Typora kayıtları
typora üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %4,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-290 Authentication Bypass by Spoofing1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-2317İstismar yok | Typora DOM-Based Cross-site Scripting leading to Remote Code Executiontypora · typora · CWE-79 | Kritik9,6 | — | %2,4 | 19 Ağu 2023 |
39İzleyin | CVE-2019-20374İstismar yok | A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Executiontypora · typora · CWE-79 | Kritik9,6 | — | %2,3 | 9 Oca 2020 |
33İzleyin | CVE-2019-12137Kavram kanıtı | Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared notetypora · typora · CWE-22 | Yüksek7,8 | — | %6,5 | 16 May 2019 |
32İzleyin | CVE-2019-12172İstismar yok | Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstypora · typora · CWE-22 | Yüksek7,8 | — | %1,8 | 17 May 2019 |
31İzleyin | CVE-2023-1003İstismar yok | Typora WSH JScript code injectiontypora · typora · CWE-94 | Yüksek7,8 | — | %0,4 | 7 Mar 2023 |
29İzleyin | CVE-2023-2316İstismar yok | Typora Local File Disclosuretypora · typora · CWE-22 | Yüksek7,4 | — | %0,7 | 19 Ağu 2023 |
29İzleyin | CVE-2020-18336İstismar yok | Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file typora · typora · CWE-79 | Yüksek7,4 | — | %0,6 | 9 Eki 2023 |
29İzleyin | CVE-2024-33300İstismar yok | Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to executetypora · typora · CWE-79 | Yüksek7,3 | — | %0,6 | 1 May 2024 |
26İzleyin | CVE-2023-2971İstismar yok | Typora Local File Disclosuretypora · typora · CWE-22 | Orta6,5 | — | %0,5 | 19 Ağu 2023 |
25İzleyin | CVE-2019-6803İstismar yok | typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.typora · typora · CWE-79 | Orta6,1 | — | %1,9 | 25 Oca 2019 |
25İzleyin | CVE-2019-7296İstismar yok | typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.typora · typora · CWE-79 | Orta6,1 | — | %1,7 | 31 Oca 2019 |
25İzleyin | CVE-2019-7295İstismar yok | typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.typora · typora · CWE-79 | Orta6,1 | — | %1,7 | 31 Oca 2019 |
24İzleyin | CVE-2020-18737İstismar yok | An issue was discovered in Typora 0.9.67.typora · typora · CWE-79 | Orta6,1 | — | %1,3 | 5 Şub 2021 |
24İzleyin | CVE-2020-18221İstismar yok | Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during bloctypora · typora · CWE-79 | Orta6,1 | — | %1,2 | 26 May 2021 |
24İzleyin | CVE-2020-18748İstismar yok | Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration ertypora · typora · CWE-79 | Orta6,1 | — | %0,9 | 19 Ağu 2021 |
24İzleyin | CVE-2020-21058İstismar yok | Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.typora · typora · CWE-79 | Orta6,1 | — | %0,6 | 20 Haz 2023 |
24İzleyin | CVE-2023-39703İstismar yok | A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via typora · typora · CWE-79 | Orta6,1 | — | %0,5 | 1 Eyl 2023 |
24İzleyin | CVE-2022-40011İstismar yok | Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then ustypora · typora · CWE-79 | Orta6,1 | — | %0,4 | 23 Ara 2022 |
24İzleyin | CVE-2024-41481İstismar yok | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.typora · typora · CWE-79 | Orta6,1 | — | %0,4 | 12 Ağu 2024 |
24İzleyin | CVE-2024-31783İstismar yok | Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a craftedtypora · typora · CWE-79 | Orta6,1 | — | %0,4 | 16 Nis 2024 |
24İzleyin | CVE-2022-43668İstismar yok | Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the typora · typora · CWE-79 | Orta6,1 | — | %0,4 | 7 Ara 2022 |
