dawetmaster
165 exploits
Active since Aug 2013
FasterXML Jackson <2.9.7 - Code Injection
CVSS 9.8
FasterXML jackson-databind 2.0.0-2.6.7.2 - Remote Code Execution via BlazeDS Polymorphic Deserialization
CVSS 9.8
FasterXML jackson-databind 2.6.0-2.6.7.1 - XML External Entity Injection via Polymorphic Deserialization
CVSS 9.8
FasterXML jackson-databind <2.9.7 - SSRF
CVSS 10.0
Apache Qpid Proton-J 0.3-0.29.0 - Improper Certificate Validation in TLS Transport Wrapper
CVSS 7.4
FasterXML jackson-databind <2.9.8 - Code Injection
CVSS 9.8
FasterXML jackson-databind <2.9.8 - Deserialization
CVSS 9.8
FasterXML jackson-databind <2.9.8 - Use After Free
CVSS 9.8
RDF4J < 2.5.0 - Path Traversal via ZIP Archive Entry
CVSS 7.5
.weixin-java-tools <3.2.0 - Info Disclosure
CVSS 9.8
FasterXML jackson-databind <2.8.11, 2.9.x<2.9.3 - RCE
CVSS 8.1
jackson-databind < 2.7.9.3, 2.8.0-2.8.11.1, < 2.9.5 - Remote Code Execution via Deserialization Bypass
CVSS 9.8
Apache Qpid Broker-J 7.0.0-7.0.4 - Denial of Service via Oversized AMQP Message
CVSS 7.5
sparkjava/spark < 2.7.2 - Path Traversal via File URL
CVSS 5.3
Apache ZooKeeper 1.0.0-3.4.13 and 3.5.0-alpha-3.5.4-beta - Unauthenticated Information Disclosure via getACL() Command
CVSS 5.9
Jenkins Script Security Plugin < 1.50 - Sandbox Bypass Remote Code Execution
CVSS 8.8
Jenkins Git Plugin < 3.9.1 - Cross-Site Request Forgery in GitTagAction
CVSS 4.3
Hibernate Validator < 6.0.18 - Cross-Site Scripting via SafeHtml Validator Annotation
CVSS 6.1
FasterXML jackson-databind <2.9.9 - Code Injection
CVSS 7.5
FasterXML jackson-databind <2.9.9.1 - Deserialization
CVSS 5.9
Apache Santuario XML Security for Java <2.0.3 - Info Disclosure
CVSS 5.5
Apache Commons Compress <1.19 - DoS
CVSS 7.5
jackson-databind 2.0.0-2.9.9 - Unauthenticated Arbitrary File Read via JDOM Polymorphic Typing
CVSS 5.9
jackson-databind < 2.9.9.2 - Remote Code Execution via Default Typing with Ehcache
CVSS 9.8
FasterXML jackson-databind <2.9.9.2 - Info Disclosure
CVSS 7.5