Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.25% | — | Amazon S3AIHackmd CodimdAI | 26/4/2025 | 17/6/2026 | CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed in certain cases of different-origin file storage, such as AWS S3. NOTE: it can be considered a user error if AWS is employed for hosting untrusted JavaScript content, but… | |
| Analizada | Media (4.9) | 0.26% | — | Hackmd Codimd | 26/4/2025 | 17/6/2026 | CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .html file that references an uploaded .js file. | |
| Modificada | Media (6.1) | 0.42% | — | Hackmd Codimd | 10/7/2024 | 17/6/2026 | CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized `name` attribute. This vulnerability enables attackers to perform cross-site scripting (XSS) attacks via DOM clobbering. This vulnerability is… | |
| Analizada | Media (5.3) | 1.1% | — | Hackmd Codimd | 10/7/2024 | 17/6/2026 | CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated attacker to gain unauthorised access to image data uploaded to CodiMD. CodiMD does not require valid authentication to access uploaded images… | |
| Analizada | Alta (7.5) | 0.69% | — | Hackmd Codimd | 21/2/2024 | 17/6/2026 | HackMD CodiMD <2.5.2 is vulnerable to Denial of Service. | |
| Modificada | Media (6.1) | 0.86% | — | Hackmd Codimd | 23/8/2019 | 17/6/2026 | CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL. |