Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
2544 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.14% | — | Notebook PROAI | 25/5/2026 | 24/7/2026 | Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can create a malicious text file containing 500 or more characters, paste the content into the New Notebook Name field, and… | |
| Aplazada | Media (5.3) | 0.47% | — | Motopress Hotel BookingAI | 22/5/2026 | 23/7/2026 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite or delete the internal… | |
| Aplazada | Crítica (9.8) | 0.87% | 💥 PoC | Bookingpress PROAI | 21/5/2026 | 23/7/2026 | The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Aplazada | Alta (8.2) | 0.52% | — | Phenixdigital Phoenix StorybookAI | 20/5/2026 | 23/7/2026 | Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthenticated denial-of-service via BEAM atom table exhaustion. Multiple LiveView event handlers convert user-supplied event parameter strings to atoms using String.to_atom/1 without validation:… | |
| Aplazada | Crítica (9.5) | 2.1% | 💥 PoC | Phenixdigital Phoenix StorybookAI | 20/5/2026 | 23/7/2026 | Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generation. The psb-assign WebSocket event handler in 'Elixir.PhoenixStorybook.Story.PlaygroundPreviewLive':handle_event/3 accepts arbitrary… | |
| Aplazada | Baja (2.3) | 0.53% | — | Phenixdigital Phoenix StorybookAI | 20/5/2026 | 23/7/2026 | Authorization Bypass Through User-Controlled Key vulnerability in phenixdigital phoenix_storybook allows cross-session PubSub topic injection via a URL query parameter. 'Elixir.PhoenixStorybook.Story.ComponentIframeLive':handle_params/3 in lib/phoenix_storybook/live/story/component_iframe_live.ex reads a PubSub topic… | |
| Aplazada | Media (6.5) | 0.42% | — | Magepeople WpbookinglyAI | 20/5/2026 | 24/7/2026 | Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WpBookingly: from n/a through 1.2.9. | |
| Modificada | Alta (8.6) | 0.71% | — | JupyterlabJupyter Notebook | 13/5/2026 | 28/8/2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on… | |
| Aplazada | Media (5.3) | 0.39% | — | Smart Appointment BookingAI | 12/5/2026 | 17/6/2026 | The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and including, 1.0.8. The nonce check uses && (AND) instead of || (OR), which means… | |
| Aplazada | Media (6.9) | 0.50% | — | AudiobookshelfAI | 11/5/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the podcast creation endpoint at server/controllers/PodcastController.js accepts a user-controlled file path without sufficient boundary validation to ensure it remains within the intended library directory. This vulnerability is fixed in… | |
| Aplazada | Media (4.5) | 0.36% | — | AudiobookshelfAI | 11/5/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulnerability exists in the Login Page due to improper sanitization of the authLoginCustomMessage field of the /api/auth-settings endpoint. An attacker with administrative privileges can inject arbitrary… | |
| Aplazada | Media (4.9) | 0.44% | — | AudiobookshelfAI | 11/5/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint decompresses the details entry from an uploaded .audiobookshelf ZIP file entirely into memory using zip.entryData(), with no limit on the decompressed size. The upload middleware also has no file size… | |
| Aplazada | Media (4.3) | 0.34% | — | AudiobookshelfAI | 11/5/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpoint uses String.startsWith() to validate that a resolved file path is within a library folder. This check fails for sibling directories whose names share a common prefix (e.g., /audiobooks vs… | |
| Aplazada | Media (4.3) | 0.27% | — | AudiobookshelfAI | 11/5/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/collections/:id endpoints return collections from all libraries without checking whether the requesting user has access to each collection's library. An authenticated user with access to any library can… | |
| Aplazada | Media (6.5) | 0.34% | — | AudiobookshelfAI | 11/5/2026 | 17/6/2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the requesting user has access to the library specified in the URL path, but fetches downloadable items solely by attacker-provided IDs without constraining them to that library.… | |
| Aplazada | Media (5.1) | 0.19% | — | Motopress Hotel Booking LiteAI | 10/5/2026 | 25/7/2026 | Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommodation types, which… | |
| Aplazada | Media (5.1) | 0.19% | — | Advanced GuestbookAI | 10/5/2026 | 20/7/2026 | Advanced Guestbook 2.4.4 contains a persistent cross-site scripting vulnerability in the smilies administration interface that allows authenticated attackers to inject malicious scripts by manipulating the s_emotion parameter. Attackers can submit POST requests to admin.php with JavaScript code in the s_emotion field,… | |
| Analizada | Alta (8.2) | 0.31% | — | Lfnovo Open-notebook | 7/5/2026 | 17/6/2026 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal. | |
| Analizada | Alta (7) | 0.32% | — | Lfnovo Open-notebook | 7/5/2026 | 17/6/2026 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal. | |
| Analizada | Crítica (9.2) | 0.38% | — | Lfnovo Open-notebook | 7/5/2026 | 17/6/2026 | Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations. | |
| Analizada | Alta (8.7) | 0.21% | — | Lfnovo Open-notebook | 7/5/2026 | 17/6/2026 | An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible. | |
| Aplazada | Media (5.3) | 0.17% | — | Mage-people BUS Ticket Booking With Seat ReservationAI | 7/5/2026 | 7/10/2026 | Missing Authorization vulnerability in Magepeople inc. Bus Ticket Booking with Seat Reservation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bus Ticket Booking with Seat Reservation: from n/a before 5.6.8. | |
| Aplazada | Media (6.5) | 0.48% | — | Appointment Booking CalendarAI | 7/5/2026 | 17/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the public exposure of a site-wide reusable nonce. The plugin exposes a public_nonce… | |
| Pendiente de análisis | Alta (8.4) | 0.66% | — | Jupyter NotebookAIJupyterlabAIJupyter Help-extensionAIJupyterlab Help-extensionAI | 6/5/2026 | 17/6/2026 | In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook… | |
| Analizada | Alta (7.5) | 1.5% | 💥 PoC | Facebook React-server-dom-parcelFacebook React-server-dom-turbopackFacebook React-server-dom-webpack | 6/5/2026 | 12/8/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel,… |