Записи Leanote
9 опубликованных записей вендора leanote.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-26158Эксплойта нет | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered.leanote · leanote · CWE-79 | Критическая9,6 | — | 1,9 % | 30 сент. 2020 г. |
39Наблюдать | CVE-2020-26157Эксплойта нет | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing.leanote · leanote · CWE-79 | Критическая9,6 | — | 1,9 % | 30 сент. 2020 г. |
24Наблюдать | CVE-2021-43721Эксплойта нет | Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note.leanote · leanote · CWE-79 | Средняя6,1 | — | 1,1 % | 28 мар. 2022 г. |
24Наблюдать | CVE-2017-1000492Эксплойта нет | Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integrationleanote · desktop · CWE-79 | Средняя6,1 | — | 1,0 % | 2 янв. 2018 г. |
24Наблюдать | CVE-2018-18553Эксплойта нет | Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.leanote · leanote · CWE-79 | Средняя6,1 | — | 0,9 % | 21 окт. 2018 г. |
24Наблюдать | CVE-2017-1000459Эксплойта нет | Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notesleanote · leanote · CWE-79 | Средняя6,1 | — | 0,8 % | 2 янв. 2018 г. |
24Наблюдать | CVE-2019-1010003Эксплойта нет | Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).leanote · leanote · CWE-79 | Средняя6,1 | — | 0,6 % | 11 июл. 2019 г. |
24Наблюдать | CVE-2021-4263Эксплойта нет | leanote history.js define cross site scriptingleanote · leanote · CWE-79 | Средняя6,1 | — | 0,5 % | 21 дек. 2022 г. |
20Наблюдать | CVE-2024-0849Эксплойта нет | Leanote 2.7.0 - Local File Readleanote · desktop · CWE-22 | Средняя5,0 | — | 0,2 % | 6 февр. 2024 г. |
- CVE-2020-2615839Наблюдать
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered.
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %leanote · leanote30 сент. 2020 г.
- CVE-2020-2615739Наблюдать
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing.
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %leanote · leanote30 сент. 2020 г.
- CVE-2021-4372124Наблюдать
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %leanote · leanote28 мар. 2022 г.
- CVE-2017-100049224Наблюдать
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
СредняяCVSS 6,1Эксплойта нетEPSS 1 %leanote · desktop2 янв. 2018 г.
- CVE-2018-1855324Наблюдать
Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %leanote · leanote21 окт. 2018 г.
- CVE-2017-100045924Наблюдать
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
СредняяCVSS 6,1Эксплойта нетEPSS 1 %leanote · leanote2 янв. 2018 г.
- CVE-2019-101000324Наблюдать
Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).
СредняяCVSS 6,1Эксплойта нетEPSS 1 %leanote · leanote11 июл. 2019 г.
- CVE-2021-426324Наблюдать
leanote history.js define cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %leanote · leanote21 дек. 2022 г.
- CVE-2024-084920Наблюдать
Leanote 2.7.0 - Local File Read
СредняяCVSS 5,0Эксплойта нетEPSS 0 %leanote · desktop6 февр. 2024 г.