shoucheng3
136 exploits
Active since Dec 2012
org.xwiki.commons:xwiki-commons-xml - XSS
CVSS 9.0
Apache NiFi 0.0.2-1.21.0 - Authenticated Remote Code Execution via H2 JDBC Database URL
CVSS 8.8
Apache Shiro < 1.12.0 - Path Traversal and Authentication Bypass via Non-Normalized Request Routing
CVSS 9.8
sqlite-jdbc 3.6.14.1-3.41.2.1 - Remote Code Execution via JDBC URL
CVSS 8.8
Payara < 4.1.2.191.36 and < 5.2022.3 - Unauthenticated Path Traversal
CVSS 7.5
Keycloak - Path Traversal via Double URL Encoding
CVSS 9.1
ff4j 1.8.1 - Remote Code Execution
CVSS 9.8
Apache DolphinScheduler < 3.0.0 - Authenticated Path Traversal via Resource Center
CVSS 6.5
Venice < 1.10.17 - Partial Path Traversal via Absolute Path Handling
CVSS 6.1
ff4j 1.8.1 - Remote Code Execution
CVSS 9.8
DSpace dspace-jspui - Path Traversal
CVSS 8.2
DSpace 4.0-5.10 - Authenticated Path Traversal via ItemImportServiceImpl
CVSS 7.2
plexus-utils < 3.0.24 - Path Traversal via Dot-Dot-Slash Sequences
CVSS 7.5
Apache UIMA < 3.3.0 - Path Traversal via ZIP Entry in PEAR File
CVSS 7.5
Apache Commons Text 1.5-1.9 - Remote Code Execution via String Interpolation
CVSS 9.8
Apache JSPWiki < 2.12.0 - Cross-Site Scripting via Crafted Plugin Request
CVSS 6.1
cbeust testng <7.5.1,7.7.1 - Path Traversal
CVSS 5.5
Keycloak < 21.1.2 - Cross-Site Scripting via AssertionConsumerServiceURL or redirect_uri
CVSS 10.0
Keycloak < 20.0.5 - Reflected Cross-Site Scripting via OAuth OOB Endpoint
CVSS 8.1
Apache NiFi <1.16.2 - Command Injection
CVSS 8.8
DSpace 4.0-5.9 and dspace-jspui 5.0-5.10 - Stored Cross-Site Scripting in Request a Copy Form
CVSS 7.1
CureKit 1.0.1-1.1.3 - Path Traversal via isFileOutsideDir Input Sanitization Bypass
CVSS 7.5
Spring Framework - Remote Code Execution via Data Binding
CVSS 9.8
OWASP Enterprise Security API < 2.3.0.0 - Path Traversal via Validator.getValidDirectoryPath
CVSS 7.5
Spring Cloud Gateway Remote Code Execution
CVSS 10.0