dawetmaster
165 exploits
Active since Aug 2013
Apache Qpid Broker for Java <6.0.6, <6.1.1 - Info Disclosure
CVSS 7.5
Apache Brooklyn <0.10.0 - Code Injection
CVSS 8.8
Spark 2.5 - Path Traversal
CVSS 7.5
Redhat Jboss Wildfly Application Server < 10.1.0 - Denial of Service
CVSS 7.5
Redhat Resteasy < 3.1.1 - Improper Input Validation
CVSS 8.1
Swagger-Parser <=1.0.30 & Swagger Codegen <=2.2.2 - RCE
CVSS 8.8
Swagger-Parser <=1.0.30 - RCE
CVSS 8.8
nv-websocket-client - Man-in-the-Middle
CVSS 5.9
Plexus-utils <3.0.16 - Command Injection
CVSS 9.8
Undertow <1.4.17, <1.3.31, <2.0.0 - HTTP Request Smuggling
CVSS 2.6
libpam4j <1.9 - Auth Bypass
CVSS 6.5
Async Http Client <2.0.35 - SSRF
CVSS 7.5
jackson-databind <2.8.10, 2.9.1 - Code Injection
CVSS 9.8
Apache Sling Authentication Service < 1.4.2 - Information Disclosure
CVSS 8.8
Apache Sling Xss Protection API < 1.0.18 - XSS
CVSS 6.1
Fasterxml Jackson-databind < 2.6.7.3 - Insecure Deserialization
CVSS 9.8
SnakeYAML <1.26 - Entity Expansion
CVSS 7.5
Jenkins Active Directory < 2.2 - Improper Certificate Validation
CVSS 8.1
Redhat Undertow < 1.3.31 - HTTP Request Smuggling
CVSS 6.5
QOS Logback < 1.2.0 - Insecure Deserialization
CVSS 9.8
Undertow <2.0.0.Alpha2,<1.4.17.Final,<1.3.31.Final - SSRF
CVSS 6.1
Red Hat JBoss EAP <4.0.0.Beta1 - SSRF
CVSS 7.5
Apache CXF Fediz <1.4.0-1.2.4 - CSRF
CVSS 8.8
Apache CXF Fediz <1.4.0-1.3.2 - CSRF
CVSS 8.8
Apache MyFaces Core <2.0.12, <2.1.6 - Path Traversal