Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.28% | — | Sticky Notes WidgetAI | 16/5/2026 | 17/6/2026 | Sticky Notes Widget 3.0.6 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash… | |
| Aplazada | Alta (8.7) | 0.28% | — | Sticky Notes AND Color WidgetsAI | 16/5/2026 | 17/6/2026 | Sticky Notes & Color Widgets 1.4.2 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can paste large payloads of repeated characters into note fields to trigger application crashes and make the application stop… | |
| Aplazada | Alta (8.7) | 0.28% | — | MY Notes SafeAI | 16/5/2026 | 17/6/2026 | My Notes Safe 5.3 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash. | |
| Aplazada | Alta (8.7) | 0.28% | — | Macaron NotesAI | 16/5/2026 | 17/6/2026 | Macaron Notes 5.5 contains a denial of service vulnerability that allows attackers to crash the application by creating notes with excessively long character strings. Attackers can generate a payload containing 350000 repeated characters and paste it into a note field to trigger application crash and stop… | |
| Aplazada | Alta (8.7) | 0.28% | — | Color NotesAI | 16/5/2026 | 17/6/2026 | Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350,000 repeated characters and paste it twice into a new note to cause the application to stop… | |
| Analizada | Crítica (9.6) | 0.85% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 4/5/2026 | 17/6/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note… | |
| Aplazada | Media (5.5) | 0.59% | — | Edvardlindelof Notes-mcpAI | 28/4/2026 | 24/7/2026 | A security vulnerability has been detected in edvardlindelof notes-mcp up to 0.1.4. This affects an unknown function of the file notes_mcp.py. The manipulation of the argument root_dir/path leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be… | |
| Analizada | Media (6.1) | 0.34% | — | Streetwriters Notesnook Mobile | 1/4/2026 | 17/6/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip metadata is concatenated into HTML without escaping and then rendered with innerHTML inside the mobile share editor… | |
| Analizada | Crítica (9.6) | 0.69% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 27/3/2026 | 17/6/2026 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element… | |
| Modificada | Alta (8.6) | 0.26% | — | Streetwriters Notesnook Desktop | 27/3/2026 | 17/6/2026 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using… | |
| Aplazada | Alta (7.5) | 0.33% | — | Tychesoftwares Woocommerce Delivery NotesAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.9.0. | |
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds Online Notes Sharing SystemAI | 22/3/2026 | 17/6/2026 | A vulnerability was detected in projectworlds Online Notes Sharing System 1.0. This issue affects some unknown processing of the file /login.php of the component Parameters Handler. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and may be… | |
| Analizada | Media (5.4) | 0.24% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 11/3/2026 | 17/6/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated the user-supplied URL directly into an… | |
| Aplazada | Media (6.5) | 0.21% | — | Tychesoftwares Print Invoice AND Delivery Notes FOR WoocommerceAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.8.0. | |
| Aplazada | Media (4.3) | 0.16% | — | Frontend User NotesAI | 18/2/2026 | 17/6/2026 | The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'funp_ajax_modify_notes' AJAX endpoint due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Analizada | Alta (7.4) | 0.57% | — | Triliumnotes Trilium | 6/2/2026 | 17/6/2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability in Trilium's sync authentication endpoint allows unauthenticated remote attackers to recover HMAC authentication hashes… | |
| Aplazada | Alta (7.2) | 0.31% | — | AJS FootnotesAI | 14/1/2026 | 17/6/2026 | The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup_display_effect_in' parameters in all versions up to, and including, 1.0 due to missing authorization and nonce verification on settings save, as well as insufficient input sanitization and output… | |
| Aplazada | Media (4.3) | 0.21% | — | Webbuilder143 Sticky Notes FOR WP DashboardAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in Web Builder 143 Sticky Notes for WP Dashboard wb-sticky-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sticky Notes for WP Dashboard: from n/a through <= 1.2.4. | |
| Analizada | Baja (2.1) | 0.28% | — | Code-projects College Notes Uploading System | 29/12/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects College Notes Uploading System 1.0. Impacted is an unknown function of the file /dashboard/userprofile.php. The manipulation of the argument image leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Modificada | Media (5.5) | 0.39% | — | Code-projects College Notes Uploading System | 29/12/2025 | 5/10/2026 | A weakness has been identified in code-projects College Notes Uploading System 1.0. This issue affects some unknown processing of the file /login.php. Executing a manipulation of the argument User can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and… | |
| Aplazada | Crítica (9.8) | 3.7% | — | Woocommerce Delivery NotesAI | 24/12/2025 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in… | |
| Aplazada | Media (6.3) | 0.50% | — | Quest Coexistence Manager FOR NotesAI | 19/12/2025 | 17/6/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Quest Coexistence Manager for Notes (Free/Busy Connector modules) allows HTTP Request Smuggling via the Content-Length-Transfer-Encoding (CL.TE) attack vector. This could allow an attacker to bypass access controls,… | |
| Aplazada | Alta (8.1) | 0.38% | — | HCL InotesAI | 25/11/2025 | 17/6/2026 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's… | |
| Modificada | Baja (2.1) | 0.36% | — | Projectworlds Online Notes Sharing Platform | 7/11/2025 | 17/6/2026 | A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Media (4.3) | 0.23% | — | Yydev Page AND Post NotesAI | 7/11/2025 | 17/6/2026 | The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capability check on the 'yydev_notes_save_dashboard_data' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… |