cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-38485,https://securityvulnerability.io/vulnerability/CVE-2024-38485,Host Header Injection Vulnerability in Dell ECS Versions,"Dell ECS versions preceding 3.8.0 are susceptible to a Host Header Injection vulnerability. This flaw permits a remote attacker with low privileges to execute exploits that may result in redirections, ultimately leading to the exposure of sensitive information. The vulnerability underscores the need for timely security updates and awareness among users of the affected product.",Dell,Elastic Cloud Storage,4.3,MEDIUM,0.0006099999882280827,false,,false,false,false,,,false,false,,2024-12-09T15:15:00.000Z,0 CVE-2020-5386,https://securityvulnerability.io/vulnerability/CVE-2020-5386,,"Dell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list of DT (Directory Table) objects of all internally running services and gain knowledge of sensitive data of the system.",Dell,Elastic Cloud Storage,8.1,HIGH,0.0037799999117851257,false,,false,false,false,,,false,false,,2020-09-02T21:15:00.000Z,0 CVE-2020-5317,https://securityvulnerability.io/vulnerability/CVE-2020-5317,,"Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.",Dell,Elastic Cloud Storage,6.2,MEDIUM,0.0006600000197067857,false,,false,false,false,,,false,false,,2020-02-06T18:15:00.000Z,0 CVE-2019-3766,https://securityvulnerability.io/vulnerability/CVE-2019-3766,,Dell EMC ECS versions prior to 3.4.0.0 contain an improper restriction of excessive authentication attempts vulnerability. An unauthenticated remote attacker may potentially perform a password brute-force attack to gain access to the targeted accounts.,Dell,Elastic Cloud Storage,8.1,HIGH,0.005510000046342611,false,,false,false,false,,,false,false,,2019-09-27T21:15:00.000Z,0 CVE-2017-8021,https://securityvulnerability.io/vulnerability/CVE-2017-8021,,EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially be leveraged by malicious users to compromise the affected system.,Dell,Emc Elastic Cloud Storage All Versions Prior To 3.1,9.8,CRITICAL,0.0021200000774115324,false,,false,false,false,,,false,false,,2017-10-03T01:29:00.000Z,0