dawetmaster
165 exploits
Active since Aug 2013
Apache Santuario XML Security for Java <1.4.8/1.5.5 XML Signature Spoofing
Redhat Jboss Enterprise Brms Platform - Improper Input Validation
Apache Santuario XML Security for Java <1.5.6 - DoS
OWASP Enterprise Security API for Java 2.x < 2.1.0 - Authenticated-Encryption Bypass via Null MAC
OWASP Enterprise Security API 2.0-2.1.0 - Authenticated Encryption Bypass via Ciphertext Tampering
JBPM KIE Workbench 6.0.x - Authenticated Cross-Site Scripting via Task Name HTML Input
CVSS 5.4
Apache Commons FileUpload <1.3.1 - DoS
Netty < 3.9.2 - Denial of Service via SSLv2Hello Message
Keycloak < 1.0.3 - Denial of Service via Large QR Code Size Parameter
CVSS 7.5
WildFly Directory Traversal
Netty Cookie HttpOnly Flag Bypass via Improper Input Validation
CVSS 7.5
OrientDB Server Community Edition <2.0.15 & <2.1.x - CSRF
CVSS 8.8
OrientDB Server Community Edition <2.0.15 and 2.1.x <2.1.1 - Information Disclosure
CVSS 5.9
Apache Tika Server < 1.10 - Exposure of Sensitive Information via HTTP fileUrl Header
CVSS 5.3
Apache CXF <2.7.18, <3.0.7, <3.1.3 - Auth Bypass
PicketLink <2.7.0 - Info Disclosure
jsoup < 1.8.3 - Cross-Site Scripting
CVSS 6.1
Apache Commons FileUpload <1.3.3 - RCE
CVSS 9.8
Apache Tomcat 7.x < 7.0.70, 8.x < 8.0.36, 8.5.x < 8.5.3, 9.x < 9.0.0.M7 - Denial of Service via Long Boundary String
CVSS 7.5
Apache CXF Fediz 1.2.0-1.2.2 and 1.3.0 - Improper Access Control via SAML AudienceRestriction Bypass
CVSS 9.8
Apache Qpid AMQP JMS Client < 6.0.4 & JMS (AMQP 1.0) < 0.10.0 - RCE via JMS ObjectMessage Deserialization
CVSS 7.5
Apache Jackrabbit < 2.4.6 - CSRF
CVSS 8.8
Apache Shiro < 1.3.2 - Filter Bypass via Non-Root Servlet Context Path
CVSS 7.5
Apache Tika < 1.14 - Remote Code Execution via MATLAB File Deserialization
CVSS 9.8
Apache MyFaces Core <2.0.12, <2.1.6 - Path Traversal