MarkText kayıtları
marktext üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2021-29996İstismar yok | Mark Text through 0.16.3 allows attackers arbitrary command execution.marktext · marktext · CWE-79 | Kritik9,6 | — | %2,8 | 5 Nis 2021 |
39İzleyin | CVE-2022-25069İstismar yok | Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote comarktext · marktext · CWE-79 | Kritik9,6 | — | %2,0 | 4 Mar 2022 |
39İzleyin | CVE-2020-27176İstismar yok | Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution.marktext · marktext · CWE-79 | Kritik9,6 | — | %1,9 | 16 Eki 2020 |
38İzleyin | CVE-2023-2318İstismar yok | MarkText DOM-Based Cross-site Scripting leading to Remote Code Executionmarktext · marktext · CWE-79 | Kritik9,6 | — | %0,5 | 19 Ağu 2023 |
37İzleyin | CVE-2022-24123İstismar yok | MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering.marktext · marktext · CWE-79 | Kritik9,0 | — | %1,9 | 29 Oca 2022 |
31İzleyin | CVE-2023-1004İstismar yok | MarkText WSH JScript code injectionmarktext · marktext · CWE-94 | Yüksek7,8 | — | %0,4 | 24 Şub 2023 |
21İzleyin | CVE-2022-21158İstismar yok | A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: schmarktext · marktext · CWE-79 | Orta5,4 | — | %0,5 | 10 Mar 2022 |
- CVE-2021-2999639İzleyin
Mark Text through 0.16.3 allows attackers arbitrary command execution.
KritikCVSS 9,6İstismar yokEPSS %3marktext · marktext5 Nis 2021
- CVE-2022-2506939İzleyin
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote co
KritikCVSS 9,6İstismar yokEPSS %2marktext · marktext4 Mar 2022
- CVE-2020-2717639İzleyin
Mutation XSS exists in Mark Text through 0.16.2 that leads to Remote Code Execution.
KritikCVSS 9,6İstismar yokEPSS %2marktext · marktext16 Eki 2020
- CVE-2023-231838İzleyin
MarkText DOM-Based Cross-site Scripting leading to Remote Code Execution
KritikCVSS 9,6İstismar yokEPSS %1marktext · marktext19 Ağu 2023
- CVE-2022-2412337İzleyin
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering.
KritikCVSS 9,0İstismar yokEPSS %2marktext · marktext29 Oca 2022
- CVE-2023-100431İzleyin
MarkText WSH JScript code injection
YüksekCVSS 7,8İstismar yokEPSS %0marktext · marktext24 Şub 2023
- CVE-2022-2115821İzleyin
A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: sch
OrtaCVSS 5,4İstismar yokEPSS %1marktext · marktext10 Mar 2022