Записи Typora
23 опубликованных записей вендора typora.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 4,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-290 Authentication Bypass by Spoofing1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-2317Эксплойта нет | Typora DOM-Based Cross-site Scripting leading to Remote Code Executiontypora · typora · CWE-79 | Критическая9,6 | — | 2,4 % | 19 авг. 2023 г. |
39Наблюдать | CVE-2019-20374Эксплойта нет | A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Executiontypora · typora · CWE-79 | Критическая9,6 | — | 2,3 % | 9 янв. 2020 г. |
33Наблюдать | CVE-2019-12137Proof of concept | Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared notetypora · typora · CWE-22 | Высокая7,8 | — | 6,5 % | 16 мая 2019 г. |
32Наблюдать | CVE-2019-12172Эксплойта нет | Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstypora · typora · CWE-22 | Высокая7,8 | — | 1,8 % | 17 мая 2019 г. |
31Наблюдать | CVE-2023-1003Эксплойта нет | Typora WSH JScript code injectiontypora · typora · CWE-94 | Высокая7,8 | — | 0,4 % | 7 мар. 2023 г. |
29Наблюдать | CVE-2023-2316Эксплойта нет | Typora Local File Disclosuretypora · typora · CWE-22 | Высокая7,4 | — | 0,7 % | 19 авг. 2023 г. |
29Наблюдать | CVE-2020-18336Эксплойта нет | Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file typora · typora · CWE-79 | Высокая7,4 | — | 0,6 % | 9 окт. 2023 г. |
29Наблюдать | CVE-2024-33300Эксплойта нет | Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to executetypora · typora · CWE-79 | Высокая7,3 | — | 0,6 % | 1 мая 2024 г. |
26Наблюдать | CVE-2023-2971Эксплойта нет | Typora Local File Disclosuretypora · typora · CWE-22 | Средняя6,5 | — | 0,5 % | 19 авг. 2023 г. |
25Наблюдать | CVE-2019-6803Эксплойта нет | typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.typora · typora · CWE-79 | Средняя6,1 | — | 1,9 % | 25 янв. 2019 г. |
25Наблюдать | CVE-2019-7296Эксплойта нет | typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.typora · typora · CWE-79 | Средняя6,1 | — | 1,7 % | 31 янв. 2019 г. |
25Наблюдать | CVE-2019-7295Эксплойта нет | typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.typora · typora · CWE-79 | Средняя6,1 | — | 1,7 % | 31 янв. 2019 г. |
24Наблюдать | CVE-2020-18737Эксплойта нет | An issue was discovered in Typora 0.9.67.typora · typora · CWE-79 | Средняя6,1 | — | 1,3 % | 5 февр. 2021 г. |
24Наблюдать | CVE-2020-18221Эксплойта нет | Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during bloctypora · typora · CWE-79 | Средняя6,1 | — | 1,2 % | 26 мая 2021 г. |
24Наблюдать | CVE-2020-18748Эксплойта нет | Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration ertypora · typora · CWE-79 | Средняя6,1 | — | 0,9 % | 19 авг. 2021 г. |
24Наблюдать | CVE-2020-21058Эксплойта нет | Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.typora · typora · CWE-79 | Средняя6,1 | — | 0,6 % | 20 июн. 2023 г. |
24Наблюдать | CVE-2023-39703Эксплойта нет | A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via typora · typora · CWE-79 | Средняя6,1 | — | 0,5 % | 1 сент. 2023 г. |
24Наблюдать | CVE-2022-40011Эксплойта нет | Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then ustypora · typora · CWE-79 | Средняя6,1 | — | 0,4 % | 23 дек. 2022 г. |
24Наблюдать | CVE-2024-41481Эксплойта нет | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.typora · typora · CWE-79 | Средняя6,1 | — | 0,4 % | 12 авг. 2024 г. |
24Наблюдать | CVE-2024-31783Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a craftedtypora · typora · CWE-79 | Средняя6,1 | — | 0,4 % | 16 апр. 2024 г. |
24Наблюдать | CVE-2022-43668Эксплойта нет | Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the typora · typora · CWE-79 | Средняя6,1 | — | 0,4 % | 7 дек. 2022 г. |
24Наблюдать | CVE-2024-41482Эксплойта нет | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.typora · typora · CWE-79 | Средняя6,1 | — | 0,3 % | 12 авг. 2024 г. |
24Наблюдать | CVE-2024-31784Эксплойта нет | An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted paytypora · typora · CWE-290 | Средняя6,1 | — | 0,3 % | 16 апр. 2024 г. |
- CVE-2023-231739Наблюдать
Typora DOM-Based Cross-site Scripting leading to Remote Code Execution
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %typora · typora19 авг. 2023 г.
