marked project kayıtları
marked project üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-1333 Inefficient Regular Expression Complexity2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2026-41680İstismar yok | Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizermarked project · marked · CWE-400 | Yüksek8,7 | — | %0,5 | 24 Nis 2026 |
31İzleyin | CVE-2015-8854İstismar yok | The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trimarked project · marked · CWE-1333 | Yüksek7,5 | — | %4,3 | 23 Oca 2017 |
31İzleyin | CVE-2022-21680İstismar yok | Cubic catastrophic backtracking (ReDoS) in markedmarked project · marked · CWE-400 | Yüksek7,5 | — | %2,9 | 14 Oca 2022 |
31İzleyin | CVE-2022-21681İstismar yok | Exponential catastrophic backtracking (ReDoS) in markedmarked project · marked · CWE-400 | Yüksek7,5 | — | %2,8 | 14 Oca 2022 |
31İzleyin | CVE-2021-21306İstismar yok | Denial of Service in Markedmarked project · marked · CWE-400 | Yüksek7,5 | — | %2,5 | 8 Şub 2021 |
31İzleyin | CVE-2017-16114İstismar yok | The marked module is vulnerable to a regular expression denial of service.marked project · marked · CWE-400 | Yüksek7,5 | — | %1,8 | 6 Haz 2018 |
27İzleyin | CVE-2018-25110İstismar yok | Regular Expression Denial of Service (ReDoS) in markedjs/markedmarked project · marked · CWE-1333 | Orta6,9 | — | %0,6 | 23 May 2025 |
25İzleyin | CVE-2014-3743İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrarymarked project · marked · CWE-79 | Orta6,1 | — | %1,7 | 6 Oca 2020 |
24İzleyin | CVE-2017-1000427İstismar yok | marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.marked project · marked · CWE-79 | Orta6,1 | — | %1,5 | 2 Oca 2018 |
24İzleyin | CVE-2016-10531İstismar yok | marked is an application that is meant to parse and compile markdown.marked project · marked · CWE-79 | Orta6,1 | — | %1,5 | 31 May 2018 |
18İzleyin | CVE-2015-1370İstismar yok | Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attmarked project · marked | Orta4,3 | — | %2,1 | 27 Oca 2015 |
- CVE-2026-4168034İzleyin
Marked: OOM Denial of Service via Infinite Recursion in marked Tokenizer
YüksekCVSS 8,7İstismar yokEPSS %1marked project · marked24 Nis 2026
- CVE-2015-885431İzleyin
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that tri
YüksekCVSS 7,5İstismar yokEPSS %4marked project · marked23 Oca 2017
- CVE-2022-2168031İzleyin
Cubic catastrophic backtracking (ReDoS) in marked
YüksekCVSS 7,5İstismar yokEPSS %3marked project · marked14 Oca 2022
- CVE-2022-2168131İzleyin
Exponential catastrophic backtracking (ReDoS) in marked
YüksekCVSS 7,5İstismar yokEPSS %3marked project · marked14 Oca 2022
- CVE-2021-2130631İzleyin
Denial of Service in Marked
YüksekCVSS 7,5İstismar yokEPSS %2marked project · marked8 Şub 2021
- CVE-2017-1611431İzleyin
The marked module is vulnerable to a regular expression denial of service.
YüksekCVSS 7,5İstismar yokEPSS %2marked project · marked6 Haz 2018
- CVE-2018-2511027İzleyin
Regular Expression Denial of Service (ReDoS) in markedjs/marked
OrtaCVSS 6,9İstismar yokEPSS %1marked project · marked23 May 2025
- CVE-2014-374325İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary
OrtaCVSS 6,1İstismar yokEPSS %2marked project · marked6 Oca 2020
- CVE-2017-100042724İzleyin
marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.
OrtaCVSS 6,1İstismar yokEPSS %2marked project · marked2 Oca 2018
- CVE-2016-1053124İzleyin
marked is an application that is meant to parse and compile markdown.
OrtaCVSS 6,1İstismar yokEPSS %1marked project · marked31 May 2018
- CVE-2015-137018İzleyin
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) att
OrtaCVSS 4,3İstismar yokEPSS %2marked project · marked27 Oca 2015