dawetmaster
165 exploits
Active since Aug 2013
Apache Commons Email <1.5 - Info Disclosure
CVSS 7.5
inversoft prime-jwt <1.3.0 - Info Disclosure
CVSS 9.8
prime-jwt < 1.3.0 - JWT Signature Validation Bypass via 'none' Algorithm
CVSS 7.5
codelibs fess < 12.2.3 and 12.3.0-12.3.1 - XML External Entity Injection in GSA XML File Parser
CVSS 10.0
Square Retrofit < 2.5.0 - XML External Entity Injection via JAXB
CVSS 9.1
jackson-modules-java8 < 2.9.8 - Denial of Service via Large Nanoseconds Field in Time Value
CVSS 6.5
Plexus-archiver <3.6.0 - Path Traversal
CVSS 5.5
zt-zip < 1.13 - Path Traversal via Zip Archive Entry Extraction
CVSS 5.5
postgresql-jdbc <42.2.5 - SSL Man-In-The-Middle
CVSS 8.1
Undertow < 1.4.25.Final - File Descriptor Leak via URLResource.getLastModified()
CVSS 6.5
jackson-databind 2.0.0-2.9.5 - Deserialization of Untrusted Data via iBatis Gadget Class
CVSS 9.8
Apache Commons Compress 1.7-1.17 - Denial of Service via Malformed ZIP Archive
CVSS 5.5
FasterXML jackson-databind <2.7.9.4, 2.8.11.2, 2.9.6 - Code Injection
CVSS 7.5
FasterXML jackson-databind <2.7.9.4-2.8.11.2-2.9.6 - Code Injection
CVSS 7.5
Eclipse Vert.x <3.5.1 - Code Injection
CVSS 5.3
Eclipse Vert.x 3.0.0-3.5.2 - Cross-Site Request Forgery via XSRF Token Replay
CVSS 8.8
Eclipse Vert.x <3.5.3 - Memory Corruption
CVSS 6.5
Eclipse Vert.x <3.5.3 - Path Traversal
CVSS 9.8
Eclipse Vert.x 3.5.Beta1-3.5.3 - XML External Entity Injection via OpenAPI XML Type Validator
CVSS 9.8
Spring Data Commons < 1.13.11 - Unauthenticated Remote Code Execution via Property Binder
CVSS 9.8
Pivotal Software Spring Data Commons < 1.13.11 - Resource Allocation Without Limits
CVSS 7.5
Apache Pluto 3.0.0 - Exposure of Sensitive Information via File Upload Path Disclosure
CVSS 7.5
Apache Commons Compress 1.11-1.15 - Denial of Service via ZIP Extra Field Parser
CVSS 5.5
Apache Directory LDAP API < 1.0.2 - Exposure of Sensitive Information via TLS Handshake Bypass
CVSS 9.8
Apache MyFaces Core <2.0.12, <2.1.6 - Path Traversal