Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Siyuan CRITICAL 9.8
CVE-2024-53507

A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.

No fix yet
Fix from $2,300 2024-11-29
Siyuan CRITICAL 9.8
CVE-2024-53504

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.

No fix yet
Fix from $2,300 2024-11-29
Siyuan CRITICAL 9.8
CVE-2024-53505

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.

No fix yet
Fix from $2,300 2024-11-29
Siyuan CRITICAL 9.8
CVE-2024-53506

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.

No fix yet
Fix from $2,300 2024-11-29
Siyuan MEDIUM 5.4
CVE-2024-6938

A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file …

No fix yet
Fix from $1,600 2024-07-21
Vditor MEDIUM 6.1
CVE-2024-34449

Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.

No fix yet
Fix from $1,600 2024-05-03
Siyuan CRITICAL 9.0
CVE-2024-2692

SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.

No fix yet
Fix from $2,300 2024-04-04
Solo MEDIUM 6.1
CVE-2018-16248

b3log Solo 2.9.3 has XSS in the Input page under the "Publish Articles" menu with an ID of "articleTags" stored in the "tag" JSON field, which allows…

No fix yet
Fix from $1,600 2019-06-20
Symphony CRITICAL 9.8
CVE-2018-10469

b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.

No fix yet
Fix from $2,300 2018-04-27
Symphony MEDIUM 5.4
CVE-2017-16821

b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP heade…

No fix yet
Fix from $1,600 2017-11-15