Vulnerabilidades em laurent22

26 resultados
Análise Vexday

Laurent22 apresenta um portfólio modesto de 15 vulnerabilidades, com apenas 1 classificada como crítica e nenhuma sob exploração ativa conhecida, reduzindo o risco imediato. A fraqueza dominante é Cross-Site Scripting (CWE-79), típica de aplicações web, enquanto 3 vulnerabilidades publicadas nos últimos 90 dias indicam atividade de descoberta contínua que requer monitoramento.

CVE-2025-27134HIGHPrivilege escalation in Joplin server via user patch endpointEPSS 2.1%CVE-2024-49362HIGHRemote Code Execution on click of <a> Link in markdown previewEPSS 1.0%CVE-2023-45673HIGHArbitrary code execution on click of PDF links in JoplinEPSS 1.0%CVE-2024-40643CRITICALJoplin has a parsing error leading to Cross-site Scripting (XSS)EPSS 0.8%CVE-2024-53268HIGHLack of validation on openExternal allows 1 click remote code execution in joplinEPSS 0.7%CVE-2025-27409HIGHJoplin Server Vulnerable to Path TraversalEPSS 0.6%CVE-2026-46649CRITICALJoplin: SSO Auth Code Login Missing Rate Limiting — 9-Digit Numeric Code Brute-Forceable via Unprotected EndpointEPSS 0.6%CVE-2025-24028HIGHCross-site Scripting (XSS) in Rich Text Editor allows arbitrary code execution in JoplinEPSS 0.5%CVE-2026-55105HIGHJoplin: Fountain embeds allow arbitrary script execution in published notes and the note viewerEPSS 0.5%CVE-2026-55210HIGHJoplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin)EPSS 0.5%CVE-2025-25187HIGHCross-site Scripting in Goto Anything allows arbitrary code execution in JoplinEPSS 0.5%CVE-2023-39517HIGHCross site scripting (XSS) when clicking on an untrusted `<map>` link in JoplinEPSS 0.5%CVE-2023-37898HIGHSafe mode Cross-site Scripting (XSS) vulnerability in JoplinEPSS 0.4%CVE-2023-38506HIGHCross-site Scripting (XSS) when pasting HTML into the rich text editor in JoplinEPSS 0.4%CVE-2026-49453HIGHJoplin: Path traversal in resource sync — silent arbitrary file write outside the resource directoryEPSS 0.4%CVE-2026-34600MEDIUMJoplin Server delta API returns note content after share access is revokedEPSS 0.4%CVE-2026-59816MEDIUMJoplin: Path traversal in transcribe proxy endpoint via URL-encoded slashEPSS 0.4%CVE-2026-59814HIGHJoplin: Stored XSS via inline-served note attachment on published sharesEPSS 0.4%CVE-2024-55630LOWDOM Clobbering leads to temporary DOS in the note viewer in JoplinEPSS 0.3%CVE-2026-46650MEDIUMJoplin: Stored XSS in public share viewer via javascript: URL bypass in isAcceptedUrlEPSS 0.3%