Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.29% | — | Footnotes Made EasyAI | 4/11/2025 | 17/6/2026 | The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Notes | 10/10/2025 | 17/6/2026 | Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory. | |
| Analizada | Alta (7.1) | 0.12% | — | Samsung Notes | 10/10/2025 | 17/6/2026 | Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | |
| Analizada | Alta (7.1) | 0.12% | — | Samsung Notes | 10/10/2025 | 17/6/2026 | Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | |
| Analizada | Alta (7.1) | 0.12% | — | Samsung Notes | 10/10/2025 | 17/6/2026 | Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | |
| Analizada | Baja (3.3) | 0.11% | — | Samsung Notes | 10/10/2025 | 17/6/2026 | Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes. | |
| Analizada | Alta (7.1) | 0.12% | — | Samsung Notes | 10/10/2025 | 1/10/2026 | Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | |
| Aplazada | Media (5.9) | 0.22% | — | Cartpauj User NotesAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj User Notes user-notes allows Stored XSS.This issue affects User Notes: from n/a through <= 1.0.2. | |
| Analizada | Media (5) | 0.12% | — | Samsung Notes | 3/9/2025 | 17/6/2026 | Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported note files. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (4.3) | 0.15% | — | Samsung Notes | 3/9/2025 | 1/10/2026 | Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.1) | 0.36% | — | Brufdev Many Notes | 2/9/2025 | 17/6/2026 | Many Notes 0.10.1 is vulnerable to Cross Site Scripting (XSS), which allows malicious Markdown files to execute JavaScript when viewed. | |
| Analizada | Media (6.1) | 0.19% | — | Exe-system Notescms | 26/8/2025 | 17/6/2026 | A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=sites. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit… | |
| Analizada | Media (6.1) | 0.21% | — | Exe-system Notescms | 26/8/2025 | 17/6/2026 | A vulnerability has been found in NotesCMS and classified as medium. Affected by this vulnerability is the page /index.php?route=categories. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit… | |
| Analizada | Media (6.1) | 0.21% | — | Exe-system Notescms | 26/8/2025 | 17/6/2026 | A vulnerability in NotesCMS and specifically in the page /index.php?route=notes. The manipulation of the title of the service descriptions leads to a stored XSS vulnerability. The issue was confirmed to be present in the source code as of commit 7d821a0f028b0778b245b99ab3d3bff1ac10e2d3 (dated 2024-05-08) and was fixed… | |
| Analizada | Media (5.5) | 0.42% | — | Projectworlds Online Notes Sharing Platform | 14/8/2025 | 17/6/2026 | A vulnerability has been found in projectworlds Online Notes Sharing Platform 1.0. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (7.5) | 0.37% | — | Triliumnotes Trilium NotesAI | 5/8/2025 | 17/6/2026 | Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. In versions below 0.97.0, a brute-force protection bypass in the initial sync seed retrieval endpoint allows unauthenticated attackers to guess the login password without… | |
| Analizada | Media (5.5) | 0.54% | — | Phpgurukul Online Notes Sharing System | 8/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Online Notes Sharing System 1.0. This affects an unknown part of the file /Dashboard of the component Cookie Handler. The manipulation of the argument sessionid leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Aplazada | Media (6.5) | 0.23% | — | Prismtechstudios Modern-footnotesAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prismtechstudios Modern Footnotes modern-footnotes allows Stored XSS.This issue affects Modern Footnotes: from n/a through <= 1.4.19. | |
| Aplazada | Media (4.3) | 0.15% | — | Minhlaobao Admin NotesAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.This issue affects Admin Notes: from n/a through <= 1.1. | |
| Aplazada | Media (5.4) | 0.15% | — | Tychesoftwares Woocommerce Delivery NotesAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Cross Site Request Forgery.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.5.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpfactory Product-notes-for-woocommerceAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Product Notes Tab & Private Admin Notes for WooCommerce product-notes-for-woocommerce allows Stored XSS.This issue affects Product Notes Tab & Private Admin Notes for WooCommerce: from n/a through <= 3.1.0. | |
| Aplazada | Media (6.5) | 0.20% | — | Steve Puddick WP Notes WidgetAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Puddick WP Notes Widget wp-notes-widget allows DOM-Based XSS.This issue affects WP Notes Widget: from n/a through <= 1.0.6. | |
| Analizada | Alta (7.5) | 0.53% | — | Jeroensormani WP Dashboard Notes | 15/5/2025 | 17/6/2026 | The WP Dashboard Notes WordPress plugin before 1.0.11 does not validate that the user has access to the post_id parameter in its wpdn_update_note AJAX action. This allows users with a role of contributor and above to update notes created by other users. | |
| Analizada | Baja (3.3) | 0.15% | — | Samsung Notes | 7/5/2025 | 17/6/2026 | Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability. | |
| Analizada | Alta (7.5) | 0.29% | — | Samsung Notes | 7/5/2025 | 17/6/2026 | Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory. |