Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.31%—Lfnovo Open-notebook7/5/202617/6/2026
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.
AnalizadaAlta (7)0.32%—Lfnovo Open-notebook7/5/202617/6/2026
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
AnalizadaCrítica (9.2)0.38%—Lfnovo Open-notebook7/5/202617/6/2026
Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.
AnalizadaAlta (8.7)0.21%—Lfnovo Open-notebook7/5/202617/6/2026
An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible.
Pendiente de análisisAlta (8.4)0.66%—Jupyter NotebookAIJupyterlabAIJupyter Help-extensionAIJupyterlab Help-extensionAI6/5/202617/6/2026
In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook…
AnalizadaAlta (7.5)1.5%💥 PoCFacebook React-server-dom-parcelFacebook React-server-dom-turbopackFacebook React-server-dom-webpack6/5/202612/8/2026
A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel,…
AplazadaMedia (5.5)0.59%—Usamak98 Python-notebook-mcpAI5/5/202617/6/2026
A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been published…
AnalizadaMedia (6.1)0.31%—Dovestones AD Phonebook21/4/202617/6/2026
Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in…
Pendiente de análisisAlta (7.5)1.6%💥 PoCFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI8/4/202625/7/2026
A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially…
AplazadaMedia (5.3)0.29%—Themetechmount TruebookerAI8/4/202624/7/2026
Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.5.
AplazadaMedia (5.3)0.21%—Themetechmount TruebookerAI31/3/202617/6/2026
The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed…
AnalizadaAlta (8.6)0.21%—HNB Project Hierarchical Notebook28/3/20267/10/2026
HNB Organizer 1.9.18-10 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -rc command-line parameter. Attackers can craft a malicious input string exceeding 108 bytes containing shellcode and a return address to overwrite the…
AnalizadaAlta (8.2)0.22%—Calibre-ebook Calibre27/3/202617/6/2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include arbitrary files from the file system into the…
AnalizadaMedia (4.8)0.17%—Calibre-ebook Calibre27/3/202617/6/2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate…
AnalizadaAlta (8.7)0.80%—Phreesoft Phreebookserp24/3/202617/6/2026
PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension controls. Attackers can upload malicious PHP files through the image manager endpoint and execute them to establish reverse…
ModificadaAlta (8.7)0.90%—Phreesoft Phreebookserp24/3/202617/6/2026
PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and…
AplazadaMedia (5.3)0.29%—AYS Facebook Popup LikeboxAI13/3/202617/6/2026
Missing Authorization vulnerability in Ays Pro Popup Like box ays-facebook-popup-likebox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Like box: from n/a through <= 3.7.7.
AnalizadaAlta (8.2)0.19%—Calibre-ebook Calibre13/3/202617/6/2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to write arbitrary files to any path writable by the calibre process when a user…
AplazadaAlta (8.8)0.58%—Nextscripts Social-networks-auto-poster-facebook-twitter-gAI5/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7.
AnalizadaMedia (5.3)0.19%—Calibre-ebook Calibre27/2/202617/6/2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the `X-Forwarded-For` header is read directly…
AnalizadaMedia (6.4)0.32%—Calibre-ebook Calibre27/2/202617/6/2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, an HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated user to inject arbitrary HTTP headers into server responses via an unsanitized…
AnalizadaCrítica (9.3)0.56%—Calibre-ebook Calibre20/2/202617/6/2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that allow arbitrary file writes with arbitrary extension and arbitrary content anywhere the…
AnalizadaCrítica (9.3)0.85%—Calibre-ebook Calibre20/2/202617/6/2026
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows, this leads to Remote Code Execution by writing a payload to the…
AnalizadaAlta (7.8)0.29%💥 PoCCalibre-ebook Calibre6/2/202617/6/2026
calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This…
AnalizadaAlta (7.8)0.18%—Calibre-ebook Calibre6/2/202617/6/2026
calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from META-INF/encryption.xml to an absolute…
Orbitaley — Vulnerabilidades