Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.51% | — | Phpgurukul Online Notes Sharing System | 22/12/2023 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /user/add-notes.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Alta (8.8) | 0.79% | — | Phpgurukul Online Notes Sharing System | 22/12/2023 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user/signup.php. The manipulation leads to weak password requirements. The attack can be initiated remotely. The complexity of an attack is rather high. The… | |
| Modificada | Media (4.3) | 0.37% | — | Phpgurukul Online Notes Sharing System | 22/12/2023 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been classified as problematic. This affects an unknown part of the file /user/profile.php. The manipulation of the argument name leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (4.3) | 0.35% | — | Phpgurukul Online Notes Sharing System | 21/12/2023 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/manage-notes.php of the component Notes Handler. The manipulation of the argument delid leads to cross-site request forgery. The attack may be… | |
| Modificada | Media (5.4) | 0.50% | — | Phpgurukul Online Notes Sharing System | 21/12/2023 | 17/6/2026 | A vulnerability has been found in PHPGurukul Online Notes Sharing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file user/profile.php. The manipulation of the argument name/email leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Media (6.5) | 0.34% | — | Remyandrade Sticky Notes APP | 22/11/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to add-note.php. | |
| Modificada | Crítica (9.8) | 0.65% | — | Remyandrade Sticky Notes APP | 26/10/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Sticky Notes App 1.0 and classified as critical. This vulnerability affects unknown code of the file endpoint/delete-note.php. The manipulation of the argument note leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Modificada | Media (6.1) | 0.51% | — | Remyandrade Sticky Notes APP | 26/10/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Sticky Notes App 1.0. This affects an unknown part of the file endpoint/add-note.php. The manipulation of the argument noteTitle/noteContent leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has… | |
| Modificada | Media (5.4) | 0.40% | — | Prismtechstudios Modern Footnotes | 20/10/2023 | 17/6/2026 | The Modern Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 1.4.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level… | |
| Modificada | Media (6.1) | 0.59% | — | Nextcloud Notes | 10/8/2023 | 17/6/2026 | Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No… | |
| Modificada | Media (4.8) | 0.39% | — | Prismtechstudios Modern Footnotes | 22/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions. | |
| Modificada | Media (5.5) | 0.33% | — | Omninotes Omni Notes | 27/5/2023 | 17/6/2026 | Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path validation vulnerability when displaying the details of a note received through an externally-provided intent. The paths of the note's attachments were not properly validated, allowing malicious or… | |
| Modificada | Alta (7.8) | 0.75% | — | Hcltech Notes | 19/12/2022 | 17/6/2026 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751. This… | |
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Notes | 19/12/2022 | 17/6/2026 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM. | |
| Modificada | Alta (7.8) | 0.69% | — | Hcltech Notes | 19/12/2022 | 17/6/2026 | HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755. This… | |
| Modificada | Alta (7.5) | 0.57% | — | Hcltech DominoHcltech HCL Inotes | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking. | |
| Modificada | Alta (7.4) | 0.53% | — | Hcltech HCL InotesHcltech Domino | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc. | |
| Modificada | Media (6.1) | 0.64% | — | Hcltech HCL InotesHcltech Domino | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security… | |
| Modificada | Media (5.5) | 0.24% | — | Samsung Notes | 5/8/2022 | 17/6/2026 | Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission. | |
| Modificada | Media (4.8) | 0.59% | — | Bracketspace Simple Post Notes | 17/7/2022 | 17/6/2026 | The Simple Post Notes WordPress plugin before 1.7.6 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (6.1) | 2.9% | — | Triliumnotes Trilium | 3/7/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta. | |
| Modificada | Media (4.6) | 0.41% | — | Kitetech Keep MY Notes | 2/6/2022 | 17/6/2026 | Keep My Notes v1.80.147 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation. | |
| Modificada | Media (5.5) | 0.73% | — | Hcltech HCL Inotes | 6/5/2022 | 17/6/2026 | An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code. | |
| Modificada | Media (5.5) | 0.28% | — | Trillium Notes Project Trillum Notes | 24/2/2022 | 17/6/2026 | A Denial of Service vulnerabilty exists in Trilium Notes 0.48.6 in the setupPage function | |
| Analizada | Media (6.1) | 1.8% | — | Codexnotes Codex | 4/2/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Codex before 1.4.0 via Notebook/Page name field, which allows malicious users to execute arbitrary code via a crafted http code in a .json file. |