andikahilmy
165 exploits
Active since Aug 2013
Apache Sling Xss Protection API < 1.0.18 - XSS
CVSS 6.1
Swagger-Parser <=1.0.30 & Swagger Codegen <=2.2.2 - RCE
CVSS 8.8
Redhat Resteasy < 3.1.1 - Improper Input Validation
CVSS 8.1
Redhat Jboss Wildfly Application Server < 10.1.0 - Denial of Service
CVSS 7.5
Spark 2.5 - Path Traversal
CVSS 7.5
Apache Brooklyn <0.10.0 - Code Injection
CVSS 8.8
Apache Qpid Broker for Java <6.0.6, <6.1.1 - Info Disclosure
CVSS 7.5
Fasterxml Jackson-dataformat-xml < 2.7.8 - SSRF
CVSS 8.6
Apache Tika < 1.13 - Insecure Deserialization
CVSS 9.8
Apache Shiro < 1.3.2 - Improper Access Control
CVSS 7.5
Apache Jackrabbit < 2.4.6 - CSRF
CVSS 8.8
Apache Amqp 0-x Jms Client < 6.0.3 - Improper Input Validation
CVSS 7.5
Apache Cxf Fediz < 1.2.3 - Improper Access Control
CVSS 9.8
Apache Tomcat < 1.3.1 - Improper Input Validation
CVSS 7.5
Apache Commons FileUpload <1.3.3 - RCE
CVSS 9.8
Jsoup < 1.8.3 - XSS
CVSS 6.1
PicketLink <2.7.0 - Info Disclosure
jackson-databind <2.8.10, 2.9.1 - Code Injection
CVSS 9.8
Async Http Client <2.0.35 - SSRF
CVSS 7.5
libpam4j <1.9 - Auth Bypass
CVSS 6.5
Undertow <1.4.17, <1.3.31, <2.0.0 - HTTP Request Smuggling
CVSS 2.6
Plexus-utils <3.0.16 - Command Injection
CVSS 9.8
nv-websocket-client - Man-in-the-Middle
CVSS 5.9
Swagger-Parser <=1.0.30 - RCE
CVSS 8.8
Apache MyFaces Core <2.0.12, <2.1.6 - Path Traversal