JAckLosingHeart
31 exploits
Active since Apr 2018
http4k-format-xml 5.0.0.0-5.41.0.0 - XML External Entity Injection
XStream <1.4.15 - File Deletion
XStream < 1.4.14 - Remote Code Execution via Blocklist Bypass
XStream <1.4.15 - Server-Side Request Forgery via XML Unmarshalling
XStream < 1.4.17 - Remote Code Execution via Untrusted Data Deserialization
Apache Commons Text 1.5-1.9 - Remote Code Execution via String Interpolation
Apache Dubbo 2.7.0-2.7.21, 3.0.0-3.0.13, 3.1.0-3.1.5 - Remote Code Execution via Generic Invoke Deserialization
fastjson < 1.2.83 - Deserialization of Untrusted Data via autoType Bypass
FasterXML Jackson-Databind <2.9.10.2 - RCE
Apache Log4j 1.2 - Remote Code Execution via JMSAppender JNDI Requests
Log4Shell HTTP Header Injection
Oracle MySQL Connector/J <8.0.26 - Privilege Escalation
Apache Shiro < 1.5.3 - Authentication Bypass via Spring Dynamic Controllers
Apache Shiro < 1.6.0 - Authentication Bypass via Specially Crafted HTTP Request
Apache Shiro < 1.7.1 - Authentication Bypass via Crafted HTTP Request
Apache Shiro < 1.10.0 - Authentication Bypass via RequestDispatcher
PyTorch Model Server Registration and Deserialization RCE
Pivotal Spring Framework <5.3.16 - RCE
Spring Data Commons < 1.13.11 - Unauthenticated Remote Code Execution via Property Binder
Spring Framework 4.3.0-4.3.28, 5.0.0-5.0.18, 5.1.0-5.1.17, 5.2.0-5.2.8 - Reflection File Download
Spring Cloud Function < 3.1.6 - Remote Code Execution via SpEL Routing Expression
Spring Framework - Remote Code Execution via Data Binding
Spring Data MongoDB - Code Injection
Spring for Apache Kafka <3.0.9 & <2.9.10 - Deserialization
Spring AMQP <2.4.16 & <3.0.9 - Deserialization