Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.5) | 0.50% | — | Jupyterhub | 13/1/2021 | 17/6/2026 | JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account). | |
| Modificada | Media (6.1) | 1.4% | — | Jupyter Server | 21/12/2020 | 17/6/2026 | The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open redirect vulnerability could cause the jupyter server to redirect the browser to a different malicious… | |
| Modificada | Alta (7.9) | 0.48% | — | Jupyterhub Systemdspawner | 9/12/2020 | 17/6/2026 | jupyterhub-systemdspawner enables JupyterHub to spawn single-user notebook servers using systemd. In jupyterhub-systemdspawner before version 0.15 user API tokens issued to single-user servers are specified in the environment of systemd units. These tokens are incorrectly accessible to all users. In particular,… | |
| Modificada | Media (6.3) | 1.1% | — | Jupyter Oauthenticator | 1/12/2020 | 17/6/2026 | OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which should be transparently mapped to `Authenticator.allowed_users` with a warning, is instead ignored by OAuthenticator… | |
| Modificada | Media (5.4) | 1.0% | — | Jupyter Server | 24/11/2020 | 17/6/2026 | Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to a different website. All jupyter servers are technically affected, however, these maliciously crafted links can only be reasonably made for known jupyter server hosts. A… | |
| Modificada | Media (6.1) | 1.2% | — | Jupyter NotebookDebian Linux | 18/11/2020 | 17/6/2026 | Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server… | |
| Modificada | Alta (8.1) | 1.1% | — | Jupyterhub Kubespawner | 17/7/2020 | 17/6/2026 | In jupyterhub-kubespawner before 0.12, certain usernames will be able to craft particular server names which will grant them access to the default server of other users who have matching usernames. This has been fixed in 0.12. | |
| Modificada | Media (5.3) | 1.4% | — | Jupyter Notebook | 31/10/2019 | 17/6/2026 | Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document. | |
| Modificada | Media (6.1) | 1.3% | — | Jupyter Notebook | 4/4/2019 | 17/6/2026 | In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255. | |
| Modificada | Media (6.1) | 1.8% | — | JupyterhubJupyter Notebook | 28/3/2019 | 17/6/2026 | An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected. | |
| Modificada | Media (5.4) | 1.5% | — | Jupyter Notebook | 12/3/2019 | 17/6/2026 | An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though… | |
| Modificada | Media (6.1) | 1.3% | — | Jupyter Notebook | 18/11/2018 | 17/6/2026 | Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely. | |
| Modificada | Media (6.1) | 1.5% | — | Jupyter Notebook | 18/11/2018 | 17/6/2026 | Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and… | |
| Modificada | Alta (7.8) | 1.1% | — | Jupyter Notebook | 18/3/2018 | 17/6/2026 | In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous. | |
| Modificada | Alta (8.8) | 1.8% | — | Jupyter Oauthenticator | 18/2/2018 | 17/6/2026 | An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab group whitelisting for access control, group membership was not checked correctly, allowing members not in the whitelisted groups to create accounts on the Hub. (Users were… | |
| Modificada | Media (6.8) | 2.5% | — | Ipython NotebookJupyter Notebook | 29/9/2015 | 17/6/2026 | The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types. | |
| Modificada | Media (4.3) | 2.8% | — | Jupyter NotebookFedoraproject FedoraOpensuseIpython Notebook | 21/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF)… |