Skip to content
Noroxi

marked project records

11 published records for vendor marked project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 18
  3. 20
  4. 21
  5. 22
  6. 25
  7. 26

Bar: total · dark part: CISA KEV.

All records

11 records
  • Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer

    HighCVSS 8.7No exploitEPSS 1%

    marked project · markedApr 24, 2026

  • CVE-2015-8854
    31Monitor

    The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that tri

    HighCVSS 7.5No exploitEPSS 4%

    marked project · markedJan 23, 2017

  • Cubic catastrophic backtracking (ReDoS) in marked

    HighCVSS 7.5No exploitEPSS 3%

    marked project · markedJan 14, 2022

  • Exponential catastrophic backtracking (ReDoS) in marked

    HighCVSS 7.5No exploitEPSS 3%

    marked project · markedJan 14, 2022

  • Denial of Service in Marked

    HighCVSS 7.5No exploitEPSS 2%

    marked project · markedFeb 8, 2021

  • The marked module is vulnerable to a regular expression denial of service.

    HighCVSS 7.5No exploitEPSS 2%

    marked project · markedJun 6, 2018

  • Regular Expression Denial of Service (ReDoS) in markedjs/marked

    MediumCVSS 6.9No exploitEPSS 1%

    marked project · markedMay 23, 2025

  • CVE-2014-3743
    25Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary

    MediumCVSS 6.1No exploitEPSS 2%

    marked project · markedJan 6, 2020

  • marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

    MediumCVSS 6.1No exploitEPSS 2%

    marked project · markedJan 2, 2018

  • marked is an application that is meant to parse and compile markdown.

    MediumCVSS 6.1No exploitEPSS 1%

    marked project · markedMay 31, 2018

  • CVE-2015-1370
    18Monitor

    Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) att

    MediumCVSS 4.3No exploitEPSS 2%

    marked project · markedJan 27, 2015