Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.51% | — | B3log Siyuan | 19/1/2026 | 17/6/2026 | SiYuan is a personal knowledge management system. Versions prior to 3.5.4 contain a logic vulnerability in the /api/file/globalCopyFiles endpoint. The function allows authenticated users to copy files from any location on the server's filesystem into the application's workspace without proper path validation. The… | |
| Analizada | Alta (7.8) | 0.61% | — | B3log Siyuan | 19/1/2026 | 17/6/2026 | SiYuan is a personal knowledge management system. In versions prior to 3.5.4, the markdown feature allows unrestricted server side html-rendering which allows arbitrary file read (LFD). Version 3.5.4 fixes the issue. | |
| Analizada | Baja (2.1) | 0.31% | — | B3log Siyuan | 19/1/2026 | 17/6/2026 | SiYuan is a personal knowledge management system. Versions prior to 3.5.4 are vulnerable to reflected cross-site scripting in /api/icon/getDynamicIcon due to unsanitized SVG input. The endpoint generates SVG images for text icons (type=8). The content query parameter is inserted directly into the SVG <text> tag… | |
| Analizada | Media (5.3) | 0.28% | — | B3log Siyuan | 16/1/2026 | 17/6/2026 | SiYuan is self-hosted, open source personal knowledge management software. Prior to 3.5.4-dev2, a Stored Cross-Site Scripting (XSS) vulnerability exists in SiYuan Note. The application does not sanitize uploaded SVG files. If a user uploads and views a malicious SVG file (e.g., imported from an untrusted source),… | |
| Analizada | Media (6.9) | 0.22% | — | B3log Siyuan | 27/12/2025 | 17/6/2026 | SiYuan is self-hosted, open source personal knowledge management software. In versions 3.5.1 and prior, the SiYuan Note application utilizes a hardcoded cryptographic secret for its session store. This unsafe practice renders the session encryption ineffective. Since the sensitive AccessAuthCode is stored within the… | |
| Analizada | Alta (8.8) | 0.44% | — | B3log Siyuan | 9/12/2025 | 17/6/2026 | SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function importZipMd which is vulnerable to ZipSlips, allowing an authenticated user to overwrite files on the system. An authenticated user with access to the import functionality in… | |
| Analizada | Alta (8.7) | 0.60% | — | B3log Siyuan | 3/1/2025 | 17/6/2026 | SiYuan is self-hosted, open source personal knowledge management software. SiYuan Note version 3.1.18 has an arbitrary file deletion vulnerability. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint. An attacker can craft a payload to exploit this vulnerability, resulting in the deletion… | |
| Analizada | Media (6.9) | 0.62% | — | B3log Siyuan | 12/12/2024 | 17/6/2026 | SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template engine. Although the engine has limitations, it allows attackers to access environment variables. Version 3.1.16… | |
| Analizada | Alta (8.7) | 0.38% | — | B3log Siyuan | 12/12/2024 | 17/6/2026 | SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is vulnerable to both arbitrary file write to the host and stored cross-site scripting (via the file write). Version 3.1.16 contains a patch for the issue. | |
| Analizada | Alta (8.7) | 0.60% | — | B3log Siyuan | 12/12/2024 | 17/6/2026 | SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace… | |
| Analizada | Alta (8.7) | 0.74% | — | B3log Siyuan | 12/12/2024 | 17/6/2026 | SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/render` endpoint. The absence of proper validation on the path parameter allows attackers to access sensitive files on the host system. Version 3.1.16 contains a patch for… | |
| Analizada | Crítica (9.8) | 0.57% | — | B3log Siyuan | 29/11/2024 | 17/6/2026 | A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems. | |
| Analizada | Crítica (9.8) | 0.54% | — | B3log Siyuan | 29/11/2024 | 17/6/2026 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs. | |
| Analizada | Crítica (9.8) | 0.51% | — | B3log Siyuan | 29/11/2024 | 17/6/2026 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent. | |
| Analizada | Crítica (9.8) | 0.57% | — | B3log Siyuan | 29/11/2024 | 17/6/2026 | A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory. | |
| Analizada | Media (5.3) | 0.36% | — | B3log Siyuan | 21/7/2024 | 17/6/2026 | A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file PDF.js of the component PDF Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9) | 0.73% | — | B3log Siyuan | 4/4/2024 | 17/6/2026 | SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS. |