romeara
22 exploits
Active since Jan 2008
Apache ActiveMQ 5.x < 5.10.1 - Cross-Site Scripting in Web Administration Console
1 stars
Apache CXF < 3.1.16 and 3.2.0-3.2.5 - Improper TLS Hostname Verification
CVSS 8.1
Eclipse Vert.x <3.5.1 - Code Injection
CVSS 5.3
Eclipse Vert.x 3.0.0-3.5.2 - Cross-Site Request Forgery via XSRF Token Replay
CVSS 8.8
Spring Data Commons 1.13-1.13.11 & 2.0-2.0.6 - XXE via Projection-Based Request Binding
CVSS 7.5
Spring Framework < 4.3.16 and 5.0 < 5.0.5 - Remote Code Execution via STOMP over WebSocket
CVSS 9.8
Apache Derby 10.3.1.4-10.14.1.0 - Info Disclosure
CVSS 5.3
Apache Commons Compress 1.11-1.15 - Denial of Service via ZIP Extra Field Parser
CVSS 5.5
Play Framework 2.6.12-2.6.15 - Path Traversal via Assets Controller
CVSS 7.5
jackson-databind < 2.7.9.3, 2.8.0-2.8.11.1, < 2.9.5 - Remote Code Execution via Deserialization Bypass
CVSS 9.8
Apache CXF Fediz <1.4.4 - Info Disclosure
CVSS 7.5
postgresql-jdbc <42.2.5 - SSL Man-In-The-Middle
CVSS 8.1
junrar < 1.0.1 - Denial of Service via Corrupt RAR File Handling
CVSS 5.5
jackson-databind < 2.6.7.3, 2.9.0-2.9.3 - Unauthenticated Remote Code Execution via Malicious JSON Input
CVSS 9.8
Undertow < 1.3.31 - HTTP Request Smuggling via Invalid Request Line Characters
CVSS 6.5
WildFly <10.0.0.Final - Info Disclosure
CVSS 7.5
Apache Struts 2.3.19-2.3.28.1 - Remote Code Execution via REST Plugin
CVSS 9.8
Apache Sling XSS Protection API < 1.0.12 - XML External Entity Injection via Insecure SAX Parser
CVSS 9.8
Apache CXF 3.0.0-3.0.15, 3.1.0-3.1.13, 3.2.0 - Denial of Service via Large Message Attachment Header
CVSS 5.5
Apache Tomcat <5.5.21 - Info Disclosure
Apache CXF Cryptographic Downgrade via WS-SecurityPolicy AlgorithmSuite Bypass
IBM Java - Denial of Service via XML Attribute Names