Vulnerabilities
Summary — last 7 days
New vulnerabilities2,751▲ 48 vs. last week
Critical / high1,479▲ 371 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 2.8% | — | Boostnote | 9/17/2021 | 6/17/2026 | static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API. | |
| Modified | Medium (5.4) | 0.53% | — | Issuehunt Boostnote | 5/18/2021 | 6/17/2026 | In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks. | |
| Modified | Medium (5.4) | 0.67% | — | Boostio Boostnote | 5/19/2019 | 6/17/2026 | There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence, gallery, or chart, as demonstrated by a crafted SRC attribute of an IFRAME element, a different vulnerability than CVE-2019-12136. | |
| Modified | Medium (5.4) | 0.61% | — | Boostio Boostnote | 5/16/2019 | 6/17/2026 | There is XSS in BoostIO Boostnote 0.11.15 via a label named mermaid, as demonstrated by a crafted SRC attribute of an IFRAME element. | |
| Modified | Medium (6.1) | 0.86% | — | Boostnote | 7/8/2018 | 6/17/2026 | Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element. |