AiLux kayıtları
ailux üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-425 Direct Request ('Forced Browsing')2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-1269 Product Released in Non-Release Configuration1
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-250 Execution with Unnecessary Privileges1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-45592İstismar yok | A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the ailux · imx6 · CWE-250 | Kritik9,8 | — | %0,7 | 5 Mar 2024 |
39İzleyin | CVE-2023-5457İstismar yok | A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to theailux · imx6 · CWE-1269 | Kritik9,8 | — | %0,6 | 5 Mar 2024 |
39İzleyin | CVE-2023-5456İstismar yok | A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacailux · imx6 · CWE-798 | Kritik9,8 | — | %0,6 | 5 Mar 2024 |
39İzleyin | CVE-2023-45600İstismar yok | A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, failux · imx6 · CWE-613 | Kritik9,8 | — | %0,4 | 5 Mar 2024 |
36İzleyin | CVE-2023-45597İstismar yok | A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web apailux · imx6 · CWE-1236 | Kritik9,0 | — | %0,4 | 5 Mar 2024 |
35İzleyin | CVE-2023-45591İstismar yok | A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated aailux · imx6 · CWE-122 | Yüksek8,8 | — | %0,7 | 5 Mar 2024 |
35İzleyin | CVE-2023-45595İstismar yok | A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application aailux · imx6 · CWE-434 | Yüksek8,8 | — | %0,4 | 5 Mar 2024 |
35İzleyin | CVE-2023-45599İstismar yok | A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web applicatailux · imx6 · CWE-646 | Yüksek8,8 | — | %0,2 | 5 Mar 2024 |
27İzleyin | CVE-2023-45594İstismar yok | A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker toailux · imx6 · CWE-552 | Orta6,8 | — | %0,3 | 5 Mar 2024 |
27İzleyin | CVE-2023-45593İstismar yok | A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLsailux · imx6 · CWE-184 | Orta6,8 | — | %0,3 | 5 Mar 2024 |
21İzleyin | CVE-2023-45596İstismar yok | A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remotailux · imx6 · CWE-425 | Orta5,3 | — | %0,5 | 5 Mar 2024 |
21İzleyin | CVE-2023-45598İstismar yok | A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthentailux · imx6 · CWE-425 | Orta5,3 | — | %0,5 | 5 Mar 2024 |
- CVE-2023-4559239İzleyin
A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the
KritikCVSS 9,8İstismar yokEPSS %1ailux · imx65 Mar 2024
- CVE-2023-545739İzleyin
A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the
KritikCVSS 9,8İstismar yokEPSS %1ailux · imx65 Mar 2024
- CVE-2023-545639İzleyin
A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attac
KritikCVSS 9,8İstismar yokEPSS %1ailux · imx65 Mar 2024
- CVE-2023-4560039İzleyin
A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, f
KritikCVSS 9,8İstismar yokEPSS %0ailux · imx65 Mar 2024
- CVE-2023-4559736İzleyin
A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web ap
KritikCVSS 9,0İstismar yokEPSS %0ailux · imx65 Mar 2024
- CVE-2023-4559135İzleyin
A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated a
YüksekCVSS 8,8İstismar yokEPSS %1ailux · imx65 Mar 2024
- CVE-2023-4559535İzleyin
A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application a
YüksekCVSS 8,8İstismar yokEPSS %0ailux · imx65 Mar 2024
- CVE-2023-4559935İzleyin
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web applicat
YüksekCVSS 8,8İstismar yokEPSS %0ailux · imx65 Mar 2024
- CVE-2023-4559427İzleyin
A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to
OrtaCVSS 6,8İstismar yokEPSS %0ailux · imx65 Mar 2024
- CVE-2023-4559327İzleyin
A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs
OrtaCVSS 6,8İstismar yokEPSS %0ailux · imx65 Mar 2024
- CVE-2023-4559621İzleyin
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remot
OrtaCVSS 5,3İstismar yokEPSS %0ailux · imx65 Mar 2024
- CVE-2023-4559821İzleyin
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthent
OrtaCVSS 5,3İstismar yokEPSS %0ailux · imx65 Mar 2024