Skip to content
Noroxi

jquery records

11 published records for vendor jquery.

Researcher profile

Entered KEV
1 · 9.1%
Weaponized
1 · 9.1%
Pre-auth RCE
0
With a fix record
72.7%
Median publish → KEV
1730 days

All records

11 records
  • CVE-2020-11023
    79This week

    Potential XSS vulnerability in jQuery

    MediumCVSS 6.1KEVWeaponizedEPSS 85%

    jquery · jqueryApr 29, 2020

  • jQuery has a potential XSS vulnerability

    MediumCVSS 6.1Proof of conceptEPSS 99%

    jquery · jqueryApr 29, 2020

  • jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp

    MediumCVSS 6.1Proof of conceptEPSS 87%

    jquery · jqueryApr 19, 2019

  • CVE-2015-9251
    33Monitor

    jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType o

    MediumCVSS 6.1Proof of conceptEPSS 30%

    jquery · jqueryJan 18, 2018

  • jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names.

    HighCVSS 7.5No exploitEPSS 3%

    jquery · jqueryJan 18, 2018

  • CVE-2012-6708
    27Monitor

    jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks.

    MediumCVSS 6.1Proof of conceptEPSS 9%

    jquery · jqueryJan 18, 2018

  • CVE-2020-7656
    26Monitor

    jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.

    MediumCVSS 6.1Proof of conceptEPSS 6%

    jquery · jqueryMay 19, 2020

  • CVE-2014-6071
    25Monitor

    jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside afte

    MediumCVSS 6.1No exploitEPSS 2%

    jquery · jqueryJan 16, 2018

  • jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.

    MediumCVSS 6.1No exploitEPSS 2%

    jquery · jqueryApr 22, 2020

  • CVE-2011-4969
    23Monitor

    Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj

    MediumCVSS 4.3No exploitEPSS 19%

    jquery · jqueryMar 8, 2013

  • CVE-2007-2379
    21Monitor

    The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote att

    MediumCVSS 5.0No exploitEPSS 3%

    jquery · jqueryApr 30, 2007