Записи matrix-react-sdk project
6 опубликованных записей вендора matrix-react-sdk project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2024-47824Эксплойта нет | Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a roommatrix-org · matrix-react-sdk · CWE-200 | Высокая8,7 | — | 0,7 % | 15 окт. 2024 г. |
32Наблюдать | CVE-2023-28103Эксплойта нет | Prototype pollution in matrix-react-sdkmatrix-react-sdk project · matrix-react-sdk · CWE-1321 | Высокая8,2 | — | 0,7 % | 28 мар. 2023 г. |
31Наблюдать | CVE-2021-32622Эксплойта нет | File upload local preview can run embedded scripts after user interactionmatrix-react-sdk project · matrix-react-sdk · CWE-74 | Высокая7,8 | — | 0,4 % | 17 мая 2021 г. |
21Наблюдать | CVE-2023-37259Эксплойта нет | Cross site scripting in Export Chat featurematrix-react-sdk project · matrix-react-sdk · CWE-79 | Средняя5,4 | — | 0,5 % | 18 июл. 2023 г. |
18Наблюдать | CVE-2023-30609Эксплойта нет | matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlightingmatrix-react-sdk project · matrix-react-sdk · CWE-74 | Средняя4,7 | — | 0,6 % | 25 апр. 2023 г. |
17Наблюдать | CVE-2021-21320Эксплойта нет | User content sandbox can be confused into opening arbitrary documentsmatrix-react-sdk project · matrix-react-sdk · CWE-345 | Средняя4,3 | — | 0,9 % | 1 мар. 2021 г. |
- CVE-2024-4782434Наблюдать
Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %matrix-org · matrix-react-sdk15 окт. 2024 г.
- CVE-2023-2810332Наблюдать
Prototype pollution in matrix-react-sdk
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %matrix-react-sdk project · matrix-react-sdk28 мар. 2023 г.
- CVE-2021-3262231Наблюдать
File upload local preview can run embedded scripts after user interaction
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %matrix-react-sdk project · matrix-react-sdk17 мая 2021 г.
- CVE-2023-3725921Наблюдать
Cross site scripting in Export Chat feature
СредняяCVSS 5,4Эксплойта нетEPSS 0 %matrix-react-sdk project · matrix-react-sdk18 июл. 2023 г.
- CVE-2023-3060918Наблюдать
matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlighting
СредняяCVSS 4,7Эксплойта нетEPSS 1 %matrix-react-sdk project · matrix-react-sdk25 апр. 2023 г.
- CVE-2021-2132017Наблюдать
User content sandbox can be confused into opening arbitrary documents
СредняяCVSS 4,3Эксплойта нетEPSS 1 %matrix-react-sdk project · matrix-react-sdk1 мар. 2021 г.