Ankitects records
6 published records for vendor ankitects.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 16.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-184 Incomplete List of Disallowed Inputs1
- CWE-23 Relative Path Traversal1
- CWE-427 Uncontrolled Search Path Element1
- CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-830 Inclusion of Web Functionality from an Untrusted Source1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-32484No exploit | An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.ankitects · anki · CWE-80 | High8.2 | — | 22.3% | Jul 22, 2024 |
31Monitor | CVE-2025-62185No exploit | In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed ankitects · anki · CWE-427 | High7.8 | — | 0.2% | Oct 7, 2025 |
31Monitor | CVE-2025-62186No exploit | Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL schemeankitects · anki · CWE-829 | High7.8 | — | 0.1% | Oct 7, 2025 |
21Monitor | CVE-2024-32152No exploit | A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04.ankitects · anki · CWE-184 | Medium4.3 | — | 12.7% | Jul 22, 2024 |
21Monitor | CVE-2025-43703No exploit | An issue was discovered in Ankitects Anki through 25.02.ankitects · anki · CWE-830 | Medium5.4 | — | 0.2% | Apr 16, 2025 |
13Monitor | CVE-2025-62187No exploit | In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux ankitects · anki · CWE-23 | Low3.3 | — | 0.2% | Oct 7, 2025 |
- CVE-2024-3248439Monitor
An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04.
HighCVSS 8.2No exploitEPSS 22%ankitects · ankiJul 22, 2024
- CVE-2025-6218531Monitor
In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed
HighCVSS 7.8No exploitEPSS 0%ankitects · ankiOct 7, 2025
- CVE-2025-6218631Monitor
Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme
HighCVSS 7.8No exploitEPSS 0%ankitects · ankiOct 7, 2025
- CVE-2024-3215221Monitor
A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04.
MediumCVSS 4.3No exploitEPSS 13%ankitects · ankiJul 22, 2024
- CVE-2025-4370321Monitor
An issue was discovered in Ankitects Anki through 25.02.
MediumCVSS 5.4No exploitEPSS 0%ankitects · ankiApr 16, 2025
- CVE-2025-6218713Monitor
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux
LowCVSS 3.3No exploitEPSS 0%ankitects · ankiOct 7, 2025