andikahilmy
165 exploits
Active since Aug 2013
Apache Directory LDAP API < 1.0.2 - Exposure of Sensitive Information via TLS Handshake Bypass
CVSS 9.8
FasterXML Jackson <2.9.7 - Code Injection
CVSS 9.8
FasterXML jackson-databind 2.0.0-2.6.7.2 - Remote Code Execution via BlazeDS Polymorphic Deserialization
CVSS 9.8
FasterXML jackson-databind 2.6.0-2.6.7.1 - XML External Entity Injection via Polymorphic Deserialization
CVSS 9.8
FasterXML jackson-databind <2.9.7 - SSRF
CVSS 10.0
Apache Qpid Proton-J 0.3-0.29.0 - Improper Certificate Validation in TLS Transport Wrapper
CVSS 7.4
FasterXML jackson-databind <2.9.8 - Code Injection
CVSS 9.8
FasterXML jackson-databind <2.9.8 - Deserialization
CVSS 9.8
RDF4J < 2.5.0 - Path Traversal via ZIP Archive Entry
CVSS 7.5
.weixin-java-tools <3.2.0 - Info Disclosure
CVSS 9.8
FasterXML jackson-databind <2.8.11, 2.9.x<2.9.3 - RCE
CVSS 8.1
jackson-databind < 2.7.9.3, 2.8.0-2.8.11.1, < 2.9.5 - Remote Code Execution via Deserialization Bypass
CVSS 9.8
Apache Qpid Broker-J 7.0.0-7.0.4 - Denial of Service via Oversized AMQP Message
CVSS 7.5
sparkjava/spark < 2.7.2 - Path Traversal via File URL
CVSS 5.3
Apache Sling Authentication Service 1.4.0 - Exposure of Sensitive Information via Login Form Redirect
CVSS 8.8
Redhat Fuse < 1.4.9 - Improper Input Validation
CVSS 7.5
Apache CXF Fediz <1.4.0-1.3.2 - CSRF
CVSS 8.8
Apache CXF Fediz <1.4.0-1.2.4 - CSRF
CVSS 8.8
Red Hat JBoss EAP 3.0.7-3.0.25.Final - Server-Side Cache Poisoning via JAX-RS Component
CVSS 7.5
Undertow <2.0.0.Alpha2,<1.4.17.Final,<1.3.31.Final - SSRF
CVSS 6.1
Logback < 1.2.0 - Deserialization of Untrusted Data in SocketServer and ServerSocketReceiver
CVSS 9.8
Undertow < 1.3.31 - HTTP Request Smuggling via Invalid Request Line Characters
CVSS 6.5
Jenkins Active Directory Plugin <= 2.2 - Improper Certificate Validation
CVSS 8.1
SnakeYAML < 1.26 - XML Entity Expansion via Alias Feature
CVSS 7.5
jackson-databind < 2.6.7.3, 2.9.0-2.9.3 - Unauthenticated Remote Code Execution via Malicious JSON Input
CVSS 9.8