← All credits
Jonathan Leitschuh
18 vulnerability records and advisories credit this contributor.
CVE-2025-9611
Microsoft Playwright MCP Server < 0.0.40 DNS Rebinding via Missing Origin Header Validation
CVE-2020-36851
Rob--W cors-anywhere Misconfigured CORS Proxy Allows SSRF
CVE-2025-1686
Versions of the package io.pebbletemplates:pebble from 0 and before 4.1.0 are vulnerable to External Control of File Name or Path via the include tag. A high privileged attacker can access sensitive local files by crafting malicious notification templates
CVE-2024-36264
Apache Submarine Commons Utils: default secret
CVE-2024-24683
Apache Hop Engine: ID isn't escaped when generating HTML
CVE-2024-22281
Apache Helix Front (UI): Helix front hard-coded secret in the express-session
CVE-2023-50740
Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged
CVE-2022-45787
Apache James MIME4J: Temporary File Information Disclosure in MIME4J TempFileStorageProvider
CVE-2022-26049
Arbitrary File Write via Archive Extraction (Zip Slip)
CVE-2022-24913
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing tempora