Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.38% | — | HCL InotesAI | 25/11/2025 | 17/6/2026 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input. A remote, unauthenticated attacker can specially craft a URL to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's… | |
| Modificada | Media (5.5) | 0.33% | — | Omninotes Omni Notes | 27/5/2023 | 17/6/2026 | Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path validation vulnerability when displaying the details of a note received through an externally-provided intent. The paths of the note's attachments were not properly validated, allowing malicious or… | |
| Modificada | Alta (7.5) | 0.57% | — | Hcltech DominoHcltech HCL Inotes | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking. | |
| Modificada | Alta (7.4) | 0.53% | — | Hcltech HCL InotesHcltech Domino | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc. | |
| Modificada | Media (6.1) | 0.64% | — | Hcltech HCL InotesHcltech Domino | 29/8/2022 | 17/6/2026 | HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security… | |
| Modificada | Media (5.5) | 0.73% | — | Hcltech HCL Inotes | 6/5/2022 | 17/6/2026 | An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote Code Execution on another chat client by sending a specially formatted message through chat containing Javascript code. | |
| Modificada | Media (6.5) | 1.3% | — | Hcltech HCL InotesHcltechsw HCL Inotes | 21/12/2020 | 17/6/2026 | HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could use this vulnerability to trick the end user into entering sensitive information such as credentials, e.g. as part of a phishing attack. | |
| Modificada | Media (6.1) | 1.1% | — | Hcltech HCL Inotes | 18/12/2020 | 17/6/2026 | HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthenticated remote attacker could exploit this vulnerability using specially-crafted markup to execute script in a victim's web browser within the security context of the… | |
| Modificada | Media (5.9) | 0.67% | — | Hcltech HCL Inotes | 1/12/2020 | 17/6/2026 | HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later. | |
| Modificada | Media (6.1) | 0.67% | — | IBM Inotes | 1/7/2020 | 17/6/2026 | "HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials." | |
| Modificada | Media (6.1) | 1.3% | — | IBM Inotes | 11/7/2018 | 16/6/2026 | Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383. | |
| Modificada | Media (5.4) | 0.70% | — | IBM Inotes | 11/7/2018 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 83815. | |
| Modificada | Alta (7.5) | 1.7% | — | IBM Inotes | 11/7/2018 | 16/6/2026 | IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to bypass the remote image filtering mechanism and obtain sensitive information via a crafted e-mail message. IBM X-Force ID: 83371. | |
| Modificada | Media (6.1) | 1.1% | — | IBM Inotes | 13/12/2017 | 17/6/2026 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.5) | 29% | — | IBM Inotes | 5/9/2017 | 17/6/2026 | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it would open up many file select dialog boxes which would cause the client hang and have to be restarted. IBM X-Force ID: 121371. | |
| Modificada | Media (6.5) | 30% | — | IBM InotesIBM Expeditor | 5/9/2017 | 17/6/2026 | IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it could cause the Notes client to hang and have to be restarted. IBM X-Force ID: 121370. | |
| Modificada | Media (6.1) | 0.97% | — | IBM Inotes | 3/8/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126062. | |
| Modificada | Media (6.1) | 0.98% | — | IBM Inotes | 31/7/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126234. | |
| Modificada | Media (5.7) | 1.3% | — | IBM Inotes | 12/6/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. IBM X-Force ID: 123854. | |
| Modificada | Media (6.1) | 0.85% | — | IBM Inotes | 26/5/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125976. | |
| Modificada | Media (6.1) | 1.3% | — | IBM Inotes | 31/3/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998824. | |
| Modificada | Media (6.1) | 1.1% | — | IBM Inotes | 23/2/2017 | 17/6/2026 | IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997010. | |
| Modificada | Media (6.1) | 0.96% | — | IBM Inotes | 1/2/2017 | 17/6/2026 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.1) | 0.96% | — | IBM DominoIBM Inotes | 1/2/2017 | 17/6/2026 | IBM Verse is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Media (6.1) | 0.96% | — | IBM DominoIBM Inotes | 1/2/2017 | 17/6/2026 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |