Leanote kayıtları
leanote üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-26158İstismar yok | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered.leanote · leanote · CWE-79 | Kritik9,6 | — | %1,9 | 30 Eyl 2020 |
39İzleyin | CVE-2020-26157İstismar yok | Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing.leanote · leanote · CWE-79 | Kritik9,6 | — | %1,9 | 30 Eyl 2020 |
24İzleyin | CVE-2021-43721İstismar yok | Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note.leanote · leanote · CWE-79 | Orta6,1 | — | %1,1 | 28 Mar 2022 |
24İzleyin | CVE-2017-1000492İstismar yok | Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integrationleanote · desktop · CWE-79 | Orta6,1 | — | %1,0 | 2 Oca 2018 |
24İzleyin | CVE-2018-18553İstismar yok | Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.leanote · leanote · CWE-79 | Orta6,1 | — | %0,9 | 21 Eki 2018 |
24İzleyin | CVE-2017-1000459İstismar yok | Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notesleanote · leanote · CWE-79 | Orta6,1 | — | %0,8 | 2 Oca 2018 |
24İzleyin | CVE-2019-1010003İstismar yok | Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).leanote · leanote · CWE-79 | Orta6,1 | — | %0,6 | 11 Tem 2019 |
24İzleyin | CVE-2021-4263İstismar yok | leanote history.js define cross site scriptingleanote · leanote · CWE-79 | Orta6,1 | — | %0,5 | 21 Ara 2022 |
20İzleyin | CVE-2024-0849İstismar yok | Leanote 2.7.0 - Local File Readleanote · desktop · CWE-22 | Orta5,0 | — | %0,2 | 6 Şub 2024 |
- CVE-2020-2615839İzleyin
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered.
KritikCVSS 9,6İstismar yokEPSS %2leanote · leanote30 Eyl 2020
- CVE-2020-2615739İzleyin
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing.
KritikCVSS 9,6İstismar yokEPSS %2leanote · leanote30 Eyl 2020
- CVE-2021-4372124İzleyin
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note.
OrtaCVSS 6,1İstismar yokEPSS %1leanote · leanote28 Mar 2022
- CVE-2017-100049224İzleyin
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
OrtaCVSS 6,1İstismar yokEPSS %1leanote · desktop2 Oca 2018
- CVE-2018-1855324İzleyin
Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.
OrtaCVSS 6,1İstismar yokEPSS %1leanote · leanote21 Eki 2018
- CVE-2017-100045924İzleyin
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
OrtaCVSS 6,1İstismar yokEPSS %1leanote · leanote2 Oca 2018
- CVE-2019-101000324İzleyin
Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %1leanote · leanote11 Tem 2019
- CVE-2021-426324İzleyin
leanote history.js define cross site scripting
OrtaCVSS 6,1İstismar yokEPSS %1leanote · leanote21 Ara 2022
- CVE-2024-084920İzleyin
Leanote 2.7.0 - Local File Read
OrtaCVSS 5,0İstismar yokEPSS %0leanote · desktop6 Şub 2024