- CVE-2019-2037439Наблюдать
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %typora · typora9 янв. 2020 г.
- CVE-2019-1213733Наблюдать
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note
ВысокаяCVSS 7,8Proof of conceptEPSS 6 %typora · typora16 мая 2019 г.
- CVE-2019-1217232Наблюдать
Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demons
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %typora · typora17 мая 2019 г.
- CVE-2023-100331Наблюдать
Typora WSH JScript code injection
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %typora · typora7 мар. 2023 г.
- CVE-2023-231629Наблюдать
Typora Local File Disclosure
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %typora · typora19 авг. 2023 г.
- CVE-2020-1833629Наблюдать
Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %typora · typora9 окт. 2023 г.
- CVE-2024-3330029Наблюдать
Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %typora · typora1 мая 2024 г.
- CVE-2023-297126Наблюдать
Typora Local File Disclosure
СредняяCVSS 6,5Эксплойта нетEPSS 0 %typora · typora19 авг. 2023 г.
- CVE-2019-680325Наблюдать
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
СредняяCVSS 6,1Эксплойта нетEPSS 2 %typora · typora25 янв. 2019 г.
- CVE-2019-729625Наблюдать
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
СредняяCVSS 6,1Эксплойта нетEPSS 2 %typora · typora31 янв. 2019 г.
- CVE-2019-729525Наблюдать
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
СредняяCVSS 6,1Эксплойта нетEPSS 2 %typora · typora31 янв. 2019 г.
- CVE-2020-1873724Наблюдать
An issue was discovered in Typora 0.9.67.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %typora · typora5 февр. 2021 г.
- CVE-2020-1822124Наблюдать
Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during bloc
СредняяCVSS 6,1Эксплойта нетEPSS 1 %typora · typora26 мая 2021 г.
- CVE-2020-1874824Наблюдать
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration er
СредняяCVSS 6,1Эксплойта нетEPSS 1 %typora · typora19 авг. 2021 г.
- CVE-2020-2105824Наблюдать
Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %typora · typora20 июн. 2023 г.
- CVE-2023-3970324Наблюдать
A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via
СредняяCVSS 6,1Эксплойта нетEPSS 0 %typora · typora1 сент. 2023 г.
- CVE-2022-4001124Наблюдать
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then us
СредняяCVSS 6,1Эксплойта нетEPSS 0 %typora · typora23 дек. 2022 г.
- CVE-2024-4148124Наблюдать
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %typora · typora12 авг. 2024 г.
- CVE-2024-3178324Наблюдать
Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted
СредняяCVSS 6,1Эксплойта нетEPSS 0 %typora · typora16 апр. 2024 г.
- CVE-2022-4366824Наблюдать
Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the
СредняяCVSS 6,1Эксплойта нетEPSS 0 %typora · typora7 дек. 2022 г.
- CVE-2024-4148224Наблюдать
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %typora · typora12 авг. 2024 г.
- CVE-2024-3178424Наблюдать
An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted pay
СредняяCVSS 6,1Эксплойта нетEPSS 0 %typora · typora16 апр. 2024 г.