andikahilmy
165 exploits
Active since Aug 2013
OWASP Enterprise Security API < 2.3.0.0 - Path Traversal via Validator.getValidDirectoryPath
CVSS 7.5
Apache Maven maven-shared-utils <3.3.3 - Command Injection
CVSS 9.8
json-smart-v1 1.3-1.3.2 and 2.4-2.4.3 - Denial of Service via JSONParserByteArray indexOf Function
CVSS 7.5
Apache Commons Compress 1.0-1.20 - Denial of Service via Malicious ZIP Archive
CVSS 7.5
Apache Commons Compress 1.6-1.19 - Denial of Service via Malicious 7Z Archive
CVSS 7.5
Apache Commons Compress 1.6-1.19 - Denial of Service via Crafted 7Z Archive
CVSS 7.5
XStream <1.4.19 - DoS
CVSS 7.5
cron-utils < 9.1.6 - Unauthenticated Remote Code Execution via Java EL Expression Injection
CVSS 10.0
Apache Commons Compress 1.1-1.19 - Denial of Service via Malicious TAR Archive
CVSS 7.5
jackson-databind < 2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1
jackson-databind 2.0.0-2.7.9.7 - Deserialization of Untrusted Data via com.ibatis.sqlmap Gadget
CVSS 9.8
jackson-databind 2.7.0-2.7.9.6 - Deserialization of Untrusted Data via HikariConfig Gadget
CVSS 9.8
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1
Vert.x-Web 4.0.0-milestone1-4.0.0-milestone4 - Cross-Site Request Forgery via Incorrect Token Verification
CVSS 8.8
jackson-databind 2.0.0-2.7.9.7 - Deserialization of Untrusted Data via anteros-core Gadget
CVSS 9.8
swagger-codegen < 2.4.19 - Local Privilege Escalation via Temporary Directory Race Condition
CVSS 5.3
jackson-databind < 2.13.0 - Denial of Service via Nested Object Depth
CVSS 7.5
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data via SharedPoolDataSource
CVSS 8.1
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data via SharedPoolDataSource
CVSS 8.1
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data via JNDIConnectionSource
CVSS 8.1
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1
jackson-dataformats-binary < 2.11.4 - Denial of Service via Unchecked Byte Buffer Allocation
CVSS 7.5
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data via SharedPoolDataSource
CVSS 8.1
Google OAuth Client Library for Java < 1.31.0 - Incorrect Authorization via Missing PKCE Implementation
CVSS 7.4