jas502n
68 exploits
Active since May 2015
Oracle WebLogic Server <12.2.1.3 - RCE
Webmin <= 1.920 - OS Command Injection via password_change.cgi Old Parameter
Oracle WebLogic Server <12.2.1.3 - Confidentiality Impaired
Spring Data Commons < 1.13.11 - Unauthenticated Remote Code Execution via Property Binder
Pulse Secure PCS <9.0R3.4 - Info Disclosure
Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 - Authenticated Remote Code Execution via T3
Nexus Repository Manager Java EL Injection RCE
Webmin < 1.920 - Authenticated Remote Code Execution via unserialise_variable Eval Call
Apache ShardingSphere 4.0.0-RC3-4.0.0 - Remote Code Execution via SnakeYAML Deserialization
Jira Server 7.6.0-8.3.9 - Server-Side Request Forgery via Gadgets MakeRequest Endpoint
MikroTik RouterOS <6.42 - Path Traversal
XStream <1.4.15 - File Deletion
Apache Struts 2.3.x < 2.3.32 and 2.5.x < 2.5.10.1 - Remote Code Execution via Jakarta Multipart Parser
Nagios XI 5.6.9 - Authenticated OS Command Injection via schedulereport.php id Parameter
Jenkins Git Client Plugin < 2.8.4 - OS Command Injection via Git ls-remote URL Argument
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
libssh Authentication Bypass Scanner
Apache Struts 2.3.x < 2.3.32 and 2.5.x < 2.5.10.1 - Remote Code Execution via Jakarta Multipart Parser
Oracle WebLogic Server <12.2.1.3 - RCE
Confluence 6.1.0-6.6.15, 6.7.0-6.13.6, 6.14.0-6.15.7 - Authenticated Local File Disclosure via Page Export
xorg-x11-server <1.20.3 - Privilege Escalation
Docker Container Escape Via runC Overwrite
Apache ActiveMQ <5.13.0 - RCE
Oracle WebLogic Server <12.2.1.3 - RCE
Oracle WebLogic Server <12.2.1.3 - RCE