Ipa maintains a small portfolio of specialized application and educational software, including project-monitoring tools, code-analysis utilities, and simulation environments. The vendor's recurring vulnerability exposure centers on application input-handling and web-interface weaknesses—cross-site scripting, cross-site request forgery, and input-validation flaws—that are characteristic of web-facing and interactive tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ipa over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2181HIGH Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors, a different vulnerabilit | Jun 9, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-2182HIGH Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors, a different vulnerabilit | Jun 9, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-2179HIGH Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors, a different vulnerability than CVE-2017- | Jun 9, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-2175HIGH Untrusted search path vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directo | May 22, 2017 | 7.8 | 25 | NO | NO |
CVE-2017-2220HIGH Untrusted search path vulnerability in Installer of CASL II simulator (self-extract format) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory | Jul 7, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-2102HIGH Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to hijack the authe | Apr 28, 2017 | 8.8 | 22 | NO | NO |
CVE-2017-2100MEDIUM Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attacks via unspecified vectors. | Apr 28, 2017 | 6.3 | 22 | NO | NO |
CVE-2017-2174MEDIUM Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | May 22, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-2101HIGH Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arbitrary operations via unspecifi | Apr 28, 2017 | 7.3 | 21 | NO | NO |
CVE-2019-6019HIGH Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Dec 26, 2019 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ipa.
Media articles that mention a CVE ID that affects a product developed by Ipa — matched by CVE ID, not by vendor name.