Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

53 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)84%💥 ExploitCalibre-ebook CalibreAI6/8/202417/6/2026
Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.
AnalizadaAlta (7.5)62%💥 ExploitCalibre-ebook Calibre6/8/202417/6/2026
Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.
AnalizadaMedia (5.4)23%💥 PoCJaneczku Calibre-web19/7/202417/6/2026
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization performed by the clean_string function. The vulnerability arises from the way the clean_string function handles HTML sanitization.
ModificadaAlta (7.5)1.3%—Calibre-ebook Calibre22/10/202317/6/2026
link_to_local_path in ebooks/conversion/plugins/html_input.py in calibre before 6.19.0 can, by default, add resources outside of the document root.
ModificadaCrítica (9.8)0.75%—Janeczku Calibre-web15/4/202317/6/2026
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
ModificadaCrítica (9.8)0.77%—Janeczku Calibre-web15/4/202317/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
ModificadaCrítica (9.8)1.2%—Janeczku Calibre-web16/5/202217/6/2026
Calibre-Web before 0.6.18 allows user table SQL Injection.
ModificadaCrítica (9.1)1.3%—Janeczku Calibre-web4/4/202217/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
ModificadaCrítica (9.9)1.1%—Janeczku Calibre-web4/4/202217/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
ModificadaMedia (4.3)0.66%—Janeczku Calibre-web3/4/202217/6/2026
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
ModificadaMedia (4.3)0.76%—Janeczku Calibre-web3/4/202217/6/2026
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
ModificadaCrítica (9.9)0.98%—Janeczku Calibre-web7/3/202217/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
ModificadaCrítica (9.8)1.3%—Janeczku Calibre-web7/3/202217/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
ModificadaCrítica (9.8)0.96%—Janeczku Calibre-web30/1/202217/6/2026
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
ModificadaMedia (6.5)0.67%—Janeczku Calibre-web30/1/202217/6/2026
Improper Access Control in Pypi calibreweb prior to 0.6.16.
ModificadaMedia (6.1)0.85%—Janeczku Calibre-web28/1/202217/6/2026
Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.
ModificadaAlta (8.8)0.55%—Janeczku Calibre-web17/1/202217/6/2026
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
ModificadaCrítica (9.8)1.4%—Janeczku Calibre-web17/1/202217/6/2026
calibre-web is vulnerable to Business Logic Errors
ModificadaMedia (5.4)0.81%—Janeczku Calibre-web16/1/202217/6/2026
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
ModificadaAlta (7.5)5.2%—Calibre-ebook CalibreFedoraproject Fedora7/12/202117/6/2026
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.
ModificadaAlta (8.8)0.53%—Janeczku Calibre-web16/11/202117/6/2026
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the application.
ModificadaAlta (8.1)1.5%—Calibre-ebook Calibre27/10/202116/6/2026
Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.
ModificadaCrítica (9.8)2.3%—Calibre-ebook Calibre27/10/202116/6/2026
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.
ModificadaCrítica (9.8)2.3%—Calibre-ebook Calibre27/10/202116/6/2026
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.
ModificadaMedia (5.4)0.55%—Janeczku Calibre-web4/10/202117/6/2026
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered.
Orbitaley — Vulnerabilidades