CVE-2025-25187 – “Joplin Cross-Site Scripting (XSS) and Remote Code Execution”
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by adding note titles to the document using React’s `dangerouslySetInnerHTML`, without first escaping HTML entities. Joplin lacks a Content-Security-Policy with a restrictive `script-src`. This allows arbitrary JavaScript execution via […]
CVE-2025-24028 – Joplin Rich Text Editor Cross-Site Scripting (XSS) Vulnerability
Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into notebooks. This vulnerability is caused by differences between how Joplin’s HTML sanitizer handles comments and how the browser handles comments. This affects both the Rich Text Editor and the Markdown viewer. However, unlike the […]
CVE-2025-1114 – Newbee-Mall Cross-Site Scripting Vulnerability in Add Category Page
The following table lists the changes that have been made to the CVE-2025-1114 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 07, 2025 Action […]
CVE-2024-55630 – Joplin XPath Injection Denial of Service
The following table lists the changes that have been made to the CVE-2024-55630 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 07, 2025 Action […]
CVE-2025-24366 – SFTPGo RSync Argument Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-24366 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 07, 2025 Action […]
CVE-2025-1113 – Taisan Tarzan-cms Remote Deserialization Vulnerability
The following table lists the changes that have been made to the CVE-2025-1113 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Feb. 07, 2025 Action Type […]
CVE-2024-57357 – TPLINK TL-WPA 8630 Router Command Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-57357 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Feb. 07, 2025 Action Type […]
CVE-2024-57606 – “JeecgBoot SQL Injection Vulnerability”
The following table lists the changes that have been made to the CVE-2024-57606 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 07, 2025 Action […]
CVE-2024-57279 – OpenLDAP LDAP User Manager Reflected Cross-Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2024-57279 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Feb. 07, 2025 Action Type […]
CVE-2024-57278 – QingScan Reflected Cross-Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2024-57278 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0 Feb. 07, 2025 Action Type […]