Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Facebook FOR WoocommerceAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Facebook FOR WordpressAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions. | |
| Analizada | Alta (7.7) | 0.80% | — | Livebook | 5/8/2026 | 10/8/2026 | Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server connected to Livebook Teams caches the identifier of the deployment group it… | |
| Analizada | Media (6.8) | 0.24% | — | Livebook | 5/8/2026 | 10/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When Livebook is configured to use Livebook Teams for identity, Livebook.ZTA.LivebookTeams.handle_request/4 in… | |
| Analizada | Alta (7) | 0.61% | — | Livebook | 5/8/2026 | 10/8/2026 | Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a file entry through the user interface… | |
| Analizada | Alta (8.6) | 0.27% | — | Livebook | 5/8/2026 | 10/8/2026 | Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime restart. Livebook's JS-view feature renders notebook-defined JavaScript inside a sandboxed, cross-origin iframe… | |
| Analizada | Media (5) | 2.4% | — | Livebook | 5/8/2026 | 10/8/2026 | Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.docker_instructions/2 and… | |
| Aplazada | Alta (7.5) | 0.77% | — | Themetechmount TruebookerAI | 28/7/2026 | 28/7/2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Themetechmount TruebookerAI | 28/7/2026 | 28/7/2026 | The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site. | |
| Aplazada | Alta (7.5) | 0.39% | — | Shopfiles Ebook StoreAI | 27/7/2026 | 27/7/2026 | Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | |
| Aplazada | Alta (7.5) | 0.57% | — | Facebook ProxygenAI | 23/7/2026 | 23/7/2026 | Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory… | |
| Aplazada | Media (5.3) | 0.29% | — | Shopfiles Ebook StoreAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | Shopfiles Ebook StoreAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Themetechmount TruebookerAI | 23/7/2026 | 23/7/2026 | Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Themetechmount TruebookerAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. | |
| Pendiente de análisis | Alta (7.5) | 0.60% | — | Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI | 21/7/2026 | 21/7/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0… | |
| Pendiente de análisis | Alta (8.6) | 1.0% | 💥 PoC | LibrebookingAI | 9/7/2026 | 30/7/2026 | LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0. | |
| Aplazada | Alta (8.5) | 0.20% | — | Calibre-ebook CalibreAI | 7/7/2026 | 18/8/2026 | calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom column definition with a python: template in calibre:user_metadata that is passed unsanitized to… | |
| Aplazada | Media (5.5) | 2.1% | 💥 PoC | Facebook Create-react-appAIFacebook React-dev-utilsAI | 6/7/2026 | 6/7/2026 | A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Themetechmount TruebookerAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. | |
| Aplazada | Media (4.8) | 0.25% | — | Dovestones Softwares AdphonebookAI | 3/6/2026 | 22/7/2026 | Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding. | |
| Aplazada | Alta (8.2) | 0.51% | — | RVF SET GETAIRVF CoreAIRemixAIFacebook React RouterAI | 27/5/2026 | 17/6/2026 | RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when walking a path.… | |
| Aplazada | Media (4.7) | 0.28% | — | Facebook FOR WoocommerceAI | 27/5/2026 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0. | |
| Aplazada | Media (6.9) | 0.14% | — | Notebook PROAI | 25/5/2026 | 24/7/2026 | Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can create a malicious text file containing 500 or more characters, paste the content into the New Notebook Name field, and… | |
| Modificada | Alta (8.6) | 0.71% | — | JupyterlabJupyter Notebook | 13/5/2026 | 28/8/2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on… |