Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
–

367 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.35%—Anirbandutta9 College-notes-galleryAI22/9/202623/9/2026
A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a manipulation of the argument image results in unrestricted upload. It is possible to…
AplazadaMedia (5.5)0.41%—Anirbandutta9 College-notes-galleryAI22/9/202623/9/2026
A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The…
AplazadaCrítica (9.6)0.70%—Brufdev Many NotesAI17/9/202630/9/2026
Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write arbitrary files outside the importing user's…
AplazadaBaja (2.1)0.37%—Sourcecodester College Notes Gallery Management SystemAI15/9/202615/9/2026
A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The…
AplazadaMedia (5.5)0.50%—Sourcecodester College Notes Gallery Management SystemAI15/9/202615/9/2026
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The…
AplazadaMedia (5.5)0.43%—Sourcecodester College Notes Gallery Management SystemAI15/9/202615/9/2026
A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been…
AplazadaMedia (5.4)0.23%—Triliumnotes Trilium NotesAI14/9/202616/9/2026
Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that…
AnalizadaMedia (6.9)0.09%—Samsung Notes9/9/202623/9/2026
Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.
AplazadaMedia (6.9)0.12%—Standard NotesAIEvernoteAIGoogle KeepAI7/9/20269/9/2026
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and…
AplazadaMedia (5.3)0.45%—Rexrainbow Phaser3-rex-notesAI24/8/202624/8/2026
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of…
AplazadaMedia (6.5)0.87%—Webtoffee Woocommerce PDF Invoices Packing Slips Delivery Notes Shipping LabelsAI23/8/202624/8/2026
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.9.8 via the get_image_src_in_base64 function. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaAlta (8.3)0.43%—Triliumnotes Trilium NotesAI18/8/202618/9/2026
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and…
AplazadaAlta (8.2)0.36%—Agenticmail ClaudecodeAIAgenticmail CoreAICodexnotes CodexAIOpenclawAI20/7/202623/7/2026
AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail handlers act on a privileged effect without…
Pendiente de análisisMedia (5.5)0.44%—HCL NotesAI15/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS). Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another user. This issue affects HCL Notes: Release…
AplazadaAlta (7.5)0.42%—Wpfactory Print Invoice AND Delivery Notes FOR WoocommerceAI26/6/202626/6/2026
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.
AplazadaAlta (7.5)0.42%—Wpcloud Woocommerce PDF Invoices Packing Slips Delivery Notes AND Shipping LabelsAI15/6/202617/6/2026
Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions.
AplazadaCrítica (9.8)0.64%—FlatnotesAI15/6/202617/6/2026
An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.
AplazadaMedia (6.4)0.25%—Jquery Hover FootnotesAI9/6/202623/7/2026
The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...}}' Syntax) in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and…
AplazadaMedia (4.3)0.14%—Jquery Hover FootnotesAI9/6/202623/7/2026
The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the jqFootnotes_options_subpanel function. This makes it possible for unauthenticated attackers to update the plugin's settings…
AplazadaMedia (4.3)0.19%—Frontend User NotesAI6/6/202623/7/2026
The Frontend User Notes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to missing or incorrect nonce validation on the funp_ajax_modify_notes function. This makes it possible for unauthenticated attackers to trick a logged-in user into visiting…
AplazadaCrítica (9.3)0.21%—Triliumnotes Trilium NotesAI29/5/202622/7/2026
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.102.2, a malicious ZIP archive imported with safe import enabled achieves RCE via #docName path traversal and XSS by combining a payload note (type: code, mime: text/plain) containing…
AplazadaMedia (6.8)0.36%—Triliumnotes Trilium NotesAI20/5/202623/7/2026
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security flaw where lack of SVG sanitization combined with a disabled Content Security Policy (CSP) and a publicly reachable backend execution API…
AplazadaAlta (8.6)0.50%—Triliumnotes Trilium NotesAI20/5/202623/7/2026
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron…
AplazadaMedia (5.5)0.16%—Triliumnotes Trilium NotesAI20/5/202624/7/2026
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running…
AplazadaMedia (6.8)0.73%—Triliumnotes Trilium NotesAI20/5/202624/7/2026
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read sensitive arbitrary files from the server's filesystem. The…