JAckLosingHeart
30 exploits
Active since Apr 2018
Org.http4k Http4k-format-xml < 5.41.0.0 - Information Disclosure
Xstream < 1.4.17 - Insecure Deserialization
Org.springframework Spring-webflux < 6.1.14 - Path Traversal
Xstream < 1.4.14 - OS Command Injection
XStream <1.4.15 - SSRF
XStream <1.4.15 - File Deletion
Apache Commons Text < 1.10.0 - Code Injection
Apache Dubbo < 2.7.21 - Insecure Deserialization
Alibaba Fastjson < 1.2.83 - Insecure Deserialization
FasterXML Jackson-Databind <2.9.10.2 - RCE
Apache Log4j < 12.0.0.4.0 - Insecure Deserialization
Log4Shell HTTP Header Injection
Oracle MySQL Connector/J <8.0.26 - Privilege Escalation
Apache Shiro < 1.5.3 - Authentication Bypass
Apache Shiro < 1.6.0 - Authentication Bypass
Apache Shiro <1.7.1 - Auth Bypass
Apache Shiro < 1.10.0 - Authentication Bypass
PyTorch Model Server Registration and Deserialization RCE
Pivotal Spring Framework <5.3.16 - RCE
Pivotal Software Spring Data Commons < 1.12.10 - Code Injection
Spring Framework <5.2.9 - RCE
Vmware Spring Cloud Function < 3.1.6 - Remote Code Execution
Vmware Spring Framework < 5.2.20 - Code Injection
Spring Data MongoDB - Code Injection
Spring for Apache Kafka <3.0.9 & <2.9.10 - Deserialization