Skip to content
Noroxi

notable records

3 published records for vendor notable.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20
  2. 22

Bar: total · dark part: CISA KEV.

All records

3 records
  • Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected into the Title text

    CriticalCVSS 9.8No exploitEPSS 2%

    notable · notableMar 26, 2022

  • Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true)

    CriticalCVSS 9.6No exploitEPSS 5%

    notable · notableDec 10, 2020

  • Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link.

    HighCVSS 8.8No exploitEPSS 2%

    notable · notableApr 15, 2022