parall kayıtları
parall üreticisine ait 15 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-116 Improper Encoding or Escaping of Output3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-400 Uncontrolled Resource Consumption2
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-35 Path Traversal: '.../...//'1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
15 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2025-68428Kavram kanıtı | jsPDF has Local File Inclusion/Path Traversal vulnerabilityparall · jspdf · CWE-35 | Kritik9,2 | — | %2,2 | 5 Oca 2026 |
35İzleyin | CVE-2026-25755Kavram kanıtı | jsPDF has PDF Object Injection via Unsanitized Input in addJS Methodparall · jspdf · CWE-94 | Yüksek8,8 | — | %0,8 | 19 Şub 2026 |
34İzleyin | CVE-2026-25535İstismar yok | jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensionsparall · jspdf · CWE-400 | Yüksek8,7 | — | %0,9 | 19 Şub 2026 |
34İzleyin | CVE-2025-57810İstismar yok | jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)parall · jspdf · CWE-20 | Yüksek8,7 | — | %0,7 | 26 Ağu 2025 |
34İzleyin | CVE-2025-29907İstismar yok | jsPDF Bypass Regular Expression Denial of Service (ReDoS)parall · jspdf · CWE-400 | Yüksek8,7 | — | %0,7 | 18 Mar 2025 |
34İzleyin | CVE-2026-24133İstismar yok | jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoderparall · jspdf · CWE-770 | Yüksek8,7 | — | %0,6 | 2 Şub 2026 |
32İzleyin | CVE-2026-25940Kavram kanıtı | jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)parall · jspdf · CWE-116 | Yüksek8,1 | — | %0,6 | 19 Şub 2026 |
32İzleyin | CVE-2026-24737İstismar yok | jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Executionparall · jspdf · CWE-116 | Yüksek8,1 | — | %0,5 | 2 Şub 2026 |
31İzleyin | CVE-2021-23353İstismar yok | Regular Expression Denial of Service (ReDoS)parall · jspdf | Yüksek7,5 | — | %2,6 | 9 Mar 2021 |
27İzleyin | CVE-2026-24043İstismar yok | jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation)parall · jspdf · CWE-74 | Orta6,9 | — | %0,3 | 2 Şub 2026 |
26İzleyin | CVE-2026-31898İstismar yok | jsPDF has a PDF Object Injection via FreeText colorparall · jspdf · CWE-116 | Orta6,5 | — | %0,6 | 18 Mar 2026 |
25İzleyin | CVE-2026-24040İstismar yok | jsPDF has a Shared State Race Condition in addJS Pluginparall · jspdf · CWE-362 | Orta6,3 | — | %0,3 | 2 Şub 2026 |
24İzleyin | CVE-2020-7691İstismar yok | Cross-site Scripting (XSS)parall · jspdf · CWE-79 | Orta6,1 | — | %1,6 | 6 Tem 2020 |
24İzleyin | CVE-2020-7690İstismar yok | All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS).parall · jspdf · CWE-79 | Orta6,1 | — | %1,0 | 6 Tem 2020 |
24İzleyin | CVE-2026-31938İstismar yok | jsPDF has HTML Injection in New Window pathsparall · jspdf · CWE-79 | Orta6,1 | — | %0,4 | 18 Mar 2026 |
- CVE-2025-6842837İzleyin
jsPDF has Local File Inclusion/Path Traversal vulnerability
KritikCVSS 9,2Kavram kanıtıEPSS %2parall · jspdf5 Oca 2026
- CVE-2026-2575535İzleyin
jsPDF has PDF Object Injection via Unsanitized Input in addJS Method
YüksekCVSS 8,8Kavram kanıtıEPSS %1parall · jspdf19 Şub 2026
- CVE-2026-2553534İzleyin
jsPDF Affected by Client-Side/Server-Side Denial of Service via Malicious GIF Dimensions
YüksekCVSS 8,7İstismar yokEPSS %1parall · jspdf19 Şub 2026
- CVE-2025-5781034İzleyin
jsPDF Parsing of Corrupt PNGs Leads to Potential Denial of Service (DoS)
YüksekCVSS 8,7İstismar yokEPSS %1parall · jspdf26 Ağu 2025
- CVE-2025-2990734İzleyin
jsPDF Bypass Regular Expression Denial of Service (ReDoS)
YüksekCVSS 8,7İstismar yokEPSS %1parall · jspdf18 Mar 2025
- CVE-2026-2413334İzleyin
jsPDF Affected by Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder
YüksekCVSS 8,7İstismar yokEPSS %1parall · jspdf2 Şub 2026
- CVE-2026-2594032İzleyin
jsPDF's PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)
YüksekCVSS 8,1Kavram kanıtıEPSS %1parall · jspdf19 Şub 2026
- CVE-2026-2473732İzleyin
jsPDF has a PDF Injection in AcroFormChoiceField which allows Arbitrary JavaScript Execution
YüksekCVSS 8,1İstismar yokEPSS %1parall · jspdf2 Şub 2026
- CVE-2021-2335331İzleyin
Regular Expression Denial of Service (ReDoS)
YüksekCVSS 7,5İstismar yokEPSS %3parall · jspdf9 Mar 2021
- CVE-2026-2404327İzleyin
jsPDF Affected by Stored XMP Metadata Injection (Spoofing & Integrity Violation)
OrtaCVSS 6,9İstismar yokEPSS %0parall · jspdf2 Şub 2026
- CVE-2026-3189826İzleyin
jsPDF has a PDF Object Injection via FreeText color
OrtaCVSS 6,5İstismar yokEPSS %1parall · jspdf18 Mar 2026
- CVE-2026-2404025İzleyin
jsPDF has a Shared State Race Condition in addJS Plugin
OrtaCVSS 6,3İstismar yokEPSS %0parall · jspdf2 Şub 2026
- CVE-2020-769124İzleyin
Cross-site Scripting (XSS)
OrtaCVSS 6,1İstismar yokEPSS %2parall · jspdf6 Tem 2020
- CVE-2020-769024İzleyin
All affected versions <2.0.0 of package jspdf are vulnerable to Cross-site Scripting (XSS).
OrtaCVSS 6,1İstismar yokEPSS %1parall · jspdf6 Tem 2020
- CVE-2026-3193824İzleyin
jsPDF has HTML Injection in New Window paths
OrtaCVSS 6,1İstismar yokEPSS %0parall · jspdf18 Mar 2026