Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 2.5% | — | Ipython NotebookJupyter Notebook | 29/9/2015 | 17/6/2026 | The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types. | |
| Modificada | Media (4.3) | 2.8% | — | Jupyter NotebookFedoraproject FedoraOpensuseIpython Notebook | 21/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF)… | |
| Modificada | Media (6.8) | 4.7% | — | OpensuseIpython NotebookMageia | 7/8/2014 | 17/6/2026 | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1296. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1229. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1228. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1227. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1226. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1225. | |
| Modificada | Alta (10) | 12% | — | HP Data Protector FOR Personal ComputersHP Data Protector Notebook Extension | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Notebook Extension 6.20 and Data Protector for Personal Computers 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1222. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Dmxready Online Notebook Manager | 21/6/2010 | 16/6/2026 | SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Dmxready Online Notebook Manager | 10/2/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in DMXReady Online Notebook Manager 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. NOTE: some third parties report inability to verify this issue. | |
| Modificada | Alta (7.2) | 0.53% | — | Compaq Presario A900Compaq Presario C700HP G7000Hpqflash FOR HP Notebook System Bios | 31/3/2008 | 16/6/2026 | Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password. | |
| Modificada | Baja (2.1) | 0.54% | — | Gabriele Teotino Gnotebook | 1/12/2006 | 16/6/2026 | The Gabriele Teotino GNotebook 0.7.0.1 gadget for Google Desktop stores Gmail passwords in plaintext in the %SYSTEMDRIVE%\temp\Gnotebook.txt log file, which allows local users to obtain passwords by reading the file. | |
| Modificada | Alta (8.3) | 13% | 💥 Exploit | Linksys Wpc300n Wireless-n Notebook Adapter DriverBroadcom Bcmwl5.sys Wireless Device Driver | 14/11/2006 | 16/6/2026 | Stack-based buffer overflow in the Broadcom BCMWL5.SYS wireless device driver 3.50.21.10, as used in Cisco Linksys WPC300N Wireless-N Notebook Adapter before 4.100.15.5 and other products, allows remote attackers to execute arbitrary code via an 802.11 response frame containing a long SSID field. | |
| Modificada | Media (5) | 1.2% | — | THE Magic Notebook | 31/12/2002 | 16/6/2026 | Magic Notebook 1.0b and 1.1b allows remote attackers to cause a denial of service (crash) via an invalid username during login. |