answer records
34 published records for vendor answer.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-613 Insufficient Session Expiration2
- CWE-840 Business Logic Errors2
- CWE-862 Missing Authorization2
- CWE-263 Password Aging with Long Expiration1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2023-0744Proof of concept | Improper Access Control in answerdev/answeranswer · answer · CWE-284 | Critical9.8 | — | 6.4% | Feb 8, 2023 |
39Monitor | CVE-2023-1537No exploit | Authentication Bypass by Capture-replay in answerdev/answeranswer · answer · CWE-294 | Critical9.8 | — | 0.8% | Mar 21, 2023 |
36Monitor | CVE-2023-0742No exploit | Cross-site Scripting (XSS) - Stored in answerdev/answeranswer · answer · CWE-79 | Critical9.0 | — | 0.9% | Feb 8, 2023 |
36Monitor | CVE-2023-0741No exploit | Cross-site Scripting (XSS) - DOM in answerdev/answeranswer · answer · CWE-79 | Critical9.0 | — | 0.9% | Feb 8, 2023 |
36Monitor | CVE-2023-0743No exploit | Cross-site Scripting (XSS) - Generic in answerdev/answeranswer · answer · CWE-79 | Critical9.0 | — | 0.7% | Feb 8, 2023 |
36Monitor | CVE-2023-0740No exploit | Cross-site Scripting (XSS) - Stored in answerdev/answeranswer · answer · CWE-79 | Critical9.0 | — | 0.7% | Feb 8, 2023 |
35Monitor | CVE-2023-4125No exploit | Weak Password Requirements in answerdev/answeranswer · answer · CWE-521 | High8.8 | — | 0.9% | Aug 3, 2023 |
35Monitor | CVE-2023-4815No exploit | Missing Authentication for Critical Function in answerdev/answeranswer · answer · CWE-306 | High8.8 | — | 0.8% | Sep 7, 2023 |
35Monitor | CVE-2023-1543No exploit | Insufficient Session Expiration in answerdev/answeranswer · answer · CWE-613 | High8.8 | — | 0.8% | Mar 21, 2023 |
35Monitor | CVE-2023-1976No exploit | Password Aging with Long Expiration in answerdev/answeranswer · answer · CWE-263 | High8.8 | — | 0.6% | Apr 11, 2023 |
35Monitor | CVE-2023-4126No exploit | Insufficient Session Expiration in answerdev/answeranswer · answer · CWE-613 | High8.8 | — | 0.6% | Aug 3, 2023 |
27Monitor | CVE-2023-0739No exploit | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in answerdev/answeranswer · answer · CWE-362 | Medium6.8 | — | 0.7% | Feb 8, 2023 |
26Monitor | CVE-2023-4124No exploit | Missing Authorization in answerdev/answeranswer · answer · CWE-862 | Medium6.5 | — | 0.7% | Aug 3, 2023 |
26Monitor | CVE-2023-1974No exploit | Exposure of Sensitive Information Through Metadata in answerdev/answeranswer · answer · CWE-1230 | Medium6.5 | — | 0.6% | Apr 11, 2023 |
26Monitor | CVE-2023-1975No exploit | Insertion of Sensitive Information Into Sent Data in answerdev/answeranswer · answer · CWE-201 | Medium6.5 | — | 0.6% | Apr 11, 2023 |
23Monitor | CVE-2023-4127No exploit | Race Condition within a Thread in answerdev/answeranswer · answer · CWE-366 | Medium5.9 | — | 0.5% | Aug 3, 2023 |
21Monitor | CVE-2023-1542No exploit | Business Logic Errors in answerdev/answeranswer · answer · CWE-840 | Medium5.4 | — | 0.8% | Mar 21, 2023 |
21Monitor | CVE-2023-1538No exploit | Observable Timing Discrepancy in answerdev/answeranswer · answer · CWE-208 | Medium5.3 | — | 0.6% | Mar 21, 2023 |
21Monitor | CVE-2023-1540No exploit | Observable Response Discrepancy in answerdev/answeranswer · answer · CWE-204 | Medium5.3 | — | 0.6% | Mar 21, 2023 |
21Monitor | CVE-2023-1242No exploit | Cross-site Scripting (XSS) - Stored in answerdev/answeranswer · answer · CWE-79 | Medium5.4 | — | 0.6% | Mar 7, 2023 |
21Monitor | CVE-2023-1241No exploit | Cross-site Scripting (XSS) - Stored in answerdev/answeranswer · answer · CWE-79 | Medium5.4 | — | 0.6% | Mar 7, 2023 |
21Monitor | CVE-2023-1240No exploit | Cross-site Scripting (XSS) - Stored in answerdev/answeranswer · answer · CWE-79 | Medium5.4 | — | 0.6% | Mar 7, 2023 |
21Monitor | CVE-2023-1539No exploit | Improper Restriction of Excessive Authentication Attempts in answerdev/answeranswer · answer · CWE-307 | Medium5.3 | — | 0.6% | Mar 21, 2023 |
