Записи MarkText
7 опубликованных записей вендора marktext.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2021-29996Эксплойта нет | Mark Text through 0.16.3 allows attackers arbitrary command execution.marktext · marktext · CWE-79 | Критическая9,6 | — | 2,8 % | 5 апр. 2021 г. |
39Наблюдать | CVE-2022-25069Эксплойта нет | Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote comarktext · marktext · CWE-79 | Критическая9,6 | — | 2,0 % | 4 мар. 2022 г. |
39Наблюдать | CVE-2020-27176Эксплойта нет | Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution.marktext · marktext · CWE-79 | Критическая9,6 | — | 1,9 % | 16 окт. 2020 г. |
38Наблюдать | CVE-2023-2318Эксплойта нет | MarkText DOM-Based Cross-site Scripting leading to Remote Code Executionmarktext · marktext · CWE-79 | Критическая9,6 | — | 0,5 % | 19 авг. 2023 г. |
37Наблюдать | CVE-2022-24123Эксплойта нет | MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering.marktext · marktext · CWE-79 | Критическая9,0 | — | 1,9 % | 29 янв. 2022 г. |
31Наблюдать | CVE-2023-1004Эксплойта нет | MarkText WSH JScript code injectionmarktext · marktext · CWE-94 | Высокая7,8 | — | 0,4 % | 24 февр. 2023 г. |
21Наблюдать | CVE-2022-21158Эксплойта нет | A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: schmarktext · marktext · CWE-79 | Средняя5,4 | — | 0,5 % | 10 мар. 2022 г. |
- CVE-2021-2999639Наблюдать
Mark Text through 0.16.3 allows attackers arbitrary command execution.
КритическаяCVSS 9,6Эксплойта нетEPSS 3 %marktext · marktext5 апр. 2021 г.
- CVE-2022-2506939Наблюдать
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote co
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %marktext · marktext4 мар. 2022 г.
- CVE-2020-2717639Наблюдать
Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution.
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %marktext · marktext16 окт. 2020 г.
- CVE-2023-231838Наблюдать
MarkText DOM-Based Cross-site Scripting leading to Remote Code Execution
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %marktext · marktext19 авг. 2023 г.
- CVE-2022-2412337Наблюдать
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering.
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %marktext · marktext29 янв. 2022 г.
- CVE-2023-100431Наблюдать
MarkText WSH JScript code injection
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %marktext · marktext24 февр. 2023 г.
- CVE-2022-2115821Наблюдать
A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: sch
СредняяCVSS 5,4Эксплойта нетEPSS 1 %marktext · marktext10 мар. 2022 г.