Записи AiLux
12 опубликованных записей вендора ailux.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-425 Direct Request ('Forced Browsing')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-1269 Product Released in Non-Release Configuration1
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-45592Эксплойта нет | A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the ailux · imx6 · CWE-250 | Критическая9,8 | — | 0,7 % | 5 мар. 2024 г. |
39Наблюдать | CVE-2023-5457Эксплойта нет | A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to theailux · imx6 · CWE-1269 | Критическая9,8 | — | 0,6 % | 5 мар. 2024 г. |
39Наблюдать | CVE-2023-5456Эксплойта нет | A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacailux · imx6 · CWE-798 | Критическая9,8 | — | 0,6 % | 5 мар. 2024 г. |
39Наблюдать | CVE-2023-45600Эксплойта нет | A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, failux · imx6 · CWE-613 | Критическая9,8 | — | 0,4 % | 5 мар. 2024 г. |
36Наблюдать | CVE-2023-45597Эксплойта нет | A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web apailux · imx6 · CWE-1236 | Критическая9,0 | — | 0,4 % | 5 мар. 2024 г. |
35Наблюдать | CVE-2023-45591Эксплойта нет | A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated aailux · imx6 · CWE-122 | Высокая8,8 | — | 0,7 % | 5 мар. 2024 г. |
35Наблюдать | CVE-2023-45595Эксплойта нет | A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application aailux · imx6 · CWE-434 | Высокая8,8 | — | 0,4 % | 5 мар. 2024 г. |
35Наблюдать | CVE-2023-45599Эксплойта нет | A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web applicatailux · imx6 · CWE-646 | Высокая8,8 | — | 0,2 % | 5 мар. 2024 г. |
27Наблюдать | CVE-2023-45594Эксплойта нет | A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker toailux · imx6 · CWE-552 | Средняя6,8 | — | 0,3 % | 5 мар. 2024 г. |
27Наблюдать | CVE-2023-45593Эксплойта нет | A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLsailux · imx6 · CWE-184 | Средняя6,8 | — | 0,3 % | 5 мар. 2024 г. |
21Наблюдать | CVE-2023-45596Эксплойта нет | A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remotailux · imx6 · CWE-425 | Средняя5,3 | — | 0,5 % | 5 мар. 2024 г. |
21Наблюдать | CVE-2023-45598Эксплойта нет | A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthentailux · imx6 · CWE-425 | Средняя5,3 | — | 0,5 % | 5 мар. 2024 г. |
- CVE-2023-4559239Наблюдать
A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ailux · imx65 мар. 2024 г.
- CVE-2023-545739Наблюдать
A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ailux · imx65 мар. 2024 г.
- CVE-2023-545639Наблюдать
A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attac
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ailux · imx65 мар. 2024 г.
- CVE-2023-4560039Наблюдать
A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, f
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %ailux · imx65 мар. 2024 г.
- CVE-2023-4559736Наблюдать
A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web ap
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %ailux · imx65 мар. 2024 г.
- CVE-2023-4559135Наблюдать
A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated a
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ailux · imx65 мар. 2024 г.
- CVE-2023-4559535Наблюдать
A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application a
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ailux · imx65 мар. 2024 г.
- CVE-2023-4559935Наблюдать
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web applicat
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ailux · imx65 мар. 2024 г.
- CVE-2023-4559427Наблюдать
A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to
СредняяCVSS 6,8Эксплойта нетEPSS 0 %ailux · imx65 мар. 2024 г.
- CVE-2023-4559327Наблюдать
A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs
СредняяCVSS 6,8Эксплойта нетEPSS 0 %ailux · imx65 мар. 2024 г.
- CVE-2023-4559621Наблюдать
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remot
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ailux · imx65 мар. 2024 г.
- CVE-2023-4559821Наблюдать
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthent
СредняяCVSS 5,3Эксплойта нетEPSS 0 %ailux · imx65 мар. 2024 г.