matrix-react-sdk project kayıtları
matrix-react-sdk project üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2024-47824İstismar yok | Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a roommatrix-org · matrix-react-sdk · CWE-200 | Yüksek8,7 | — | %0,7 | 15 Eki 2024 |
32İzleyin | CVE-2023-28103İstismar yok | Prototype pollution in matrix-react-sdkmatrix-react-sdk project · matrix-react-sdk · CWE-1321 | Yüksek8,2 | — | %0,7 | 28 Mar 2023 |
31İzleyin | CVE-2021-32622İstismar yok | File upload local preview can run embedded scripts after user interactionmatrix-react-sdk project · matrix-react-sdk · CWE-74 | Yüksek7,8 | — | %0,4 | 17 May 2021 |
21İzleyin | CVE-2023-37259İstismar yok | Cross site scripting in Export Chat featurematrix-react-sdk project · matrix-react-sdk · CWE-79 | Orta5,4 | — | %0,5 | 18 Tem 2023 |
18İzleyin | CVE-2023-30609İstismar yok | matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlightingmatrix-react-sdk project · matrix-react-sdk · CWE-74 | Orta4,7 | — | %0,6 | 25 Nis 2023 |
17İzleyin | CVE-2021-21320İstismar yok | User content sandbox can be confused into opening arbitrary documentsmatrix-react-sdk project · matrix-react-sdk · CWE-345 | Orta4,3 | — | %0,9 | 1 Mar 2021 |
- CVE-2024-4782434İzleyin
Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room
YüksekCVSS 8,7İstismar yokEPSS %1matrix-org · matrix-react-sdk15 Eki 2024
- CVE-2023-2810332İzleyin
Prototype pollution in matrix-react-sdk
YüksekCVSS 8,2İstismar yokEPSS %1matrix-react-sdk project · matrix-react-sdk28 Mar 2023
- CVE-2021-3262231İzleyin
File upload local preview can run embedded scripts after user interaction
YüksekCVSS 7,8İstismar yokEPSS %0matrix-react-sdk project · matrix-react-sdk17 May 2021
- CVE-2023-3725921İzleyin
Cross site scripting in Export Chat feature
OrtaCVSS 5,4İstismar yokEPSS %0matrix-react-sdk project · matrix-react-sdk18 Tem 2023
- CVE-2023-3060918İzleyin
matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlighting
OrtaCVSS 4,7İstismar yokEPSS %1matrix-react-sdk project · matrix-react-sdk25 Nis 2023
- CVE-2021-2132017İzleyin
User content sandbox can be confused into opening arbitrary documents
OrtaCVSS 4,3İstismar yokEPSS %1matrix-react-sdk project · matrix-react-sdk1 Mar 2021