cuijiung
10 exploits
Active since Jun 2020
Apache Dubbo 2.7.0-2.7.21, 3.0.0-3.0.13, 3.1.0-3.1.5 - Remote Code Execution via Generic Invoke Deserialization
fastjson < 1.2.83 - Deserialization of Untrusted Data via autoType Bypass
CVSS 8.1
XStream < 1.4.17 - Remote Code Execution via Untrusted Data Deserialization
CVSS 7.5
Apache Log4j 1.2 - Remote Code Execution via JMSAppender JNDI Requests
CVSS 7.5
Log4Shell HTTP Header Injection
CVSS 10.0
Netapp Cloud Backup < 21.1.2 - Insecure Deserialization
CVSS 8.1
Apache Shiro < 1.5.3 - Authentication Bypass via Spring Dynamic Controllers
CVSS 9.8
XStream <1.4.15 - Server-Side Request Forgery via XML Unmarshalling
CVSS 6.3
XStream < 1.4.14 - Remote Code Execution via Blocklist Bypass
CVSS 8.0
XStream <1.4.15 - File Deletion
CVSS 6.8