Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Marked HIGH 7.5
CVE-2026-41680

Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a sp…

Fix: 18.0.2+
Fix from $1,950 2026-04-24
Marked HIGH 7.5
CVE-2018-25110

Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several reg…

Fix: 0.3.17+
Fix from $1,950 2025-05-23
Marked HIGH 7.5
CVE-2021-21306

Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before version 2.0.0, there is a Regul…

Fix: 2.0.0+
Fix from $1,950 2021-02-08
Marked MEDIUM 6.1
CVE-2014-3743

Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web scri…

Fix: 0.3.1+
Fix from $1,600 2020-01-06
Marked HIGH 7.5
CVE-2017-16114

The marked module is vulnerable to a regular expression denial of service. Based on the information published in the public issue, 1k characters can …

Fix: 0.3.9+
Fix from $1,950 2018-06-07
Marked MEDIUM 6.1
CVE-2016-10531

marked is an application that is meant to parse and compile markdown. Due to the way that marked 0.3.5 and earlier parses input, specifically HTML en…

Fix: after 0.3.5
Fix from $1,600 2018-05-31
Marked MEDIUM 6.1
CVE-2017-1000427

marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

Fix: after 0.3.6
Fix from $1,600 2018-01-02