jquery kayıtları
jquery üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %9,1
- Silahlaştırılmış
- 1 · %9,1
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %72,7
- Yayından KEV’e ortanca
- 1730 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-674 Uncontrolled Recursion1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
79Bu hafta | CVE-2020-11023Silahlaştırılmış | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Orta6,1 | KEV | %84,9 | 29 Nis 2020 |
54Planlayın | CVE-2020-11022Kavram kanıtı | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Orta6,1 | — | %99,2 | 29 Nis 2020 |
50Planlayın | CVE-2019-11358Kavram kanıtı | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Orta6,1 | — | %87,2 | 19 Nis 2019 |
33İzleyin | CVE-2015-9251Kavram kanıtı | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType ojquery · jquery · CWE-79 | Orta6,1 | — | %29,7 | 18 Oca 2018 |
31İzleyin | CVE-2016-10707İstismar yok | jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names.jquery · jquery · CWE-674 | Yüksek7,5 | — | %2,9 | 18 Oca 2018 |
27İzleyin | CVE-2012-6708Kavram kanıtı | jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks.jquery · jquery · CWE-79 | Orta6,1 | — | %8,6 | 18 Oca 2018 |
26İzleyin | CVE-2020-7656Kavram kanıtı | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.jquery · jquery · CWE-79 | Orta6,1 | — | %6,3 | 19 May 2020 |
25İzleyin | CVE-2014-6071İstismar yok | jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside aftejquery · jquery · CWE-79 | Orta6,1 | — | %2,3 | 16 Oca 2018 |
24İzleyin | CVE-2018-18405İstismar yok | jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.jquery · jquery · CWE-79 | Orta6,1 | — | %1,7 | 22 Nis 2020 |
23İzleyin | CVE-2011-4969İstismar yok | Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to injjquery · jquery · CWE-79 | Orta4,3 | — | %19,2 | 8 Mar 2013 |
21İzleyin | CVE-2007-2379İstismar yok | The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attjquery · jquery · CWE-200 | Orta5,0 | — | %2,8 | 30 Nis 2007 |
- CVE-2020-1102379Bu hafta
Potential XSS vulnerability in jQuery
OrtaCVSS 6,1KEVSilahlaştırılmışEPSS %85jquery · jquery29 Nis 2020
- CVE-2020-1102254Planlayın
jQuery has a potential XSS vulnerability
OrtaCVSS 6,1Kavram kanıtıEPSS %99jquery · jquery29 Nis 2020
- CVE-2019-1135850Planlayın
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
OrtaCVSS 6,1Kavram kanıtıEPSS %87jquery · jquery19 Nis 2019
- CVE-2015-925133İzleyin
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType o
OrtaCVSS 6,1Kavram kanıtıEPSS %30jquery · jquery18 Oca 2018
- CVE-2016-1070731İzleyin
jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names.
YüksekCVSS 7,5İstismar yokEPSS %3jquery · jquery18 Oca 2018
- CVE-2012-670827İzleyin
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks.
OrtaCVSS 6,1Kavram kanıtıEPSS %9jquery · jquery18 Oca 2018
- CVE-2020-765626İzleyin
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.
OrtaCVSS 6,1Kavram kanıtıEPSS %6jquery · jquery19 May 2020
- CVE-2014-607125İzleyin
jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside afte
OrtaCVSS 6,1İstismar yokEPSS %2jquery · jquery16 Oca 2018
- CVE-2018-1840524İzleyin
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.
OrtaCVSS 6,1İstismar yokEPSS %2jquery · jquery22 Nis 2020
- CVE-2011-496923İzleyin
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj
OrtaCVSS 4,3İstismar yokEPSS %19jquery · jquery8 Mar 2013
- CVE-2007-237921İzleyin
The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote att
OrtaCVSS 5,0İstismar yokEPSS %3jquery · jquery30 Nis 2007