Vulnerabilities

Summary — last 7 days

New vulnerabilities2,751▲ 48 vs. last week
Critical / high1,479▲ 371 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)64▼ 462 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedCritical (9.8)2.8%—Boostnote9/17/20216/17/2026
static/main-preload.js in Boost Note through 0.22.0 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal Electron API.
ModifiedMedium (5.4)0.53%—Issuehunt Boostnote5/18/20216/17/2026
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
ModifiedMedium (5.4)0.67%—Boostio Boostnote5/19/20196/17/2026
There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence, gallery, or chart, as demonstrated by a crafted SRC attribute of an IFRAME element, a different vulnerability than CVE-2019-12136.
ModifiedMedium (5.4)0.61%—Boostio Boostnote5/16/20196/17/2026
There is XSS in BoostIO Boostnote 0.11.15 via a label named mermaid, as demonstrated by a crafted SRC attribute of an IFRAME element.
ModifiedMedium (6.1)0.86%—Boostnote7/8/20186/17/2026
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.