ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-0849
Leanote version 2.7.0 allows obtaining arbitrary local files.

Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.

NVD description · AI analysis pending
5.0<1%
  • leanote desktop
CVE-2021-4263
A vulnerability, which was classified as problematic, has been found in leanote 2.6.1.

A vulnerability, which was classified as problematic, has been found in leanote 2.6.1. This issue affects the function define of the file public/js/plugins/history.js. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is 0f9733c890077942150696dcc6d2b1482b7a0a19. It is recommended to apply a patch to fix this issue. The identifier VDB-216461 was assigned to this vulnerability.

NVD description · AI analysis pending
6.1<1%
  • leanote leanote
CVE-2021-43721
Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note.

Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution with payload :

NVD description · AI analysis pending
6.11% PoC
  • leanote leanote
CVE-2020-26158
+1 in the same advisory: …26157
Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered.

Leanote Desktop through 2.6.2 allows XSS because a note's title is mishandled when the batch feature is triggered. This leads to remote code execution because of Node integration.

NVD description · AI analysis pending
9.62%
  • leanote leanote
CVE-2019-1010003
Leanote prior to version 2.6 is affected by:

Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS).

NVD description · AI analysis pending
6.1<1% PoC
  • leanote leanote
CVE-2018-18553
Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.

Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.

NVD description · AI analysis pending
6.1<1% PoC
  • leanote leanote
CVE-2017-1000492
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration

Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration

NVD description · AI analysis pending
6.11%
  • leanote desktop
CVE-2017-1000459
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes

Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes

NVD description · AI analysis pending
6.1<1% PoC
  • leanote leanote