dawetmaster
165 exploits
Active since Aug 2013
Apache Qpid Broker for Java <6.0.6, <6.1.1 - Info Disclosure
CVSS 7.5
Apache Brooklyn <0.10.0 - Code Injection
CVSS 8.8
Spark < 2.5 - Path Traversal via URI
CVSS 7.5
Red Hat JBoss WildFly Application Server < 10.1.0 - Denial of Service via HTTP Header Cache Exhaustion
CVSS 7.5
JBoss RESTEasy < 3.1.2 - Remote Code Execution via YamlProvider Unmarshalling
CVSS 8.1
Swagger-Parser <=1.0.30 & Swagger Codegen <=2.2.2 - RCE
CVSS 8.8
Swagger-Parser <= 1.0.30 and Swagger-Codegen <= 2.2.2 - Remote Code Execution via YAML Parsing
CVSS 8.8
nv-websocket-client - Man-in-the-Middle
CVSS 5.9
Plexus-utils <3.0.16 - Command Injection
CVSS 9.8
Undertow <1.4.17, <1.3.31, <2.0.0 - HTTP Request Smuggling
CVSS 2.6
libpam4j <= 1.8 - Authentication Bypass via Disabled Account Validation
CVSS 6.5
async-http-client < 2.0.35 - Server-Side Request Forgery via Fragment Identifier
CVSS 7.5
jackson-databind <2.8.10, 2.9.1 - Code Injection
CVSS 9.8
Apache Sling Authentication Service 1.4.0 - Exposure of Sensitive Information via Login Form Redirect
CVSS 8.8
Apache Sling XSS Protection API 1.0.4-1.0.18 and 2.0.0 - Cross-Site Scripting via URL Validation Bypass
CVSS 6.1
jackson-databind < 2.6.7.3, 2.9.0-2.9.3 - Unauthenticated Remote Code Execution via Malicious JSON Input
CVSS 9.8
SnakeYAML < 1.26 - XML Entity Expansion via Alias Feature
CVSS 7.5
Jenkins Active Directory Plugin <= 2.2 - Improper Certificate Validation
CVSS 8.1
Undertow < 1.3.31 - HTTP Request Smuggling via Invalid Request Line Characters
CVSS 6.5
Logback < 1.2.0 - Deserialization of Untrusted Data in SocketServer and ServerSocketReceiver
CVSS 9.8
Undertow <2.0.0.Alpha2,<1.4.17.Final,<1.3.31.Final - SSRF
CVSS 6.1
Red Hat JBoss EAP 3.0.7-3.0.25.Final - Server-Side Cache Poisoning via JAX-RS Component
CVSS 7.5
Apache CXF Fediz <1.4.0-1.2.4 - CSRF
CVSS 8.8
Apache CXF Fediz <1.4.0-1.3.2 - CSRF
CVSS 8.8
Apache MyFaces Core <2.0.12, <2.1.6 - Path Traversal