Keep Project maintains a narrowly scoped vulnerability footprint centered on its Keep product, a note-taking and personal-information-management application. The observed weakness class signals do not yet suggest a durable pattern; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keep Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23377HIGH Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files. | Mar 1, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-30877CRITICAL The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2. | Jun 8, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keep Project.
Media articles that mention a CVE ID that affects a product developed by Keep Project — matched by CVE ID, not by vendor name.