Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2914▼ 57 respecto a la semana anterior
Críticas / altas1416▲ 118 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.78%—Bookstackapp Bookstack7/5/202017/6/2026
In BookStack greater than or equal to 0.18.0 and less than 0.29.2, there is an XSS vulnerability in comment creation. A user with permission to create comments could POST HTML directly to the system to be saved in a comment, which would then be executed/displayed to others users viewing the comment. Through this…
ModificadaAlta (8.8)2.0%—Bookstackapp Bookstack9/3/202017/6/2026
BookStack before version 0.25.5 has a vulnerability where a user could upload PHP files through image upload functions, which would allow them to execute code on the host system remotely. They would then have the permissions of the PHP process. This most impacts scenarios where non-trusted users are given permission…
ModificadaMedia (5.4)0.76%—Bookstackapp Bookstack3/1/201817/6/2026
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.