Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Facebook FOR WoocommerceAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
AplazadaAlta (7.1)0.25%—Facebook FOR WordpressAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
AnalizadaAlta (7.7)0.80%—Livebook5/8/202610/8/2026
Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server connected to Livebook Teams caches the identifier of the deployment group it…
AnalizadaMedia (6.8)0.24%—Livebook5/8/202610/8/2026
Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When Livebook is configured to use Livebook Teams for identity, Livebook.ZTA.LivebookTeams.handle_request/4 in…
AnalizadaAlta (7)0.61%—Livebook5/8/202610/8/2026
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a file entry through the user interface…
AnalizadaAlta (8.6)0.27%—Livebook5/8/202610/8/2026
Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime restart. Livebook's JS-view feature renders notebook-defined JavaScript inside a sandboxed, cross-origin iframe…
AnalizadaMedia (5)2.4%—Livebook5/8/202610/8/2026
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.docker_instructions/2 and…
AplazadaAlta (7.5)0.77%—Themetechmount TruebookerAI28/7/202628/7/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up to, and including, 1.2.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AplazadaCrítica (9.8)0.50%—Themetechmount TruebookerAI28/7/202628/7/2026
The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.
AplazadaAlta (7.5)0.39%—Shopfiles Ebook StoreAI27/7/202627/7/2026
Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions.
AplazadaAlta (7.5)0.57%—Facebook ProxygenAI23/7/202623/7/2026
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory…
AplazadaMedia (5.3)0.29%—Shopfiles Ebook StoreAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
AplazadaMedia (5.3)0.31%—Shopfiles Ebook StoreAI23/7/202623/7/2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.
AplazadaCrítica (9.8)0.48%—Themetechmount TruebookerAI23/7/202623/7/2026
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.
AplazadaCrítica (9.3)0.40%—Themetechmount TruebookerAI23/7/202623/7/2026
Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.
Pendiente de análisisAlta (7.5)0.60%—Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI21/7/202621/7/2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0…
Pendiente de análisisAlta (8.6)1.0%💥 PoCLibrebookingAI9/7/202630/7/2026
LibreBooking's email template editor save action passes the submitted template name directly into the destination file path, allowing a remote attacker with administrator credentials to write an arbitrary file outside the template directory and execute code. Fixed in 5.1.0.
AplazadaAlta (8.5)0.20%—Calibre-ebook CalibreAI7/7/202618/8/2026
calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read by calibre, including through Add books or Edit books, by embedding a custom column definition with a python: template in calibre:user_metadata that is passed unsanitized to…
AplazadaMedia (5.5)2.1%💥 PoCFacebook Create-react-appAIFacebook React-dev-utilsAI6/7/20266/7/2026
A vulnerability was detected in react create-react-app up to 5.0.1 on macOS. This affects the function startBrowserProcess of the file openBrowser.js of the component react-dev-utils. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and…
AplazadaCrítica (9.1)0.40%—Themetechmount TruebookerAI15/6/202617/6/2026
Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
AplazadaMedia (4.8)0.25%—Dovestones Softwares AdphonebookAI3/6/202622/7/2026
Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads in multiple configuration sections without proper input validation or output encoding.
AplazadaAlta (8.2)0.51%—RVF SET GETAIRVF CoreAIRemixAIFacebook React RouterAI27/5/202617/6/2026
RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when walking a path.…
AplazadaMedia (4.7)0.28%—Facebook FOR WoocommerceAI27/5/202617/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.
AplazadaMedia (6.9)0.14%—Notebook PROAI25/5/202624/7/2026
Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can create a malicious text file containing 500 or more characters, paste the content into the New Notebook Name field, and…
ModificadaAlta (8.6)0.71%—JupyterlabJupyter Notebook13/5/202628/8/2026
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on…