dskho

2 exploits Active since Mar 2021
CVE-2021-45232 NOMISEC CRITICAL SCANNER
Apache APISIX Dashboard < 2.10.1 - Unauthenticated API Access via Gin Framework Bypass
In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of framework `gin` thus bypassing the authentication.
CVSS 9.8
CVE-2021-26295 NOMISEC CRITICAL WORKING POC
Apache OFBiz SOAP Java Deserialization
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
CVSS 9.8