Vulnerabilities
35 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-4815 | Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3. Missing Authentication for Critical Function in GitHub repository answerdev/answer prior to v1.1.3. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-4125 | Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0. Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2023-2590 | Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9. Missing Authorization in GitHub repository answerdev/answer prior to 1.0.9. NVD description · AI analysis pending | 3.5 | <1% | PoC |
| — | |
| CVE-2023-1976 | Password Aging with Long Expiration in GitHub repository answerdev/answer prior to 1.0.6. Password Aging with Long Expiration in GitHub repository answerdev/answer prior to 1.0.6. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2023-1537 | Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6. Authentication Bypass by Capture-replay in GitHub repository answerdev/answer prior to 1.0.6. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-1242 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.6. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2023-0934 | Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.5. Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.5. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-0744 | Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4. NVD description · AI analysis pending | 9.8 group max | 6% | PoC |
| — | |
| CVE-2017-12775 | qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts. qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts. NVD description · AI analysis pending | 7.5 | 2% |
| — |