Записи jquery
11 опубликованных записей вендора jquery.
Профиль для исследователя
- Попали в KEV
- 1 · 9,1 %
- С эксплойтом
- 1 · 9,1 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 72,7 %
- Медиана: публикация → KEV
- 1730 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-674 Uncontrolled Recursion1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
79На этой неделе | CVE-2020-11023Готовый эксплойт | Potential XSS vulnerability in jQueryjquery · jquery · CWE-79 | Средняя6,1 | KEV | 84,9 % | 29 апр. 2020 г. |
54В плане | CVE-2020-11022Proof of concept | jQuery has a potential XSS vulnerabilityjquery · jquery · CWE-79 | Средняя6,1 | — | 99,2 % | 29 апр. 2020 г. |
50В плане | CVE-2019-11358Proof of concept | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototypjquery · jquery · CWE-1321 | Средняя6,1 | — | 87,2 % | 19 апр. 2019 г. |
33Наблюдать | CVE-2015-9251Proof of concept | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType ojquery · jquery · CWE-79 | Средняя6,1 | — | 29,7 % | 18 янв. 2018 г. |
31Наблюдать | CVE-2016-10707Эксплойта нет | jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names.jquery · jquery · CWE-674 | Высокая7,5 | — | 2,9 % | 18 янв. 2018 г. |
27Наблюдать | CVE-2012-6708Proof of concept | jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks.jquery · jquery · CWE-79 | Средняя6,1 | — | 8,6 % | 18 янв. 2018 г. |
26Наблюдать | CVE-2020-7656Proof of concept | jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.jquery · jquery · CWE-79 | Средняя6,1 | — | 6,3 % | 19 мая 2020 г. |
25Наблюдать | CVE-2014-6071Эксплойта нет | jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside aftejquery · jquery · CWE-79 | Средняя6,1 | — | 2,3 % | 16 янв. 2018 г. |
24Наблюдать | CVE-2018-18405Эксплойта нет | jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.jquery · jquery · CWE-79 | Средняя6,1 | — | 1,7 % | 22 апр. 2020 г. |
23Наблюдать | CVE-2011-4969Эксплойта нет | Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to injjquery · jquery · CWE-79 | Средняя4,3 | — | 19,2 % | 8 мар. 2013 г. |
21Наблюдать | CVE-2007-2379Эксплойта нет | The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attjquery · jquery · CWE-200 | Средняя5,0 | — | 2,8 % | 30 апр. 2007 г. |
- CVE-2020-1102379На этой неделе
Potential XSS vulnerability in jQuery
СредняяCVSS 6,1KEVГотовый эксплойтEPSS 85 %jquery · jquery29 апр. 2020 г.
- CVE-2020-1102254В плане
jQuery has a potential XSS vulnerability
СредняяCVSS 6,1Proof of conceptEPSS 99 %jquery · jquery29 апр. 2020 г.
- CVE-2019-1135850В плане
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototyp
СредняяCVSS 6,1Proof of conceptEPSS 87 %jquery · jquery19 апр. 2019 г.
- CVE-2015-925133Наблюдать
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType o
СредняяCVSS 6,1Proof of conceptEPSS 30 %jquery · jquery18 янв. 2018 г.
- CVE-2016-1070731Наблюдать
jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %jquery · jquery18 янв. 2018 г.
- CVE-2012-670827Наблюдать
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks.
СредняяCVSS 6,1Proof of conceptEPSS 9 %jquery · jquery18 янв. 2018 г.
- CVE-2020-765626Наблюдать
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method.
СредняяCVSS 6,1Proof of conceptEPSS 6 %jquery · jquery19 мая 2020 г.
- CVE-2014-607125Наблюдать
jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside afte
СредняяCVSS 6,1Эксплойта нетEPSS 2 %jquery · jquery16 янв. 2018 г.
- CVE-2018-1840524Наблюдать
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element.
СредняяCVSS 6,1Эксплойта нетEPSS 2 %jquery · jquery22 апр. 2020 г.
- CVE-2011-496923Наблюдать
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inj
СредняяCVSS 4,3Эксплойта нетEPSS 19 %jquery · jquery8 мар. 2013 г.
- CVE-2007-237921Наблюдать
The jQuery framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote att
СредняяCVSS 5,0Эксплойта нетEPSS 3 %jquery · jquery30 апр. 2007 г.