Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Typora MEDIUM 6.1
CVE-2024-41482

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.

Fix: 1.9.3+
Fix from $1,600 2024-08-12
Typora MEDIUM 6.1
CVE-2024-41481

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.

Fix: 1.9.3+
Fix from $1,600 2024-08-12
Typora HIGH 7.3
CVE-2024-33300

Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrar…

Fix: after 1.7.0
Fix from $1,950 2024-05-01
Typora MEDIUM 6.1
CVE-2024-31783

Cross Site Scripting (XSS) vulnerability in Typora v.1.6.7 and before, allows a local attacker to obtain sensitive information via a crafted script d…

Fix: after 1.6.7
Fix from $1,600 2024-04-16
Typora MEDIUM 6.1
CVE-2024-31784

An issue in Typora v.1.8.10 and before, allows a local attacker to obtain sensitive information and execute arbitrary code via a crafted payload to t…

Fix: after 1.8.10
Fix from $1,600 2024-04-16
Typora HIGH 7.4
CVE-2020-18336

Cross Site Scripting (XSS) vulnerability found in Typora v.0.9.65 allows a remote attacker to obtain sensitive information via the PDF file exporting…

No fix yet
Fix from $1,950 2023-10-10
Typora MEDIUM 6.1
CVE-2023-39703

A cross site scripting (XSS) vulnerability in the Markdown Editor component of Typora v1.6.7 allows attackers to execute arbitrary code via uploading…

Fix: 1.6.7+
Fix from $1,600 2023-09-01
Typora MEDIUM 6.5
CVE-2023-2971

Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote w…

Fix: after 1.6.7
Fix from $1,600 2023-08-19
Typora CRITICAL 9.6
CVE-2023-2317

DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in t…

Fix: 1.6.7+
Fix from $2,300 2023-08-19
Typora HIGH 7.4
CVE-2023-2316

Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web s…

Fix: 1.6.7+
Fix from $1,950 2023-08-19
Typora MEDIUM 6.1
CVE-2020-21058

Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.

Patch available
Fix from $1,600 2023-06-20
Typora HIGH 7.8
CVE-2023-1003

A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH J…

Fix: after 1.5.5
Fix from $1,950 2023-03-07
Typora MEDIUM 6.1
CVE-2022-40011

Typora through 1.3.8 allows XSS if a document containing an SVG element with an attacker-controlled onload attribute is exported and then used at a v…

Fix: after 1.3.8
Fix from $1,600 2022-12-23
Typora MEDIUM 6.1
CVE-2022-43668

Typora versions prior to 1.4.4 fails to properly neutralize JavaScript code, which may result in executing JavaScript code contained in the file when…

Fix: 1.4.4+
Fix from $1,600 2022-12-07
Typora MEDIUM 6.1
CVE-2020-18748

Cross Site Scripting (XSS) in Typora v0.9.65 allows attackers to execute arbitrary code via mathjax syntax due to a mathjax configuration error in th…

No fix yet
Fix from $1,600 2021-08-19
Typora MEDIUM 6.1
CVE-2020-18221

Cross Site Scripting (XSS) in Typora v0.9.65 and earlier allows remote attackers to execute arbitrary code by injecting commands during block renderi…

Fix: after 0.9.65
Fix from $1,600 2021-05-26
Typora MEDIUM 6.1
CVE-2020-18737

An issue was discovered in Typora 0.9.67. There is an XSS vulnerability that causes Remote Code Execution.

No fix yet
Fix from $1,600 2021-02-05
Typora CRITICAL 9.6
CVE-2019-20374

A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through …

Fix: after 0.9.81
Fix from $2,300 2020-01-09
Typora HIGH 7.8
CVE-2019-12172

Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an AREA element, as demonstrated by…

No fix yet
Fix from $1,950 2019-05-17
Typora HIGH 7.8
CVE-2019-12137EPSS 6%

Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note.

No fix yet
Fix from $1,950 2019-05-16
Typora MEDIUM 6.1
CVE-2019-7295

typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula.

Fix: after 0.9.63
Fix from $1,600 2019-01-31
Typora MEDIUM 6.1
CVE-2019-7296

typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formula.

Fix: after 0.9.64
Fix from $1,600 2019-01-31
Typora MEDIUM 6.1
CVE-2019-6803

typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar.

No fix yet
Fix from $1,600 2019-01-25