Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2024-0849
Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.
Desktop
Mitigation only
MEDIUM 6.1
CVE-2021-4263
A vulnerability, which was classified as problematic, has been found in leanote 2.6.1. This issue affects the function define of the file public/js/p…
Leanote
Patch available
MEDIUM 6.1
CVE-2021-43721
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload : <video src=x …
Leanote
No fix yet
CRITICAL 9.6
CVE-2020-26157
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled during syncing. This leads to remote code execution because of Node int…
Leanote
after 2.6.2
CRITICAL 9.6
CVE-2020-26158
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code executio…
Leanote
after 2.6.2
MEDIUM 6.1
CVE-2019-1010003
Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).
Leanote
2.6+
MEDIUM 6.1
CVE-2018-18553
Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.
Leanote
No fix yet
MEDIUM 6.1
CVE-2017-1000492
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration
Desktop
Patch available
MEDIUM 6.1
CVE-2017-1000459
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
Leanote
after 2.5