Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
53 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 84% | 💥 Exploit | Calibre-ebook CalibreAI | 6/8/2024 | 17/6/2026 | Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution. | |
| Analizada | Alta (7.5) | 62% | 💥 Exploit | Calibre-ebook Calibre | 6/8/2024 | 17/6/2026 | Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read. | |
| Analizada | Media (5.4) | 23% | 💥 PoC | Janeczku Calibre-web | 19/7/2024 | 17/6/2026 | In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization. | |
| Modificada | Alta (7.5) | 1.3% | — | Calibre-ebook Calibre | 22/10/2023 | 17/6/2026 | link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root. | |
| Modificada | Crítica (9.8) | 0.75% | — | Janeczku Calibre-web | 15/4/2023 | 17/6/2026 | Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. | |
| Modificada | Crítica (9.8) | 0.77% | — | Janeczku Calibre-web | 15/4/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. | |
| Modificada | Crítica (9.8) | 1.2% | — | Janeczku Calibre-web | 16/5/2022 | 17/6/2026 | Calibre-Web before 0.6.18 allows user table SQL Injection. | |
| Modificada | Crítica (9.1) | 1.3% | — | Janeczku Calibre-web | 4/4/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | |
| Modificada | Crítica (9.9) | 1.1% | — | Janeczku Calibre-web | 4/4/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. | |
| Modificada | Media (4.3) | 0.66% | — | Janeczku Calibre-web | 3/4/2022 | 17/6/2026 | Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. | |
| Modificada | Media (4.3) | 0.76% | — | Janeczku Calibre-web | 3/4/2022 | 17/6/2026 | Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16. | |
| Modificada | Crítica (9.9) | 0.98% | — | Janeczku Calibre-web | 7/3/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | |
| Modificada | Crítica (9.8) | 1.3% | — | Janeczku Calibre-web | 7/3/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. | |
| Modificada | Crítica (9.8) | 0.96% | — | Janeczku Calibre-web | 30/1/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. | |
| Modificada | Media (6.5) | 0.67% | — | Janeczku Calibre-web | 30/1/2022 | 17/6/2026 | Improper Access Control in Pypi calibreweb prior to 0.6.16. | |
| Modificada | Media (6.1) | 0.85% | — | Janeczku Calibre-web | 28/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16. | |
| Modificada | Alta (8.8) | 0.55% | — | Janeczku Calibre-web | 17/1/2022 | 17/6/2026 | calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) | |
| Modificada | Crítica (9.8) | 1.4% | — | Janeczku Calibre-web | 17/1/2022 | 17/6/2026 | calibre-web is vulnerable to Business Logic Errors | |
| Modificada | Media (5.4) | 0.81% | — | Janeczku Calibre-web | 16/1/2022 | 17/6/2026 | calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Modificada | Alta (7.5) | 5.2% | — | Calibre-ebook CalibreFedoraproject Fedora | 7/12/2021 | 17/6/2026 | calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py. | |
| Modificada | Alta (8.8) | 0.53% | — | Janeczku Calibre-web | 16/11/2021 | 17/6/2026 | In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application. | |
| Modificada | Alta (8.1) | 1.5% | — | Calibre-ebook Calibre | 27/10/2021 | 16/6/2026 | Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere. | |
| Modificada | Crítica (9.8) | 2.3% | — | Calibre-ebook Calibre | 27/10/2021 | 16/6/2026 | A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root. | |
| Modificada | Crítica (9.8) | 2.3% | — | Calibre-ebook Calibre | 27/10/2021 | 16/6/2026 | Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges. | |
| Modificada | Media (5.4) | 0.55% | — | Janeczku Calibre-web | 4/10/2021 | 17/6/2026 | In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered. |