ipa records
16 published records for vendor ipa.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-426 Untrusted Search Path4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2017-2179No exploit | Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors, ipa · appgoat · CWE-20 | High8.8 | — | 2.3% | Jun 9, 2017 |
35Monitor | CVE-2017-2182No exploit | Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspeipa · appgoat | High8.8 | — | 1.5% | Jun 9, 2017 |
35Monitor | CVE-2017-2181No exploit | Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspeipa · appgoat | High8.8 | — | 1.5% | Jun 9, 2017 |
35Monitor | CVE-2017-2102No exploit | Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allipa · appgoat · CWE-352 | High8.8 | — | 0.8% | Apr 28, 2017 |
31Monitor | CVE-2017-2175No exploit | Untrusted search path vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to gain privileges via a Tripa · empirical project monitor - extended · CWE-426 | High7.8 | — | 1.4% | May 22, 2017 |
31Monitor | CVE-2017-10820No exploit | Untrusted search path vulnerability in Installer of IP Messenger for Win 4.60 and earlier allows an attacker to gain privileges via a Trojanipa · ip messenger · CWE-426 | High7.8 | — | 1.1% | Aug 4, 2017 |
31Monitor | CVE-2017-2220No exploit | Untrusted search path vulnerability in Installer of CASL II simulator (self-extract format) allows an attacker to gain privileges via a Trojipa · casl ii simulator · CWE-426 | High7.8 | — | 0.9% | Jul 7, 2017 |
31Monitor | CVE-2019-6019No exploit | Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL iipa · stamp workbench · CWE-426 | High7.8 | — | 0.8% | Dec 26, 2019 |
29Monitor | CVE-2017-2101No exploit | Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to peipa · appgoat · CWE-287 | High7.3 | — | 1.5% | Apr 28, 2017 |
25Monitor | CVE-2017-2099No exploit | Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote code execution via unspecified vectors.ipa · appgoat | Medium6.3 | — | 1.5% | Apr 28, 2017 |
25Monitor | CVE-2017-2100No exploit | Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attacipa · appgoat · CWE-20 | Medium6.3 | — | 1.0% | Apr 28, 2017 |
24Monitor | CVE-2017-2174No exploit | Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to inject arbitrary web scriipa · empirical project monitor - extended · CWE-79 | Medium6.1 | — | 1.2% | May 22, 2017 |
24Monitor | CVE-2017-2194No exploit | Cross-site scripting vulnerability in Source code security studying tool iCodeChecker allows an attacker to inject arbitrary web script or Hipa · icodechecker · CWE-79 | Medium6.1 | — | 0.7% | Jul 7, 2017 |
21Monitor | CVE-2017-2173No exploit | Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote authenticated attackers to inject arbiipa · empirical project monitor - extended · CWE-79 | Medium5.4 | — | 0.9% | May 22, 2017 |
17Monitor | CVE-2014-7248No exploit | Cross-site scripting (XSS) vulnerability in IPA iLogScanner 4.0 allows remote attackers to inject arbitrary web script or HTML by triggeringipa · ilogscanner · CWE-79 | Medium4.3 | — | 1.1% | Nov 14, 2014 |
17Monitor | CVE-2017-2180No exploit | Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspeipa · appgoat · CWE-200 | Medium4.3 | — | 1.1% | Jun 9, 2017 |
- CVE-2017-217936Monitor
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors,
HighCVSS 8.8No exploitEPSS 2%ipa · appgoatJun 9, 2017
- CVE-2017-218235Monitor
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspe
HighCVSS 8.8No exploitEPSS 2%ipa · appgoatJun 9, 2017
- CVE-2017-218135Monitor
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspe
HighCVSS 8.8No exploitEPSS 2%ipa · appgoatJun 9, 2017
- CVE-2017-210235Monitor
Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier all
HighCVSS 8.8No exploitEPSS 1%ipa · appgoatApr 28, 2017
- CVE-2017-217531Monitor
Untrusted search path vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to gain privileges via a Tr
HighCVSS 7.8No exploitEPSS 1%ipa · empirical project monitor - extendedMay 22, 2017
- CVE-2017-1082031Monitor
Untrusted search path vulnerability in Installer of IP Messenger for Win 4.60 and earlier allows an attacker to gain privileges via a Trojan
HighCVSS 7.8No exploitEPSS 1%ipa · ip messengerAug 4, 2017
- CVE-2017-222031Monitor
Untrusted search path vulnerability in Installer of CASL II simulator (self-extract format) allows an attacker to gain privileges via a Troj
HighCVSS 7.8No exploitEPSS 1%ipa · casl ii simulatorJul 7, 2017
- CVE-2019-601931Monitor
Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL i
HighCVSS 7.8No exploitEPSS 1%ipa · stamp workbenchDec 26, 2019
- CVE-2017-210129Monitor
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to pe
HighCVSS 7.3No exploitEPSS 1%ipa · appgoatApr 28, 2017
- CVE-2017-209925Monitor
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote code execution via unspecified vectors.
MediumCVSS 6.3No exploitEPSS 2%ipa · appgoatApr 28, 2017
- CVE-2017-210025Monitor
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attac
MediumCVSS 6.3No exploitEPSS 1%ipa · appgoatApr 28, 2017
- CVE-2017-217424Monitor
Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to inject arbitrary web scri
MediumCVSS 6.1No exploitEPSS 1%ipa · empirical project monitor - extendedMay 22, 2017
- CVE-2017-219424Monitor
Cross-site scripting vulnerability in Source code security studying tool iCodeChecker allows an attacker to inject arbitrary web script or H
MediumCVSS 6.1No exploitEPSS 1%ipa · icodecheckerJul 7, 2017
- CVE-2017-217321Monitor
Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote authenticated attackers to inject arbi
MediumCVSS 5.4No exploitEPSS 1%ipa · empirical project monitor - extendedMay 22, 2017
- CVE-2014-724817Monitor
Cross-site scripting (XSS) vulnerability in IPA iLogScanner 4.0 allows remote attackers to inject arbitrary web script or HTML by triggering
MediumCVSS 4.3No exploitEPSS 1%ipa · ilogscannerNov 14, 2014
- CVE-2017-218017Monitor
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspe
MediumCVSS 4.3No exploitEPSS 1%ipa · appgoatJun 9, 2017