shoucheng3
136 exploits
Active since Dec 2012
Eclipse GlassFish 5.1.0-6.2.5 - Unauthenticated Path Traversal via Relative Path
CVSS 6.5
Apache DolphinScheduler <2.0.6 - Info Disclosure
CVSS 6.5
com.diffplug.gradle:goomph <3.37.2 - Code Injection
CVSS 5.3
alibaba one-java-agent-plugin < 0.0.2 - Arbitrary File Write via Zip Slip Archive Extraction
CVSS 6.9
Jenkins Pipeline Multibranch < 706.vd43c65dec013 - Authenticated OS Command Injection via readTrusted Step
CVSS 8.8
Jenkins Pipeline < 552.vd9cc05b8a2e1 - Authenticated OS Command Injection via SCM Checkout Directory
CVSS 8.8
Jenkins Pipeline: Groovy Plugin < 2648.va9433432b33c - OS Command Injection via SCM Content
CVSS 8.8
XWiki 2.3-12.6.6 - Authenticated Path Traversal via Velocity Script File API
CVSS 7.5
OWASP Enterprise Security API < 2.3.0.0 - Cross-Site Scripting via antisamy-esapi.xml onsiteURL Regex
CVSS 5.4
OWASP Enterprise Security API < 2.3.0.0 - Path Traversal via Validator.getValidDirectoryPath
CVSS 7.5
CureKit 1.0.1-1.1.3 - Path Traversal via isFileOutsideDir Input Sanitization Bypass
CVSS 7.5
Jenkins Docker Commons Plugin <1.17 - Command Injection
CVSS 8.8
Spring Framework - Remote Code Execution via Data Binding
CVSS 9.8
Spring Cloud Gateway Remote Code Execution
CVSS 10.0
Apache Karaf < 4.2.15 and 4.3.0-4.3.6 - Path Traversal via obr Commands and karaf-maven-plugin
CVSS 5.3
Keycloak < 20.0.5 - Cross-Site Scripting via Execute-Actions-Email Endpoint
CVSS 5.4
fabric8-kubernetes 5.0.0-beta-1-5.0.3 - Arbitrary Code Execution via YAML Parsing
CVSS 6.7
Apache Commons IO - Path Traversal via FileNameUtils.normalize
CVSS 4.8
Apache Dubbo < 2.7.10 - Remote Code Execution via Tag Routing YAML Parsing
CVSS 9.8
Apache Dubbo 2.5.0-2.6.8 and 2.5.0-2.7.8 - Remote Code Execution via Script Routing Rule Parsing
CVSS 9.8
cron-utils < 9.1.6 - Unauthenticated Remote Code Execution via Java EL Expression Injection
CVSS 10.0
Nacos 2.0.3 - Cross-Site Scripting via Auth Users Page Parameters
CVSS 6.1
XXL-JOB < 2.3.0 - Stored Cross-Site Scripting in Add User via Username Parameter
CVSS 6.1
Netapp Oncommand Insight < 5.15.14 - Insecure Deserialization
CVSS 5.8
Kubernetes Java Client <10.0.0 - Path Traversal
CVSS 9.1