24İzleyin | CVE-2024-41482İstismar yok | Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.typora · typora · CWE-79 | Orta6,1 | — | %0,3 | 12 Ağu 2024 |
24İzleyin | CVE-2024-31784İstismar yok | An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted paytypora · typora · CWE-290 | Orta6,1 | — | %0,3 | 16 Nis 2024 |
- CVE-2023-231739İzleyin
Typora DOM-Based Cross-site Scripting leading to Remote Code Execution
KritikCVSS 9,6İstismar yokEPSS %2typora · typora19 Ağu 2023
- CVE-2019-2037439İzleyin
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution
KritikCVSS 9,6İstismar yokEPSS %2typora · typora9 Oca 2020
- CVE-2019-1213733İzleyin
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note
YüksekCVSS 7,8Kavram kanıtıEPSS %6typora · typora16 May 2019
- CVE-2019-1217232İzleyin
Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demons
YüksekCVSS 7,8İstismar yokEPSS %2typora · typora17 May 2019
- CVE-2023-100331İzleyin
Typora WSH JScript code injection
YüksekCVSS 7,8İstismar yokEPSS %0typora · typora7 Mar 2023
- CVE-2023-231629İzleyin
Typora Local File Disclosure
YüksekCVSS 7,4İstismar yokEPSS %1typora · typora19 Ağu 2023
- CVE-2020-1833629İzleyin
Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file
YüksekCVSS 7,4İstismar yokEPSS %1typora · typora9 Eki 2023
- CVE-2024-3330029İzleyin
Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute
YüksekCVSS 7,3İstismar yokEPSS %1typora · typora1 May 2024
- CVE-2023-297126İzleyin
Typora Local File Disclosure
OrtaCVSS 6,5İstismar yokEPSS %0typora · typora19 Ağu 2023
- CVE-2019-680325İzleyin
typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.
OrtaCVSS 6,1İstismar yokEPSS %2typora · typora25 Oca 2019
- CVE-2019-729625İzleyin
typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.
OrtaCVSS 6,1İstismar yokEPSS %2typora · typora31 Oca 2019
- CVE-2019-729525İzleyin
typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.
OrtaCVSS 6,1İstismar yokEPSS %2typora · typora31 Oca 2019
- CVE-2020-1873724İzleyin
An issue was discovered in Typora 0.9.67.
OrtaCVSS 6,1İstismar yokEPSS %1typora · typora5 Şub 2021
- CVE-2020-1822124İzleyin
Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during bloc
OrtaCVSS 6,1İstismar yokEPSS %1typora · typora26 May 2021
- CVE-2020-1874824İzleyin
Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration er
OrtaCVSS 6,1İstismar yokEPSS %1typora · typora19 Ağu 2021
- CVE-2020-2105824İzleyin
Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.
OrtaCVSS 6,1İstismar yokEPSS %1typora · typora20 Haz 2023
- CVE-2023-3970324İzleyin
A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via
OrtaCVSS 6,1İstismar yokEPSS %0typora · typora1 Eyl 2023
- CVE-2022-4001124İzleyin
Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then us
OrtaCVSS 6,1İstismar yokEPSS %0typora · typora23 Ara 2022
- CVE-2024-4148124İzleyin
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.
OrtaCVSS 6,1İstismar yokEPSS %0typora · typora12 Ağu 2024
- CVE-2024-3178324İzleyin
Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted
OrtaCVSS 6,1İstismar yokEPSS %0typora · typora16 Nis 2024
- CVE-2022-4366824İzleyin
Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the
OrtaCVSS 6,1İstismar yokEPSS %0typora · typora7 Ara 2022
- CVE-2024-4148224İzleyin
Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.
OrtaCVSS 6,1İstismar yokEPSS %0typora · typora12 Ağu 2024
- CVE-2024-3178424İzleyin
An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted pay
OrtaCVSS 6,1İstismar yokEPSS %0typora · typora16 Nis 2024