Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.67% | — | JupyterlabJupyter NotebookFedoraproject Fedora | 19/1/2024 | 17/6/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab… | |
| Modificada | Media (6.1) | 0.57% | — | JupyterlabJupyter NotebookFedoraproject Fedora | 19/1/2024 | 17/6/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has… | |
| Modificada | Crítica (9.8) | 0.49% | — | Jupyter Language Server Protocol Integration | 18/1/2024 | 17/6/2026 | jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file system access control (on the operating system level), and with jupyter-server… | |
| Modificada | Crítica (9.8) | 1.1% | — | Tinowagner Jupyter Notebook Viewer | 5/1/2024 | 17/6/2026 | nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds. | |
| Modificada | Media (4.3) | 0.64% | — | Jupyter Dockerspawner | 8/12/2023 | 17/6/2026 | dockerspawner is a tool to spawn JupyterHub single user servers in Docker containers. Users of JupyterHub deployments running DockerSpawner starting with 0.11.0 without specifying `DockerSpawner.allowed_images` configuration allow users to launch _any_ pullable docker image, instead of restricting to only the single… | |
| Modificada | Media (4.3) | 0.84% | — | Jupyter Server | 4/12/2023 | 17/6/2026 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled errors in API requests coming from an authenticated user include traceback information, which can include path information. There is no known… | |
| Modificada | Crítica (9.8) | 1.5% | — | Microsoft Jupyter | 14/11/2023 | 17/6/2026 | Visual Studio Code Jupyter Extension Spoofing Vulnerability | |
| Modificada | Media (6.1) | 0.62% | — | Jupyter Server | 28/8/2023 | 17/6/2026 | jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". This issue has been addressed in commit `87a49272728` which has been included… | |
| Modificada | Media (6.1) | 0.68% | — | Jupyter Server | 28/8/2023 | 17/6/2026 | jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs. This issue has been… | |
| Modificada | Alta (8.8) | 1.2% | — | Jupyter CoreDebian LinuxFedoraproject Fedora | 26/10/2022 | 17/6/2026 | Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version… | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Jupyter | 11/10/2022 | 17/6/2026 | Visual Studio Code Elevation of Privilege Vulnerability | |
| Modificada | Media (5.4) | 1.4% | — | Jupyter NbconvertDebian Linux | 18/8/2022 | 17/6/2026 | The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks… | |
| Modificada | Alta (8.8) | 0.95% | — | Jupyter Server | 14/6/2022 | 17/6/2026 | Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter Notebook. Prior to version 1.17.1, if notebook server is started with a value of `root_dir` that contains the starting user's home directory, then the underlying REST API can be used to leak… | |
| Modificada | Media (4.3) | 1.1% | — | Jupyter Notebook | 14/6/2022 | 17/6/2026 | Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the notebook server with `ContentsManager.allow_hidden = False` only prevented listing the contents of hidden directories, not accessing individual hidden files or files in hidden… | |
| Modificada | Media (6.5) | 0.47% | — | Jupyter Oauthenticator | 9/6/2022 | 17/6/2026 | OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets users log in to a JupyterHub via CILogon. This is primarily used to restrict a JupyterHub only to users of a given institute. The allowed_idps configuration trait of… | |
| Modificada | Alta (7.5) | 1.1% | — | Jupyter Notebook | 31/3/2022 | 17/6/2026 | The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter server logs by default. Considering these… | |
| Modificada | Alta (7.5) | 1.3% | — | Jupyter Server | 23/3/2022 | 17/6/2026 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter… | |
| Modificada | Alta (7.1) | 1.1% | — | Jupyter Server Proxy | 25/1/2022 | 17/6/2026 | Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to Server-Side Request Forgery (SSRF). Any user deploying Jupyter Server or Notebook with jupyter-proxy-server extension enabled is affected. A lack of input validation… | |
| Modificada | Alta (7.5) | 0.80% | — | Jupyterhub | 4/11/2021 | 17/6/2026 | JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if… | |
| Modificada | Media (5.4) | 0.70% | — | Jupyter NbdimeNbdime-jupyterlab | 3/11/2021 | 17/6/2026 | nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the Jupyter-owned nbdime project. It appears that when reading the file name and path from disk, the extension does not sanitize the string it constructs before returning it… | |
| Modificada | Crítica (9.8) | 1.4% | — | Jupyterhub First USE Authenticator | 28/10/2021 | 17/6/2026 | FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if `create_users=True` and the username is… | |
| Modificada | Crítica (9.8) | 1.9% | — | Jupyter Binderhub | 25/8/2021 | 17/6/2026 | BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In affected versions a remote code execution vulnerability has been identified in BinderHub, where providing BinderHub with maliciously crafted input could execute code in… | |
| Modificada | Alta (8.8) | 1.7% | — | Jupyterhub Nbgitpuller | 25/8/2021 | 17/6/2026 | nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.10.2 and all users are advised to upgrade. No work around exist… | |
| Modificada | Crítica (9.6) | 2.1% | — | Jupyter Notebook | 9/8/2021 | 17/6/2026 | The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious… | |
| Modificada | Crítica (9.6) | 2.7% | — | Jupyterlab | 9/8/2021 | 17/6/2026 | JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>`. Using this it is possible to trigger the form validation… |