Vulnerabilities
Summary — last 7 days
New vulnerabilities2,633▼ 304 vs. last week
Critical / high1,352▲ 80 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)58▼ 469 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Critical (9.6) | 0.85% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 5/4/2026 | 6/17/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to Notesnook Web/Desktop version 3.3.15 and prior to Notesnook iOS/Android version 3.3.20, a stored XSS vulnerability in the note export flow can be escalated to remote code execution in the desktop app. The root cause is that exported note… | |
| Analyzed | Medium (6.1) | 0.34% | — | Streetwriters Notesnook Mobile | 4/1/2026 | 6/17/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip metadata is concatenated into HTML without escaping and then rendered with innerHTML inside the mobile share editor… | |
| Analyzed | Critical (9.6) | 0.69% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 3/27/2026 | 6/17/2026 | Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element… | |
| Analyzed | Medium (5.4) | 0.24% | — | Streetwriters Notesnook DesktopStreetwriters Notesnook Mobile | 3/11/2026 | 6/17/2026 | Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated the user-supplied URL directly into an… |