« Volver al listado

Enchantedcode

Enchantedcode Note Mark: vulnerabilidades y CVE

Enchantedcode Note Mark tiene 8 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses7
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-50553Alta (8.6)0.46%—4 sept 2026
Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". huma compiles this with…
CVE-2026-50554Media (5.3)0.42%—3 sept 2026
Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the…
CVE-2026-44523Crítica (10)0.16%—14 may 2026
Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any base64-decodable secret regardless of…
CVE-2026-44522Alta (8.6)0.72%—14 may 2026
Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows authenticated users to upload assets to notes via POST /api/notes/{noteID}/assets, where the asset…
CVE-2026-41572Media (5.3)0.33%—4 may 2026
Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay readable at /api/notes/{id}, /api/notes/{id}/content,…
CVE-2026-40263Baja (3.7)0.31%—17 abr 2026
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the login endpoint performs bcrypt password verification only when the supplied username exists, returning immediately for nonexistent…
CVE-2026-40262Alta (8.7)0.42%—17 abr 2026
Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset delivery handler serves uploaded files inline and relies on magic-byte detection for content type, which does not identify…
CVE-2024-41819Media (5.4)0.82%—29 jul 2024
Note Mark is a web-based Markdown notes app. A stored cross-site scripting (XSS) vulnerability in Note Mark allows attackers to execute arbitrary web scripts via a crafted payload injected into the URL value of a link…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution2
  2. T1005 Data from Local System1
  3. T1059.007 JavaScript1
  4. T1078.004 Cloud Accounts1
  5. T1189 Drive-by Compromise1
  6. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.