Hexo kayıtları
hexo üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %66,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-294 Authentication Bypass by Capture-replay1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-39584İstismar yok | Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.hexo · hexo · CWE-22 | Yüksek7,5 | — | %34,5 | 8 Eyl 2023 |
39İzleyin | CVE-2023-47435İstismar yok | An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected CWE-294 | Kritik9,8 | — | %0,6 | 19 Nis 2024 |
18İzleyin | CVE-2021-25987İstismar yok | Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS.hexo · hexo · CWE-79 | Orta4,6 | — | %0,3 | 30 Kas 2021 |
- CVE-2023-3958440Planlayın
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.
YüksekCVSS 7,5İstismar yokEPSS %35hexo · hexo8 Eyl 2023
- CVE-2023-4743539İzleyin
An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected
KritikCVSS 9,8İstismar yokEPSS %119 Nis 2024
- CVE-2021-2598718İzleyin
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS.
OrtaCVSS 4,6İstismar yokEPSS %0hexo · hexo30 Kas 2021