Перейти к содержимому
Noroxi

Записи Typora

23 опубликованных записей вендора typora.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
11
С записью об исправлении
4,3 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 19
  2. 20
  3. 21
  4. 22
  5. 23
  6. 24

Столбик: всего · тёмная часть: CISA KEV.

Все записи

23 записей
  • CVE-2023-2317
    39Наблюдать

    Typora DOM-Based Cross-site Scripting leading to Remote Code Execution

    КритическаяCVSS 9,6Эксплойта нетEPSS 2 %

    typora · typora19 авг. 2023 г.

  • CVE-2019-20374
    39Наблюдать

    A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution

    КритическаяCVSS 9,6Эксплойта нетEPSS 2 %

    typora · typora9 янв. 2020 г.

  • CVE-2019-12137
    33Наблюдать

    Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note

    ВысокаяCVSS 7,8Proof of conceptEPSS 6 %

    typora · typora16 мая 2019 г.

  • CVE-2019-12172
    32Наблюдать

    Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demons

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    typora · typora17 мая 2019 г.

  • CVE-2023-1003
    31Наблюдать

    Typora WSH JScript code injection

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    typora · typora7 мар. 2023 г.

  • CVE-2023-2316
    29Наблюдать

    Typora Local File Disclosure

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    typora · typora19 авг. 2023 г.

  • CVE-2020-18336
    29Наблюдать

    Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    typora · typora9 окт. 2023 г.

  • CVE-2024-33300
    29Наблюдать

    Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute

    ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %

    typora · typora1 мая 2024 г.

  • CVE-2023-2971
    26Наблюдать

    Typora Local File Disclosure

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    typora · typora19 авг. 2023 г.

  • CVE-2019-6803
    25Наблюдать

    typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    typora · typora25 янв. 2019 г.

  • CVE-2019-7296
    25Наблюдать

    typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    typora · typora31 янв. 2019 г.

  • CVE-2019-7295
    25Наблюдать

    typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.

    СредняяCVSS 6,1Эксплойта нетEPSS 2 %

    typora · typora31 янв. 2019 г.

  • CVE-2020-18737
    24Наблюдать

    An issue was discovered in Typora 0.9.67.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    typora · typora5 февр. 2021 г.

  • CVE-2020-18221
    24Наблюдать

    Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during bloc

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    typora · typora26 мая 2021 г.

  • CVE-2020-18748
    24Наблюдать

    Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration er

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    typora · typora19 авг. 2021 г.

  • CVE-2020-21058
    24Наблюдать

    Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    typora · typora20 июн. 2023 г.

  • CVE-2023-39703
    24Наблюдать

    A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    typora · typora1 сент. 2023 г.

  • CVE-2022-40011
    24Наблюдать

    Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then us

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    typora · typora23 дек. 2022 г.

  • CVE-2024-41481
    24Наблюдать

    Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    typora · typora12 авг. 2024 г.

  • CVE-2024-31783
    24Наблюдать

    Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    typora · typora16 апр. 2024 г.

  • CVE-2022-43668
    24Наблюдать

    Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    typora · typora7 дек. 2022 г.

  • CVE-2024-41482
    24Наблюдать

    Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    typora · typora12 авг. 2024 г.

  • CVE-2024-31784
    24Наблюдать

    An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted pay

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    typora · typora16 апр. 2024 г.