Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.31% | — | Lfnovo Open-notebook | 7/5/2026 | 17/6/2026 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal. | |
| Analizada | Alta (7) | 0.32% | — | Lfnovo Open-notebook | 7/5/2026 | 17/6/2026 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal. | |
| Analizada | Crítica (9.2) | 0.38% | — | Lfnovo Open-notebook | 7/5/2026 | 17/6/2026 | Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations. | |
| Analizada | Alta (8.7) | 0.21% | — | Lfnovo Open-notebook | 7/5/2026 | 17/6/2026 | An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible. | |
| Pendiente de análisis | Alta (8.4) | 0.66% | — | Jupyter NotebookAIJupyterlabAIJupyter Help-extensionAIJupyterlab Help-extensionAI | 6/5/2026 | 17/6/2026 | In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook… | |
| Analizada | Alta (7.5) | 1.5% | 💥 PoC | Facebook React-server-dom-parcelFacebook React-server-dom-turbopackFacebook React-server-dom-webpack | 6/5/2026 | 12/8/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel,… | |
| Aplazada | Media (5.5) | 0.59% | — | Usamak98 Python-notebook-mcpAI | 5/5/2026 | 17/6/2026 | A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2. Impacted is the function create_notebook/read_notebook/edit_cell/add_cell of the file server.py. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been published… | |
| Analizada | Media (6.1) | 0.31% | — | Dovestones AD Phonebook | 21/4/2026 | 17/6/2026 | Dovestones Softwares ADPhonebook <4.0.1.1 has a reflected cross-site scripting (XSS) vulnerability in the search parameter of the /ADPhonebook?Department=HR endpoint. User-supplied input is reflected in the HTTP response without proper input validation or output encoding, allowing execution of arbitrary JavaScript in… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | 💥 PoC | Facebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI | 8/4/2026 | 25/7/2026 | A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially… | |
| Aplazada | Media (5.3) | 0.29% | — | Themetechmount TruebookerAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.5. | |
| Aplazada | Media (5.3) | 0.21% | — | Themetechmount TruebookerAI | 31/3/2026 | 17/6/2026 | The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 through views php files. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the exposed… | |
| Analizada | Alta (8.6) | 0.21% | — | HNB Project Hierarchical Notebook | 28/3/2026 | 7/10/2026 | HNB Organizer 1.9.18-10 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized argument to the -rc command-line parameter. Attackers can craft a malicious input string exceeding 108 bytes containing shellcode and a return address to overwrite the… | |
| Analizada | Alta (8.2) | 0.22% | — | Calibre-ebook Calibre | 27/3/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include arbitrary files from the file system into the… | |
| Analizada | Media (4.8) | 0.17% | — | Calibre-ebook Calibre | 27/3/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a Server-Side Request Forgery vulnerability in the background-image endpoint of calibre e-book reader's web view allows an attacker to perform blind GET requests to arbitrary URLs and exfiltrate… | |
| Analizada | Alta (8.7) | 0.80% | — | Phreesoft Phreebookserp | 24/3/2026 | 17/6/2026 | PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension controls. Attackers can upload malicious PHP files through the image manager endpoint and execute them to establish reverse… | |
| Modificada | Alta (8.7) | 0.90% | — | Phreesoft Phreebookserp | 24/3/2026 | 17/6/2026 | PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and… | |
| Aplazada | Media (5.3) | 0.29% | — | AYS Facebook Popup LikeboxAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro Popup Like box ays-facebook-popup-likebox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Like box: from n/a through <= 3.7.7. | |
| Analizada | Alta (8.2) | 0.19% | — | Calibre-ebook Calibre | 13/3/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability in the RocketBook (.rb) input plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to write arbitrary files to any path writable by the calibre process when a user… | |
| Aplazada | Alta (8.8) | 0.58% | — | Nextscripts Social-networks-auto-poster-facebook-twitter-gAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NextScripts NextScripts social-networks-auto-poster-facebook-twitter-g allows Object Injection.This issue affects NextScripts: from n/a through <= 4.4.7. | |
| Analizada | Media (5.3) | 0.19% | — | Calibre-ebook Calibre | 27/2/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, the calibre Content Server's brute-force protection mechanism uses a ban key derived from both `remote_addr` and the `X-Forwarded-For` header. Since the `X-Forwarded-For` header is read directly… | |
| Analizada | Media (6.4) | 0.32% | — | Calibre-ebook Calibre | 27/2/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.4.0, an HTTP Response Header Injection vulnerability in the calibre Content Server allows any authenticated user to inject arbitrary HTTP headers into server responses via an unsanitized… | |
| Analizada | Crítica (9.3) | 0.56% | — | Calibre-ebook Calibre | 20/2/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that allow arbitrary file writes with arbitrary extension and arbitrary content anywhere the… | |
| Analizada | Crítica (9.3) | 0.85% | — | Calibre-ebook Calibre | 20/2/2026 | 17/6/2026 | calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below contain a Path Traversal vulnerability that allows arbitrary file writes anywhere the user has write permissions. On Windows, this leads to Remote Code Execution by writing a payload to the… | |
| Analizada | Alta (7.8) | 0.29% | 💥 PoC | Calibre-ebook Calibre | 6/2/2026 | 17/6/2026 | calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templite templating engine allows arbitrary code execution when a user converts an ebook using a malicious custom template file via the --template-html or --template-html-index command-line options. This… | |
| Analizada | Alta (7.8) | 0.18% | — | Calibre-ebook Calibre | 6/2/2026 | 17/6/2026 | calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a malicious EPUB file to corrupt arbitrary existing files writable by the Calibre process. During conversion, Calibre resolves CipherReference URI from META-INF/encryption.xml to an absolute… |