Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

367 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.51%—Phpgurukul Online Notes Sharing System22/12/202317/6/2026
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and…
ModificadaAlta (8.8)0.79%—Phpgurukul Online Notes Sharing System22/12/202317/6/2026
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The…
ModificadaMedia (4.3)0.37%—Phpgurukul Online Notes Sharing System22/12/202317/6/2026
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been classified as problematic. This affects an unknown part of the file /user/profile.php. The manipulation of the argument name leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been…
ModificadaMedia (4.3)0.35%—Phpgurukul Online Notes Sharing System21/12/202317/6/2026
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/manage-notes.php of the component Notes Handler. The manipulation of the argument delid leads to cross-site request forgery. The attack may be…
ModificadaMedia (5.4)0.50%—Phpgurukul Online Notes Sharing System21/12/202317/6/2026
A vulnerability has been found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file user/profile.php. The manipulation of the argument name/email leads to cross site scripting. The attack can be launched remotely. The…
ModificadaMedia (6.5)0.34%—Remyandrade Sticky Notes APP22/11/202317/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to add-note.php.
ModificadaCrítica (9.8)0.65%—Remyandrade Sticky Notes APP26/10/202317/6/2026
A vulnerability has been found in SourceCodester Sticky Notes App 1.0 and classified as critical. This vulnerability affects unknown code of the file endpoint/delete-note.php. The manipulation of the argument note leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
ModificadaMedia (6.1)0.51%—Remyandrade Sticky Notes APP26/10/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester Sticky Notes App 1.0. This affects an unknown part of the file endpoint/add-note.php. The manipulation of the argument noteTitle/noteContent leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…
ModificadaMedia (5.4)0.40%—Prismtechstudios Modern Footnotes20/10/202317/6/2026
The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level…
ModificadaMedia (6.1)0.59%—Nextcloud Notes10/8/202317/6/2026
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No…
ModificadaMedia (4.8)0.39%—Prismtechstudios Modern Footnotes22/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions.
ModificadaMedia (5.5)0.33%—Omninotes Omni Notes27/5/202317/6/2026
Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path validation vulnerability when displaying the details of a note received through an externally-provided intent. The paths of the note's attachments were not properly validated, allowing malicious or…
ModificadaAlta (7.8)0.75%—Hcltech Notes19/12/202217/6/2026
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751. This…
ModificadaAlta (7.8)0.69%—Hcltech Notes19/12/202217/6/2026
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM.
ModificadaAlta (7.8)0.69%—Hcltech Notes19/12/202217/6/2026
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755. This…
ModificadaAlta (7.5)0.57%—Hcltech DominoHcltech HCL Inotes29/8/202217/6/2026
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
ModificadaAlta (7.4)0.53%—Hcltech HCL InotesHcltech Domino29/8/202217/6/2026
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
ModificadaMedia (6.1)0.64%—Hcltech HCL InotesHcltech Domino29/8/202217/6/2026
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security…
ModificadaMedia (5.5)0.24%—Samsung Notes5/8/202217/6/2026
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.
ModificadaMedia (4.8)0.59%—Bracketspace Simple Post Notes17/7/202217/6/2026
The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (6.1)2.9%—Triliumnotes Trilium3/7/202217/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.
ModificadaMedia (4.6)0.41%—Kitetech Keep MY Notes2/6/202217/6/2026
Keep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.
ModificadaMedia (5.5)0.73%—Hcltech HCL Inotes6/5/202217/6/2026
An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code.
ModificadaMedia (5.5)0.28%—Trillium Notes Project Trillum Notes24/2/202217/6/2026
A Denial of Service vulnerabilty exists in Trilium Notes 0.48.6 in the setupPage function
AnalizadaMedia (6.1)1.8%—Codexnotes Codex4/2/202217/6/2026
A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file.