21Monitor | CVE-2023-1238No exploit | Cross-site Scripting (XSS) - Stored in answerdev/answeranswer · answer · CWE-79 | Medium5.4 | — | 0.6% | Mar 7, 2023 |
21Monitor | CVE-2023-1535No exploit | Cross-site Scripting (XSS) - Stored in answerdev/answeranswer · answer · CWE-79 | Medium5.4 | — | 0.5% | Mar 21, 2023 |
- CVE-2023-074441Plan
Improper Access Control in answerdev/answer
CriticalCVSS 9.8Proof of conceptEPSS 6%answer · answerFeb 8, 2023
- CVE-2023-153739Monitor
Authentication Bypass by Capture-replay in answerdev/answer
CriticalCVSS 9.8No exploitEPSS 1%answer · answerMar 21, 2023
- CVE-2023-074236Monitor
Cross-site Scripting (XSS) - Stored in answerdev/answer
CriticalCVSS 9.0No exploitEPSS 1%answer · answerFeb 8, 2023
- CVE-2023-074136Monitor
Cross-site Scripting (XSS) - DOM in answerdev/answer
CriticalCVSS 9.0No exploitEPSS 1%answer · answerFeb 8, 2023
- CVE-2023-074336Monitor
Cross-site Scripting (XSS) - Generic in answerdev/answer
CriticalCVSS 9.0No exploitEPSS 1%answer · answerFeb 8, 2023
- CVE-2023-074036Monitor
Cross-site Scripting (XSS) - Stored in answerdev/answer
CriticalCVSS 9.0No exploitEPSS 1%answer · answerFeb 8, 2023
- CVE-2023-412535Monitor
Weak Password Requirements in answerdev/answer
HighCVSS 8.8No exploitEPSS 1%answer · answerAug 3, 2023
- CVE-2023-481535Monitor
Missing Authentication for Critical Function in answerdev/answer
HighCVSS 8.8No exploitEPSS 1%answer · answerSep 7, 2023
- CVE-2023-154335Monitor
Insufficient Session Expiration in answerdev/answer
HighCVSS 8.8No exploitEPSS 1%answer · answerMar 21, 2023
- CVE-2023-197635Monitor
Password Aging with Long Expiration in answerdev/answer
HighCVSS 8.8No exploitEPSS 1%answer · answerApr 11, 2023
- CVE-2023-412635Monitor
Insufficient Session Expiration in answerdev/answer
HighCVSS 8.8No exploitEPSS 1%answer · answerAug 3, 2023
- CVE-2023-073927Monitor
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in answerdev/answer
MediumCVSS 6.8No exploitEPSS 1%answer · answerFeb 8, 2023
- CVE-2023-412426Monitor
Missing Authorization in answerdev/answer
MediumCVSS 6.5No exploitEPSS 1%answer · answerAug 3, 2023
- CVE-2023-197426Monitor
Exposure of Sensitive Information Through Metadata in answerdev/answer
MediumCVSS 6.5No exploitEPSS 1%answer · answerApr 11, 2023
- CVE-2023-197526Monitor
Insertion of Sensitive Information Into Sent Data in answerdev/answer
MediumCVSS 6.5No exploitEPSS 1%answer · answerApr 11, 2023
- CVE-2023-412723Monitor
Race Condition within a Thread in answerdev/answer
MediumCVSS 5.9No exploitEPSS 0%answer · answerAug 3, 2023
- CVE-2023-154221Monitor
Business Logic Errors in answerdev/answer
MediumCVSS 5.4No exploitEPSS 1%answer · answerMar 21, 2023
- CVE-2023-153821Monitor
Observable Timing Discrepancy in answerdev/answer
MediumCVSS 5.3No exploitEPSS 1%answer · answerMar 21, 2023
- CVE-2023-154021Monitor
Observable Response Discrepancy in answerdev/answer
MediumCVSS 5.3No exploitEPSS 1%answer · answerMar 21, 2023
- CVE-2023-124221Monitor
Cross-site Scripting (XSS) - Stored in answerdev/answer
MediumCVSS 5.4No exploitEPSS 1%answer · answerMar 7, 2023
- CVE-2023-124121Monitor
Cross-site Scripting (XSS) - Stored in answerdev/answer
MediumCVSS 5.4No exploitEPSS 1%answer · answerMar 7, 2023
- CVE-2023-124021Monitor
Cross-site Scripting (XSS) - Stored in answerdev/answer
MediumCVSS 5.4No exploitEPSS 1%answer · answerMar 7, 2023
- CVE-2023-153921Monitor
Improper Restriction of Excessive Authentication Attempts in answerdev/answer
MediumCVSS 5.3No exploitEPSS 1%answer · answerMar 21, 2023
- CVE-2023-123821Monitor
Cross-site Scripting (XSS) - Stored in answerdev/answer
MediumCVSS 5.4No exploitEPSS 1%answer · answerMar 7, 2023
- CVE-2023-153521Monitor
Cross-site Scripting (XSS) - Stored in answerdev/answer
MediumCVSS 5.4No exploitEPSS 1%answer · answerMar 21, 2023