shoucheng3
136 exploits
Active since Dec 2012
Spring Boot Admin <2.7.8 - Info Disclosure
Apache Sling Servlets Resolver < 2.11.0 - Path Traversal and Remote Code Execution
CVSS 8.5
Apache DolphinScheduler <3.2.1 - Info Disclosure
CVSS 7.5
plexus-archiver < 4.8.0 - Arbitrary File Creation and Remote Code Execution via Symbolic Link Handling
CVSS 8.1
Apache Shiro <1.13.0, <2.0.0-alpha-4 - Path Traversal
CVSS 6.5
Apache DolphinScheduler <3.2.1 - RCE
CVSS 9.8
Apache DolphinScheduler <3.2.1 - Info Disclosure
CVSS 7.5
Yamcs 5.8.6 - Path Traversal in Storage API
CVSS 7.5
Apache RocketMQ - Remote Command Execution
CVSS 9.8
XWiki Rendering 14.6-14.10.3 - Cross-Site Scripting via Invalid Attribute Names
CVSS 9.0
Apache DolphinScheduler <3.2.1 - RCE
CVSS 9.8
Graylog 5.1.0-5.1.2 - Authenticated Path Traversal and Arbitrary File Deletion via Support Bundle API
CVSS 3.3
Yamcs 5.8.6 - Path Traversal via Storage API DELETE Request
CVSS 9.1
XWiki 5.0-14.4 and xwiki-commons-xml 4.2-milestone-1-14.5 - Stored Cross-Site Scripting via HTML Cleaner Restricted Mode
CVSS 9.0
HL7 FHIR Core Libraries <5.6.106 - Path Traversal
CVSS 7.5
XWiki Commons 4.2-milestone-1-14.9 - Cross-Site Scripting via Invalid HTML Comments
CVSS 9.0
HL7 FHIR Core Libraries <5.6.92 - Path Traversal
CVSS 8.1
Jenkins Script Security Plugin <1228.vd93135a_2fb_25 - Sandbox Bypass via Map Constructors
CVSS 8.8
org.xwiki.commons:xwiki-commons-xml - XSS
CVSS 9.0
XWiki Commons 14.6-14.10.5 - Remote Code Execution via HTML Sanitizer Bypass
CVSS 9.0
Apache MINA SSHD < 2.9.3 - Path Traversal via Parent Navigation
CVSS 5.0
Apache NiFi <1.22.0 - Authenticated RCE
CVSS 8.8
jstachio < 1.0.1 - Cross-Site Scripting via Single Quote Injection
CVSS 5.4
Apache RocketMQ update config RCE
CVSS 9.8
Apache NiFi 0.0.2-1.21.0 - Authenticated Remote Code Execution via H2 JDBC Database URL
CVSS 8.8