Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

465 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.1)0.20%—JupyterlabAIJupyter NotebookAIJupyterlite CoreAI29/9/20262/10/2026
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled…
AplazadaMedia (5.3)0.25%—Facebook ProxygenAI28/9/202630/9/2026
In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::onWebTransportBidiStream APIs could return stream handles that the stream handler had already freed. HQSession then installed those handles as transport read callbacks, which could lead to use of…
AplazadaAlta (7.3)0.19%—Facebook ProxygenAI28/9/20261/10/2026
In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSessionBase::closeSession method. The base method notifies the session handler, which may release the last reference to the session and destroy it.
AplazadaAlta (7.1)0.32%—Google Notebooklm MCPAI21/9/202624/9/2026
NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-to-vault` endpoint, also exposed through the `batch_to_vault` MCP tool beginning in…
AplazadaCrítica (9.8)0.42%—Themetechmount TruebookerAI16/9/202616/9/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
AplazadaBaja (2.1)0.32%—Gongshengyue OnlinebooksAI13/9/202616/9/2026
A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column results in sql injection. The attack may…
AplazadaAlta (8.3)0.41%—Open NotebookAI13/9/202624/9/2026
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application…
Pendiente de análisisAlta (7)0.20%—Facebook Zstd-jniAI9/9/202614/9/2026
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or…
AplazadaCrítica (9.8)0.60%—Themetechmount TruebookerAI19/8/202621/8/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check…
AplazadaMedia (6.9)0.71%—Mybooks TalebookAI19/8/20269/9/2026
MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REGISTER configuration flag, even though the frontend hides registration controls when the flag is false. An…
AplazadaAlta (8.7)0.45%—MybooksAITalebookAI19/8/20269/9/2026
MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler for POST /api/admin/settings in webserver/handlers/admin.py applies the auth decorator but does not check the self.admin_user property, unlike the corresponding GET handler. Any authenticated regular…
AplazadaCrítica (9.4)0.50%—MybooksAITalebookAI19/8/20269/9/2026
MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL_AUTH key names without validating quotes or newline characters, and SettingsLoader.dumpfile in webserver/loader.py…
AplazadaCrítica (9.8)0.48%—Themetechmount TruebookerAI19/8/202620/8/2026
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
AplazadaMedia (5.3)0.30%—Themetechmount TruebookerAI19/8/202626/8/2026
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to delete arbitrary appointment records along with their associated booking items and payment records.
AplazadaMedia (5.3)0.34%—Themetechmount TruebookerAI19/8/202626/8/2026
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to retrieve the personal information of customers who booked an appointment, including their name, email address, phone number and postal address.
AplazadaMedia (5.3)0.30%—Themetechmount TruebookerAI19/8/202626/8/2026
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to change the status of arbitrary appointments, as well as to trigger notification emails to the affected customers.
AplazadaCrítica (9.8)0.50%—Themetechmount TruebookerAI19/8/202626/8/2026
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password reset flow.
AplazadaMedia (5.3)0.37%—Gomarble-ai Facebook-ads-mcp-serverAI16/8/202620/8/2026
A vulnerability has been found in gomarble-ai facebook-ads-mcp-server 0.1.0. The impacted element is the function fetch_pagination_url of the file server.py. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The name of the patch is 4e53875aa22e8991c2fa4a7660d86e1caba66659.…
AplazadaCrítica (9.8)0.66%—Themetechmount TruebookerAI15/8/202620/8/2026
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user()…
AplazadaAlta (7.5)0.44%—Calibre-ebook CalibreAI11/8/20269/9/2026
calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_write_access() before update_annotations() passes attacker-controlled JSON…
AplazadaAlta (8.5)0.20%—Calibre-ebook CalibreAI11/8/20269/9/2026
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing a nested python: template to reach…
AplazadaCrítica (9.8)0.56%—Themetechmount TruebookerAI7/8/202612/8/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.8)0.51%—Themetechmount TruebookerAI7/8/202612/8/2026
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it…
AplazadaAlta (7.1)0.25%—Facebook FOR WoocommerceAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
AplazadaAlta (7.1)0.25%—Facebook FOR WordpressAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.