andikahilmy
165 exploits
Active since Aug 2013
jackson-databind 2.0.0-2.7.9.7 - Deserialization of Untrusted Data via anteros-core Gadget
CVSS 9.8
Netapp Cloud Backup < 21.1.2 - Insecure Deserialization
CVSS 8.1
Oracle JD Edwards Enterpriseone Tools - Insecure Deserialization
CVSS 8.1
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data via SharedPoolDataSource
CVSS 8.1
Netapp Service Level Manager < 21.1.2 - Insecure Deserialization
CVSS 8.1
jackson-databind < 2.13.0 - Denial of Service via Nested Object Depth
CVSS 7.5
Google OAuth Client Library for Java < 1.31.0 - Incorrect Authorization via Missing PKCE Implementation
CVSS 7.4
jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1
FasterXML jackson-databind 2.0.0-2.9.10.7 - Deserialization of Untrusted Data
CVSS 8.1
jackson-databind 2.6.0-2.6.7.3 - XML External Entity Injection
CVSS 7.5
Resteasy 3.0.0-3.11.9 and 4.0.0-4.5.9 - HTTP Response Header Injection via Improper Input Validation
CVSS 7.5
XStream < 1.4.14 - Remote Code Execution via Blocklist Bypass
CVSS 8.0
Apache Velocity Tools < 3.1 - Cross-Site Scripting via URL vm File Parameter
CVSS 6.1
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via Oracle AQjms Gadgets
CVSS 8.1
jackson-databind 2.9.0-2.9.10.3 - Deserialization of Untrusted Data via spring-aop MethodLocatingFactoryBean
CVSS 8.1
FasterXML Jackson-Databind <2.9.10.4 - Code Injection
CVSS 8.8
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via apache/drill JNDIConnectionPool
CVSS 8.1
jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via org.jsecurity.realm.jndi.JndiRealmFactory
CVSS 8.1
JUnit4 4.7-4.13 - Local Information Disclosure via TemporaryFolder Rule
CVSS 4.4
FasterXML jackson-databind <2.9.10.6 - RCE
CVSS 8.1
jackson-databind 2.0.0-2.9.10.5 - Deserialization of Untrusted Data via JndiConfiguration
CVSS 8.1
jackson-databind 2.9.0-2.9.10.3 - Deserialization of Untrusted Data via commons-jelly Gadget
CVSS 8.1
FasterXML jackson-databind 2.9.0-2.9.10.4 - Deserialization of Untrusted Data via xalan2 JNDIConnectionPool
CVSS 8.1
XStream <1.4.15 - Server-Side Request Forgery via XML Unmarshalling
CVSS 6.3
FasterXML Jackson-Databind <2.9.10.4 - Code Injection
CVSS 8.8