness classes—improper access control, incorrect authorization, and missing authorization—that are characteristic of systems managing execution permissions and workflow isolation. Defenders should treat this vendor's advisories as requiring urgent review; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Powerjob over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37754CRITICAL PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail. | Jul 28, 2023 | 9.8 | 44 | NO | NO |
CVE-2023-29923MEDIUM PowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface. | Apr 19, 2023 | 5.3 | 33 | NO | YES |
CVE-2025-14518CRITICAL A vulnerability was identified in PowerJob up to 5.1.2. This vulnerability affects the function checkConnectivity of the file src/main/java/tech/powerjob/common/utils/net/PingPongU | Dec 11, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-11580MEDIUM A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the file /user/list. This manipulation causes missing authorization. The attack can be ini | Oct 10, 2025 | 5.3 | 30 | NO | YES |
CVE-2023-29926CRITICAL PowerJob V4.3.2 has unauthorized interface that causes remote code execution. | Apr 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-29922MEDIUM PowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface. | Apr 19, 2023 | 5.3 | 30 | NO | YES |
CVE-2023-29924CRITICAL PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution. | Apr 21, 2023 | 9.8 | 29 | NO | NO |
CVE-2025-11581HIGH A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file /openApi/runJob of the component OpenAPIController. Such man | Oct 10, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-44546CRITICAL Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter. | Nov 11, 2024 | 9.8 | 25 | NO | NO |
CVE-2020-28865HIGH An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save. | Jun 16, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Powerjob.
Media articles that mention a CVE ID that affects a product developed by Powerjob — matched by CVE ID, not by vendor name.