Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-53507 A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems. Siyuan No fix yet Fix from $2,3002024-11-29 CRITICAL 9.8 CVE-2024-53504 A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory. Siyuan No fix yet Fix from $2,3002024-11-29 CRITICAL 9.8 CVE-2024-53505 A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent. Siyuan No fix yet Fix from $2,3002024-11-29 CRITICAL 9.8 CVE-2024-53506 A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs. Siyuan No fix yet Fix from $2,3002024-11-29 MEDIUM 5.4 CVE-2024-6938 A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file … Siyuan No fix yet Fix from $1,6002024-07-21 MEDIUM 6.1 CVE-2024-34449 Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true. Vditor No fix yet Fix from $1,6002024-05-03 CRITICAL 9.0 CVE-2024-2692 SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS. Siyuan No fix yet Fix from $2,3002024-04-04 MEDIUM 6.1 CVE-2018-16248 b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows… Solo No fix yet Fix from $1,6002019-06-20 CRITICAL 9.8 CVE-2018-10469 b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI. Symphony No fix yet Fix from $2,3002018-04-27 MEDIUM 5.4 CVE-2017-16821 b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP heade… Symphony No fix yet Fix from $1,6002017-11-15